<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weird access behavior to a library in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938637#M28823</link>
    <description>&lt;P&gt;770 is what i set to the directory, the thing is that you can map your login or security of the groups on a linux machine to a ldap trough a bind, with that set i have onwer sas and for the group there is an ldap group empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the question is why if the group is EMPTY some users can map the library without getting the error for user access insuficent rights?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my point is that i think that something goes on behind the session open on the server that lets some users access to directories that shouldn't have, and i would like to know what it is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: applying meta bound libraries would solve the problem for sure, but at the moment we cannot apply this change since we're in the middle of another project.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2024 06:26:30 GMT</pubDate>
    <dc:creator>W1ndwaker</dc:creator>
    <dc:date>2024-08-08T06:26:30Z</dc:date>
    <item>
      <title>Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938482#M28808</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm facing a weird situation with sas setup, we have a sas 9.4m7 installed on RHEL, everything seems to be working fine.&lt;/P&gt;
&lt;P&gt;We use the system level folders to map some libraries to the end users, we have a set of permisions on the folder which are a ldap group assigned to the folder, and the owner is sas, normally this works fine and if you're not in the users group you cannot map the library.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The point is that we've created a new workspace server with a set of libraries (os folder) assigned to it with it's specific group, and the weird thing comes when someone tested the access to the library and got it correctly, but the group has no users assigned to it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then i've made some tests with this folder, for example I have 2 users that can map the folder in their eguid, 1 is a sas administrator and the other a regular end user, but none of them are in the ldap group that grants access to the folder, and I have no access to the library nor the group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first test i did to check the situation was to access to the server with the user directly and try to create a test file and that didn't work (as expected since the user is not in the group) but then it makes me think what is happening in eguide that lets this users to map the folder and create datasets, the only thing that comes to my mind is that eguide creates a sesion with user sas (and then impersonate as the end user) and this is why it lets the user map the library.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've also tryied some other test like checking the users and comparing the permissions in the management console, and everything seems fine, all users are the same and have the same config as me, except 1 of them that has admin role. Also I put myself in the gruop to see if i had access to the folder and that worked fine, so it's how is supossed to be.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have a clue of what can be happening? since we can have a posible security breach here if a user can map libraries that's not supossed to have access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 08:52:45 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938482#M28808</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-08-07T08:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938505#M28809</link>
      <description>If you want to control access through metadata, you must make those libraries metadata-bound. Otherwise, you have to use the operating system (which means access control lists if you have more than one group per library).</description>
      <pubDate>Wed, 07 Aug 2024 12:31:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938505#M28809</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2024-08-07T12:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938507#M28810</link>
      <description>Not an expert by any means, but this documentation might help:  &lt;A href="https://documentation.sas.com/?cdcId=bicdc&amp;amp;cdcVersion=9.4&amp;amp;docsetId=bisecag&amp;amp;docsetTarget=n1nesjvtxu7783n1pveml8ct4txk.htm" target="_blank"&gt;https://documentation.sas.com/?cdcId=bicdc&amp;amp;cdcVersion=9.4&amp;amp;docsetId=bisecag&amp;amp;docsetTarget=n1nesjvtxu7783n1pveml8ct4txk.htm&lt;/A&gt;</description>
      <pubDate>Wed, 07 Aug 2024 12:43:27 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938507#M28810</guid>
      <dc:creator>SimonMcGrother</dc:creator>
      <dc:date>2024-08-07T12:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938508#M28811</link>
      <description>It's only one group per folder, it's a very easy set up.&lt;BR /&gt;&lt;BR /&gt;The thing is that if you're not in the group you should'nt be able to access, but the thing is that the users can map the library in eguide, but cannot do a cd &amp;lt;&amp;lt;directory&amp;gt;&amp;gt; in the server</description>
      <pubDate>Wed, 07 Aug 2024 12:43:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938508#M28811</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-08-07T12:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938509#M28812</link>
