<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows) in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/724184#M21721</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/37179"&gt;@StuartRogers&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sorry, I had included the wrong output, I have constrained delegation setup for the service account:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ldifde -f delegation.ldf -d "CN=svc-sasspawner,OU=Admins,DC=eom,DC=local" -l msDS-AllowedToDelegateTo

dn: CN=svc-sasspawner,OU=Admins,DC=eom,DC=local
changetype: add
msDS-AllowedToDelegateTo: sascas/sasviya35win.eom.local
msDS-AllowedToDelegateTo: sascas/sasviya35win
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Bart&lt;/P&gt;</description>
    <pubDate>Sat, 06 Mar 2021 17:12:30 GMT</pubDate>
    <dc:creator>bheinsius</dc:creator>
    <dc:date>2021-03-06T17:12:30Z</dc:date>
    <item>
      <title>SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/722683#M21656</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I followed Stuart Rogers' blog at&amp;nbsp;&lt;A href="https://communities.sas.com/t5/SAS-Communities-Library/SAS-Viya-3-5-Object-Spawner-with-Kerberos/ta-p/638484" target="_blank"&gt;https://communities.sas.com/t5/SAS-Communities-Library/SAS-Viya-3-5-Object-Spawner-with-Kerberos/ta-p/638484&lt;/A&gt; to connect EG83 to a SAS Viya 3.5 Workspace Server on Windows, using Kerberos. I created SPN's and defined constrained delegation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In EG,&amp;nbsp;I set the Security Package in the SAS Workspace Server definition explicitly to Kerberos, the Workspace Server session starts. The Object Spawner log mentions:&lt;/P&gt;
&lt;PRE&gt;IWA context established using NTLM package&lt;/PRE&gt;
&lt;P&gt;I had expected Kerberos here instead of NTLM, is that correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I then try to start a CAS session&amp;nbsp;from that Workspace Server and get the following errors&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;28         options cashost=localhost;
29         options casport=5570;
30         cas;
ERROR: Error in SSPI function AcquireCredentialsHandle. Error -2146893042 (No credentials are available in the security 
       package ).
ERROR: Unable to load extension: (tkcident)
ERROR: The Kerberos extension failed to load. Kerberos is not functional in this environment.
ERROR: Unable to connect to Cloud Analytic Services localhost on port 5570. Verify connection parameters and retry.
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;- Bart&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 20:38:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/722683#M21656</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2021-03-01T20:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/722989#M21664</link>
      <description>There seem to be duplicate SPN's for SAS/&amp;lt;hostname&amp;gt;, that's not right for sure. I will have one removed and report back.</description>
      <pubDate>Tue, 02 Mar 2021 21:33:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/722989#M21664</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2021-03-02T21:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723144#M21671</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13625"&gt;@bheinsius&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good thing to remember is that IWA is not just Kerberos, it is also NTLM.&amp;nbsp; Essentially with Windows systems it will always attempt Kerberos (so long as they are different hosts), but it will fallback to NTLM if something goes "wrong".&amp;nbsp; Having duplicate SPNs would definitely fall into the something "wrong" category&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When EG attempts to obtain the service ticket for the given SPN this will fail if duplicate SPNs are registered.&amp;nbsp; At that point "IWA" will drop back to NTLM.&amp;nbsp; So if you are expecting Kerberos and the logs show NTLM it's good practice to walk back through the prerequisites for Kerberos (check the SPN, check availability of local TGT, ensure processes are running on separate hosts).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope removing the duplicate SPNs resolves your issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 14:11:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723144#M21671</guid>
      <dc:creator>StuartRogers</dc:creator>
      <dc:date>2021-03-03T14:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723609#M21683</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/37179"&gt;@StuartRogers&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I removed the SPN for the SAS/&amp;lt;computer-account&amp;gt; but it returned right after restarting Viya.&lt;/P&gt;
&lt;P&gt;Checking the logs I see that the SAS Connect Spawner registers an SPN:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;2021-03-04T16:45:30,543 INFO &amp;nbsp;[00000008] :SYSTEM@STASASVIYAP01 - SPN registration succeeded for current host.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It doesn't say it's the SPN for the SAS service class but I think it is.&lt;/P&gt;
&lt;P&gt;Should the SAS/CONNECT service also be running as the spawner service account?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And should its usermods file then also have this line:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Set USERMODS_OPTIONS=-sspi&lt;/PRE&gt;
&lt;P&gt;and its Windows Service re-installed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your time,&lt;/P&gt;
&lt;P&gt;Bart&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:13:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723609#M21683</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2021-03-04T20:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723797#M21706</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13625"&gt;@bheinsius&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes if you have the SAS/CONNECT spawner running on the host as the localsystem account this will automatically register the SAS/hostname SPN against the computer object.&amp;nbsp; So yes you'll need to switch the SAS/CONNECT spawner to run as the same service account you are using for the Object Spawner.&amp;nbsp; I would also recommend, as you've pointed out, adding the -sspi option to the usermods as covered in the &lt;A title="SAS Viya 3.5 Administration Guide" href="https://go.documentation.sas.com/?cdcId=calcdc&amp;amp;cdcVersion=3.5&amp;amp;docsetId=calsrvpgm&amp;amp;docsetTarget=n00005viyaprgmsrvs00000admin.htm&amp;amp;locale=en#n08104viyaservers000000admin" target="_self"&gt;SAS Viya 3.5 Administration Guide&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 07:58:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723797#M21706</guid>
      <dc:creator>StuartRogers</dc:creator>
      <dc:date>2021-03-05T07:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723962#M21714</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/37179"&gt;@StuartRogers&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Removing the duplicate SPN worked as the spawner log now says:&lt;/P&gt;
&lt;PRE&gt;IWA context established using Kerberos package.&lt;/PRE&gt;
&lt;P&gt;I now see the Workspace Server running under my account on the Viya server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The next step is connecting to CAS from that Workspace Server session.&lt;/P&gt;
&lt;P&gt;The SPNs are there:&lt;/P&gt;
&lt;PRE&gt;C:\Users\svc-sasinst&amp;gt;setspn -Q SAS/sasviya35win.eom.local
Checking domain DC=eom,DC=local
CN=svc-sasspawner,OU=Admins,DC=eom,DC=local
        SAS/sasviya35win
        SAS/sasviya35win.eom.local

