<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/683691#M20006</link>
    <description>You're welcome. I'm glad the problem has been resolved.</description>
    <pubDate>Mon, 14 Sep 2020 15:13:02 GMT</pubDate>
    <dc:creator>alexal</dc:creator>
    <dc:date>2020-09-14T15:13:02Z</dc:date>
    <item>
      <title>SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666481#M19339</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I face an issue&amp;nbsp;trying to&amp;nbsp;set IWA auth for users. IWA is&amp;nbsp;functional for the metadata server, but I am unable to start workspace&amp;nbsp;via SAS EG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My configuration&amp;nbsp;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- meta, compute on two separate Linux server (RH)&lt;/P&gt;&lt;P&gt;- Workspace server is bind to an LDAP directory via PAM.&lt;/P&gt;&lt;P&gt;- Kerberos&amp;nbsp;binding to AD&amp;nbsp;is functional: on metadata server and the app server - using SAS Integration Technologies Configuration tool I can conenct usink "Negociate" to Metadata, Object Spawner, but not to the Workspace Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you see below, the kerberos auth and delegation seems ok, but the workspace doesn't start.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;I've tried all that I could find regarding this error (for example getent &lt;A href="mailto:user@domain.com" target="_blank" rel="noopener"&gt;user.name@domain.com&lt;/A&gt; and getent &lt;A href="mailto:USER@domain.com" target="_blank" rel="noopener"&gt;USER.NAME@domain.com&lt;/A&gt; both work) to no avail.&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2020-07-01T22:48:16,111 DEBUG [00000047] :user.name - IOM RETURN OMIProxy 0={compRef:7fba8520da20}-&amp;gt;CompDtor()
2020-07-01T22:48:16,111 TRACE [00000047] :user.name - IOM LOGIC TKIOM: delete compRef=7fba8520da20 for OMIProxy
2020-07-01T22:48:16,111 DEBUG [00000047] :user.name - Application-specific option lookup skipped because no application name is provided for client 11.
2020-07-01T22:48:16,111 DEBUG [00000047] :user.name - Command being used is /sas/sasconfig/Lev1/SASAppOne/WorkspaceServer/WorkspaceServer.sh.
2020-07-01T22:48:16,111 DEBUG [00000047] :user.name -    &amp;gt;noterminal&amp;lt; (Standard options)
2020-07-01T22:48:16,111 DEBUG [00000047] :user.name -    &amp;gt;netencryptalgorithm&amp;lt; (Standard options)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;SASProprietary&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;metaserver&amp;lt; (Standard options)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;srvsasmetak01t.company.com&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;metaport&amp;lt; (Standard options)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;8561&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;metarepository&amp;lt; (Standard options)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;Foundation&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;locale&amp;lt; (Client requirement)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;en_US&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;objectserver&amp;lt; (Standard options)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;objectserverparms&amp;lt; (Standard options)
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;protocol=bridge spawned spp=39532 cid=0 dnsmatch=srvsasappk01t.company.com pb classfactory=440196D4-90F0-11D0-9F41-00A024BB830C server=OMSOBJ:SERVERCOMPONENT/A504E8PI.AY00000A cel=credentials recon&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -  Environment variables are:
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;METAUSER&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;user.name@!*(generatedpassworddomain)*!&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -    &amp;gt;METAPASS&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name -       &amp;gt;********&amp;lt;
2020-07-01T22:48:16,112 DEBUG [00000047] :user.name - Obtained krb5 ccache handle: 7fba8801b8f0
2020-07-01T22:48:16,113 WARN  [00000047] :user.name - The destination buffer size was not sufficient for the requested password.
2020-07-01T22:48:16,124 DEBUG [00000047] :user.name - Freed krb5 ccache handle: 7fba8801b8f0
2020-07-01T22:48:16,124 ERROR [00000047] :user.name - Access denied.
2020-07-01T22:48:16,124 ERROR [00000047] :user.name - The launch of server SASAppOne - Workspace Server for user user.name failed.
2020-07-01T22:48:16,124 TRACE [00000047] :user.name - IOM FIRE-EVENT {compRef:7fba8520d960}-&amp;gt;ObjectSpawner::ServerFailed():
 logicalServer=SASAppOne - Logical Workspace Server
 serverComponent=SASAppOne - Workspace Server&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the sasauth-debug.log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;20200701-22:14:04 KRB5CCNAME was not set; we'll see if something happens later
[...]
20200701-22:48:16 Authenticating user user.name via GSS
20200701-22:48:16 Context username: user.name@company.com
20200701-22:48:16 Context username length: 21
20200701-22:48:16 Server Name: SAS/srvsasappK01t.company.com@company.com
20200701-22:48:16 Unknown user when getting user attributes.
