<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Single Sign on on Midtier and Desktop Applications in Linux in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857364#M25913</link>
    <description>The relevant documentation is below. If you want a process to be owned by the authenticating user, their user ID must be valid on the compute server and potentially the CAS host in Viya (i.e. configure PAM/SSSD), but this does not necessarily mean they need to be able to SSH to the server. Alternatively the SAS/CAS process can be owned by a shared account, but this prevents using file system authorization to be used to limit access.&lt;BR /&gt;&lt;BR /&gt;SAS 9.4 Administration - Middle Tier Administration Guide - Support for Integrated Windows Authentication&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1871e69gmwdr0n1o182krslc10p.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1871e69gmwdr0n1o182krslc10p.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SAS 9.4 Administration - Security Administration Guide - How to Configure Integrated Windows Authentication&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Viya 3.5 Administration - Authentication: How-to&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/calcdc/3.5/calauthmdl/n1pkgyrtk8bp4zn1d0v1ln4869og.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/calcdc/3.5/calauthmdl/n1pkgyrtk8bp4zn1d0v1ln4869og.htm&lt;/A&gt;</description>
    <pubDate>Mon, 06 Feb 2023 14:12:01 GMT</pubDate>
    <dc:creator>gwootton</dc:creator>
    <dc:date>2023-02-06T14:12:01Z</dc:date>
    <item>
      <title>Single Sign on on Midtier and Desktop Applications in Linux</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857305#M25905</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a 9.4 and Viya 3.5 environment on Linux, we would like to setup Single Sign on on Midtier (9.4 and Viya3.5) and IWA for desktop apps. Appreciate any help to refer me to documentations to achieve this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also Is it required for the user to be able to ssh to the linux servers (like configure pam/sssd)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2023 06:29:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857305#M25905</guid>
      <dc:creator>alko13</dc:creator>
      <dc:date>2023-02-06T06:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Single Sign on on Midtier and Desktop Applications in Linux</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857364#M25913</link>
      <description>The relevant documentation is below. If you want a process to be owned by the authenticating user, their user ID must be valid on the compute server and potentially the CAS host in Viya (i.e. configure PAM/SSSD), but this does not necessarily mean they need to be able to SSH to the server. Alternatively the SAS/CAS process can be owned by a shared account, but this prevents using file system authorization to be used to limit access.&lt;BR /&gt;&lt;BR /&gt;SAS 9.4 Administration - Middle Tier Administration Guide - Support for Integrated Windows Authentication&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1871e69gmwdr0n1o182krslc10p.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bimtag/p1871e69gmwdr0n1o182krslc10p.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SAS 9.4 Administration - Security Administration Guide - How to Configure Integrated Windows Authentication&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Viya 3.5 Administration - Authentication: How-to&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/calcdc/3.5/calauthmdl/n1pkgyrtk8bp4zn1d0v1ln4869og.htm" target="_blank"&gt;https://go.documentation.sas.com/doc/en/calcdc/3.5/calauthmdl/n1pkgyrtk8bp4zn1d0v1ln4869og.htm&lt;/A&gt;</description>
      <pubDate>Mon, 06 Feb 2023 14:12:01 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857364#M25913</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2023-02-06T14:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Single Sign on on Midtier and Desktop Applications in Linux</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857485#M25918</link>
      <description>&lt;P&gt;Thanks for the reply Greg.&lt;/P&gt;
&lt;P&gt;Just to clarify, PAM/SSSD is really not required to achieve SSO, this is just optional if we wanted the SAS process be owned by the authenticating user in 9.4 and Viya 3.5?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 05:06:40 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857485#M25918</guid>
      <dc:creator>alko13</dc:creator>
      <dc:date>2023-02-07T05:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Single Sign on on Midtier and Desktop Applications in Linux</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857552#M25924</link>
      <description>That's correct.</description>
      <pubDate>Tue, 07 Feb 2023 14:12:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Single-Sign-on-on-Midtier-and-Desktop-Applications-in-Linux/m-p/857552#M25924</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2023-02-07T14:12:53Z</dc:date>
    </item>
  </channel>
</rss>