      <description>it's a possiblity, but we're migrating to another security solution, but in the meantime i wanted to know what is happening with this situation, without using the metadata.&lt;BR /&gt;(note: we had this security level system for this kind of enduser libraries for a long time and never seen this behavior)</description>
      <pubDate>Wed, 07 Aug 2024 12:48:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938509#M28812</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-08-07T12:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938511#M28814</link>
      <description>&lt;P&gt;So your SAS sessions are running on Linux?&lt;/P&gt;
&lt;P&gt;What are the permissions on the directory?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;770 would give the owner (user that owns the directory) full rights and the group (group that owns the directory) full rights and others would not even be able to read the contents of the directory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned LDAP.&amp;nbsp; How are you mapping LDAP permissions to Unix permissions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You talk about mapping the library.&amp;nbsp; But that is just setting up the pointer to where to look for the files.&amp;nbsp; Did you also test whether they can actually read any of the datasets in that library?&amp;nbsp; Do you expect the users to be able to modify the datasets in that library? Did you test if they could make a new dataset in that library?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:08:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938511#M28814</guid>
      <dc:creator>Tom</dc:creator>
      <dc:date>2024-08-07T13:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938512#M28815</link>
      <description>&lt;P&gt;The permission for the directory should be rwxrwx--- (or rwxr-x--- if only the owner may write datasets to it). If you have rwxrwxr-- the users can't cd into the directory, but read the directory file, which is sufficient for EG.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:12:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938512#M28815</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2024-08-07T13:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938517#M28816</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;The permission for the directory should be rwxrwx--- (or rwxr-x--- if only the owner may write datasets to it). If you have rwxrwxr-- the users can't cd into the directory, but read the directory file, which is sufficient for EG.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Just to clarify the difference between r-x and r-- is that without the execute permission directory access does not really work.&amp;nbsp; You might be able to read the directory as a binary file, but you cannot see the list of file that are inside it (unless you parse the contents yourself), and you definitely cannot access any of the files in the directory.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:27:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938517#M28816</guid>
      <dc:creator>Tom</dc:creator>
      <dc:date>2024-08-07T13:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938559#M28817</link>
      <description>&lt;P&gt;ls will work with only the read permission (as you only read the contents of the directory). ls -l won't work, as for this you need to access the individual inode of each file, and for this the x permission is needed.&lt;/P&gt;
&lt;P&gt;So, if EG only reads&amp;nbsp;&lt;EM&gt;names&lt;/EM&gt;, the r on its own will work, but any further access (e.g. SETting a dataset) will fail.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 15:48:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938559#M28817</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2024-08-07T15:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938637#M28823</link>
      <description>&lt;P&gt;770 is what i set to the directory, the thing is that you can map your login or security of the groups on a linux machine to a ldap trough a bind, with that set i have onwer sas and for the group there is an ldap group empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the question is why if the group is EMPTY some users can map the library without getting the error for user access insuficent rights?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my point is that i think that something goes on behind the session open on the server that lets some users access to directories that shouldn't have, and i would like to know what it is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: applying meta bound libraries would solve the problem for sure, but at the moment we cannot apply this change since we're in the middle of another project.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 06:26:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938637#M28823</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-08-08T06:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938795#M28825</link>
      <description>Please check if users able to „map“ the directory can also work with it (read datasets from there, or create them).&lt;BR /&gt;What do you mean by EMPTY? Are you saying that the directory has a group ownership for a group not contained in your LDAP source?&lt;BR /&gt;Did you check if there are access control lists defined for the directory?</description>
      <pubDate>Fri, 09 Aug 2024 11:56:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938795#M28825</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2024-08-09T11:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938893#M28830</link>