20200701-22:48:16 User user.name did not authenticate. Reason: 'Unspecified reason.' (gss)
20200701-22:48:16 Request failed: 'User did not authenticate.'&lt;/PRE&gt;I am not sure about that warning about KRB5CCNAME, what should I set it to? I've seen &lt;A href="https://communities.sas.com/t5/SAS-Communities-Library/How-to-generate-a-Kerberos-ticket-when-you-log-in-to-SAS-Studio/tac-p/599095/highlight/true" target="_self"&gt;this&lt;/A&gt;, but I don't seem to find a file named "krb5cc_*". My krb5.conf has by default this option:&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;default_ccache_name = KEYRING:persistent:%{uid}&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Jul 2020 20:40:07 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666481#M19339</guid>
      <dc:creator>nirolf</dc:creator>
      <dc:date>2020-07-01T20:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666489#M19340</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/38143"&gt;@nirolf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like your Linux server isn't connected to Active Directory. What is the output of the following command?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;getent passwd user.name&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Also, we do not support keyrings, only file-based Kerberos tickets.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 21:04:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666489#M19340</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2020-07-01T21:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666491#M19341</link>
      <description>&lt;P&gt;The server is connected to AD. Using SAS I can start thw Workspace Server with user.name@company.com but without IWA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;getent &lt;A href="mailto:user@domain.com" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;user.name@domain.com&lt;/A&gt; and getent &lt;A href="mailto:USER@domain.com" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;USER.NAME@domain.com&lt;/A&gt; both work, and return:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;user.name@company.com:*:1742386352:1112800513:User Name:/home/user.name@company.com:/bin/bash&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed the krb5.conf to: default_ccache_name = &lt;A target="_blank" rel="noopener"&gt;FILE:/tmp/krb5cc_%{uid}&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But it seems that the file /tmp/krb5cc_1742386352 gets created only if I run kinit -V &lt;A href="mailto:user.name@COMPANY.COM" target="_blank" rel="noopener"&gt;user.name@COMPANY.COM&lt;/A&gt;. When connecting with EG for example I see this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[12253] 1593637956.856010: Decrypted AP-REQ with server principal SAS/srvsasappK01t.company.com@company.com: rc4-hmac/03B7
[12253] 1593637956.856011: AP-REQ ticket: user.name@company.com -&amp;gt; SAS/srvsasappK01t.company.com@company.com, session key rc4-hmac/DD52
[12253] 1593637956.856012: Negotiated enctype based on authenticator: aes256-cts
[12253] 1593637956.856013: Authenticator contains subkey: rc4-hmac/A744
[12253] 1593637956.856014: Resolving unique ccache of type MEMORY
[12253] 1593637956.856015: Initializing MEMORY:t2RN587 with default princ user.name@company.com
[12253] 1593637956.856016: Storing user.name@company.com -&amp;gt; krbtgt/company.com@company.com in MEMORY:t2RN587
[12253] 1593637956.856018: Creating AP-REP, time 1593637956.6499, subkey aes256-cts/BEAC, seqnum 497277098
[12253] 1593637956.856029: Resolving unique ccache of type FILE
[12253] 1593637956.856030: Initializing FILE:&lt;FONT face="arial black,avant garde"&gt;/&lt;STRONG&gt;tmp/tktPDXsyq&lt;/STRONG&gt;&lt;/FONT&gt; with default princ user.name@company.com
[12253] 1593637956.856033: Storing user.name@company.com -&amp;gt; krbtgt/company.com@company.com in FILE:/tmp/tktPDXsyq
[12253] 1593637956.856036: Destroying ccache MEMORY:t2RN587
[12253] 1593637956.856038: Destroying ccache FILE:/tmp/tktPDXsyq&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 21:19:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666491#M19341</guid>
      <dc:creator>nirolf</dc:creator>
      <dc:date>2020-07-01T21:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666493#M19343</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/38143"&gt;@nirolf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;20200701-22:48:16 Authenticating user user.name via GSS&lt;/PRE&gt;
&lt;P&gt;I do not see any domains in the user name here. Are you sure you can authenticate on the server using only the user name without specifying a domain?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 21:23:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666493#M19343</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2020-07-01T21:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666495#M19344</link>
      <description>&lt;P&gt;Without the domain it doesn't work, but what should I do for that to work? The server is connected to AD using pam.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed that the file &lt;FONT face="arial black,avant garde"&gt;&lt;STRONG&gt;tktPDXsyq&lt;/STRONG&gt;&lt;/FONT&gt; doesn't exist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Initializing FILE:&lt;FONT face="arial black,avant garde"&gt;/&lt;STRONG&gt;tmp/tktPDXsyq&lt;/STRONG&gt;&lt;/FONT&gt; with default princ &lt;A href="mailto:user.name@company.com" target="_blank"&gt;user.name@company.com&lt;/A&gt;&lt;BR /&gt;Storing user.name@company.com -&amp;gt; krbtgt/company.com@company.com in FILE:/tmp/tktPDXsyq&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;If I connect to the Object Spawner I get a new file and that one I can see in /tmp.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 21:34:29 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/666495#M19344</guid>
      <dc:creator>nirolf</dc:creator>
      <dc:date>2020-07-01T21:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/683683#M20005</link>
      <description>&lt;P&gt;Thanks, that was it, I just forgot to post an update. I edited sssd.conf by adding this line to &lt;STRONG&gt;[sssd]&lt;/STRONG&gt; section:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;default_domain_suffix = COMPANY.COM&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 14:43:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/683683#M20005</guid>
      <dc:creator>nirolf</dc:creator>
      <dc:date>2020-09-14T14:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/683691#M20006</link>
      <description>You're welcome. I'm glad the problem has been resolved.</description>
      <pubDate>Mon, 14 Sep 2020 15:13:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/683691#M20006</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2020-09-14T15:13:02Z</dc:date>
    </item>
  </channel>
</rss>