Existing SPN found!
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I configured constrained delegation for the computer account:&lt;/P&gt;
&lt;PRE&gt;dn: CN=sasviya35win,OU=VirtualMachines,DC=eom,DC=local
changetype: add
msDS-AllowedToDelegateTo: sascas/sasviya35win.eom.local
msDS-AllowedToDelegateTo: sascas/sasviya35win
&lt;/PRE&gt;
&lt;P&gt;I set the SAS_CONSTRAINED_DELEG_ENABLED environment variable to 1. From the SAS Workspace Server session:&lt;/P&gt;
&lt;PRE&gt;28         %put NOTE: %sysget(SAS_CONSTRAINED_DELEG_ENABLED);
NOTE: 1
&lt;/PRE&gt;
&lt;P&gt;But connecting to CAS fails:&lt;/P&gt;
&lt;PRE&gt;28         options set=CASCLIENTDEBUG=1;
29         options cashost="sasviya35win.eom.local" casport=5570;
30         cas casauto;
NOTE: HOMEDRIVE: C:
NOTE: HOMEPATH: \Users\svc-sasinst
NOTE: Client is using the token identity provider
NOTE: Calling ClientContextInit
NOTE: First call to initialize context
ERROR: Error in SSPI function InitializeSecurityContext. Error -2146893042 (No credentials are available in the security 
       package ).
ERROR: Access denied.
ERROR: Unable to connect to Cloud Analytic Services localhost on port 5570. Verify connection parameters and retry.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did I miss a step?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Bart&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 19:33:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723962#M21714</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2021-03-05T19:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723970#M21715</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13625"&gt;@bheinsius&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have the SPN registered against a service account:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;CN=svc-sasspawner,OU=Admins,DC=eom,DC=local&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Then you need to set the constrained delegation options for the service account and not the computer account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 19:10:58 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/723970#M21715</guid>
      <dc:creator>StuartRogers</dc:creator>
      <dc:date>2021-03-05T19:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/724184#M21721</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/37179"&gt;@StuartRogers&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sorry, I had included the wrong output, I have constrained delegation setup for the service account:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ldifde -f delegation.ldf -d "CN=svc-sasspawner,OU=Admins,DC=eom,DC=local" -l msDS-AllowedToDelegateTo

dn: CN=svc-sasspawner,OU=Admins,DC=eom,DC=local
changetype: add
msDS-AllowedToDelegateTo: sascas/sasviya35win.eom.local
msDS-AllowedToDelegateTo: sascas/sasviya35win
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Bart&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 17:12:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/724184#M21721</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2021-03-06T17:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Viya 3.5 Object Spawner with Kerberos fails (Windows)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/724258#M21728</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13625"&gt;@bheinsius&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So you stated:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;I now see the Workspace Server running under my account on the Viya server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;With constrained delegation on Windows we expect to see all workspace server or Compute Server processes to run as the service account which then impersonates the client-user identity.&amp;nbsp; So there is still something not working correctly even though Kerberos has now been used to authenticate to the Spawner.&amp;nbsp; I think you'll need Technical Support to drill into this in more detail than can be achieved by the "back-and-forth" offered here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for your time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Stuart&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Mar 2021 08:31:33 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Viya-3-5-Object-Spawner-with-Kerberos-fails-Windows/m-p/724258#M21728</guid>
      <dc:creator>StuartRogers</dc:creator>
      <dc:date>2021-03-07T08:31:33Z</dc:date>
    </item>
  </channel>
</rss>