      <description>&lt;P&gt;Hello &lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/423342"&gt;@W1ndwaker&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I hope you have defined a new A&lt;STRONG&gt;PP Server Context&lt;/STRONG&gt; (for example &lt;STRONG&gt;SAS APP2)&lt;/STRONG&gt; for the new workspace server.&lt;BR /&gt;Make sure that the library is defined in the Workspace Server Autoexec_usermod and not at the App Server level.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Aug 2024 23:20:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938893#M28830</guid>
      <dc:creator>Sajid01</dc:creator>
      <dc:date>2024-08-10T23:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938914#M28831</link>
      <description>&lt;P&gt;You mentioned using Enterprise Guide.&amp;nbsp; Can you confirm that the users are actually signing on the SAS application server using their own account and not some other account that does have the right group access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should be able to check the SAS automatic macro variable SYSUSERID to see the userid of the user that is running SAS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 16:48:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/938914#M28831</guid>
      <dc:creator>Tom</dc:creator>
      <dc:date>2024-08-11T16:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943099#M28974</link>
      <description>&lt;P&gt;Yes, i've checked that, the group is set in the directory with the chgrp, and the group is from the ldap, there are no acls or weird things, just a grup with a set of users and owner (sas admin user).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the user is able to do a libname XXX "/path";&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and its able to work with datasets and create/delete them.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 07:02:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943099#M28974</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-09-09T07:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943106#M28975</link>
      <description>&lt;P&gt;Log on to the server as root (or have the admin do it) and look at the process list when said user starts a new SAS session to see the owner of that process.&lt;/P&gt;
&lt;P&gt;Is it possible you have a pooled workspace server defined?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 08:39:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943106#M28975</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2024-09-09T08:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943118#M28980</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;yes that is what i did, i created a new app server, then created the folder structure with permissions, and then i made a new autoexec specific to map the libraries for the server on the startup, the thing is that there are users that are not in the group of the folder that can map it and work on it.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 10:40:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943118#M28980</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-09-09T10:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943212#M28994</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/423342"&gt;@W1ndwaker&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;When you say this "&lt;FONT color="#3366FF"&gt;t&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT color="#3366FF"&gt;he thing is that there are users that are not in the group of the folder that can map it and work on it.&lt;/FONT&gt;", it's time that these users be added to the appropriate groups both at the LDAP, SASMC and the OS level if they need access.&lt;BR /&gt;Typically, SAS Administrators handle these scenarios with ease. If there is something weird OR complicated, it's time that a support ticket is created with SAS Tech Support for assistance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 19:47:01 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943212#M28994</guid>
      <dc:creator>Sajid01</dc:creator>
      <dc:date>2024-09-09T19:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943215#M28995</link>
      <description>While all of this information is true, I am with Kurt: I think you need to understand the process owner and the permissions set up, on top of your LDAP vs local groups configuration. &lt;BR /&gt;&lt;BR /&gt;This is an OS question more than SAS.&lt;BR /&gt;&lt;BR /&gt;Permissions in UNIX based systems are tricky and meant to be more restrictive than permissive. &lt;BR /&gt;&lt;BR /&gt;If you are interested in being more in control of your Linux permissions I would suggest to apply a granular configuration with ACLs, then you gen something similar to Windows.</description>
      <pubDate>Mon, 09 Sep 2024 19:55:47 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943215#M28995</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2024-09-09T19:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Weird access behavior to a library</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943445#M29015</link>
      <description>&lt;P&gt;Probably your answer to apply another kind of security is the best solution, and we're underway to do it, the point is that i found this situation in the meantime we change our system and datawarehouse, and wanted to share the situation, i know it's strange and seems to be something not correctly configured on LDAP/system or a maybe it's a bug on SAS, i'll be checking it and see if i find anything, but this will be corrected applying a new security model.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 07:03:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Weird-access-behavior-to-a-library/m-p/943445#M29015</guid>
      <dc:creator>W1ndwaker</dc:creator>
      <dc:date>2024-09-11T07:03:03Z</dc:date>
    </item>
  </channel>
</rss>

