<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp;amp; SMC in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969103#M30067</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes, you will need SPNs and a UPN, and to enable (contrained) Keberos delegation.&lt;/P&gt;
&lt;P&gt;Again, it is all well documented by SAS:&amp;nbsp;&lt;A href="https://documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm" target="_blank"&gt;https://documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If what you need is an overview, you can find a nice one provided by&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/18432"&gt;@PaulHomes&lt;/a&gt;&amp;nbsp;here:&amp;nbsp;&lt;A href="https://platformadmin.com/blogs/paul/2015/01/iwa-sas-94m2-linux/" target="_blank"&gt;https://platformadmin.com/blogs/paul/2015/01/iwa-sas-94m2-linux/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It is based on an old maintenance (2), but I am sure that, by reading the documentation provided by SAS, you can make the adjustments required for your actual SAS environment.&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Juan&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jun 2025 11:02:18 GMT</pubDate>
    <dc:creator>JuanS_OCS</dc:creator>
    <dc:date>2025-06-16T11:02:18Z</dc:date>
    <item>
      <title>implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969097#M30064</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I&amp;nbsp;Want to implement the SSO for the SAS fat clients like SAS Enterprise guide, sas di studio and SAS Management Console.&lt;BR /&gt;Generally used to open SAS tools from Citrix Windows 2019 server and the code executes on linux server.&lt;BR /&gt;Can anyone help us to implement the SSO using the IWA method for sas fat clients.&lt;BR /&gt;&lt;BR /&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Siddhu&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 09:51:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969097#M30064</guid>
      <dc:creator>siddhu1</dc:creator>
      <dc:date>2025-06-16T09:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969098#M30065</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/375476"&gt;@siddhu1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;since your servers are on Linux, you are bound to set up Kerberos IWA system between the servers and your clients (and, preferably, between your SAS servers and your DBMS).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;IWA with Kerberos is described in the SAS documentation. If you have any more specific question, please feel free to raise those questions!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best ,&lt;/P&gt;
&lt;P&gt;Juan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 09:58:13 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969098#M30065</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2025-06-16T09:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969100#M30066</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Do we need to setup any SPN's (service prinicpal name ) for linux servers (of each meta, compute servers) with the AD of Windows server&amp;nbsp; before setting up the kerberos configuration. Is it possible to provide any step on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Siddhu1&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 10:42:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969100#M30066</guid>
      <dc:creator>siddhu1</dc:creator>
      <dc:date>2025-06-16T10:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969103#M30067</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes, you will need SPNs and a UPN, and to enable (contrained) Keberos delegation.&lt;/P&gt;
&lt;P&gt;Again, it is all well documented by SAS:&amp;nbsp;&lt;A href="https://documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm" target="_blank"&gt;https://documentation.sas.com/doc/en/bicdc/9.4/bisecag/n1d1zo1jsf2o0en1ehu4c4simfky.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If what you need is an overview, you can find a nice one provided by&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/18432"&gt;@PaulHomes&lt;/a&gt;&amp;nbsp;here:&amp;nbsp;&lt;A href="https://platformadmin.com/blogs/paul/2015/01/iwa-sas-94m2-linux/" target="_blank"&gt;https://platformadmin.com/blogs/paul/2015/01/iwa-sas-94m2-linux/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It is based on an old maintenance (2), but I am sure that, by reading the documentation provided by SAS, you can make the adjustments required for your actual SAS environment.&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Juan&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 11:02:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/969103#M30067</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2025-06-16T11:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971323#M30156</link>
      <description>Hi,&lt;BR /&gt;Need some clarification while creating the SPN's as meta and three compute servers are on linux and SAS EG is installed on the windows server 2019 machine.&lt;BR /&gt;Do we need to use SAS or Host in the SPN statement as it is quite confusing which one to use.&lt;BR /&gt;Set -A SAS/&amp;lt;meta servernamr&amp;gt; servicename&lt;BR /&gt;Set -A SAS/&amp;lt;computesever1&amp;gt; servicename&lt;BR /&gt;Set -A SAS/&amp;lt;computeserver2&amp;gt; servicename&lt;BR /&gt;OR&lt;BR /&gt;Set -A host/&amp;lt;meta servernamr&amp;gt; servicename&lt;BR /&gt;Set -A host/&amp;lt;computesever1&amp;gt; servicename&lt;BR /&gt;Set -A host/&amp;lt;computeserver2&amp;gt; servicename&lt;BR /&gt;Can someone clarify on this.&lt;BR /&gt;&lt;BR /&gt;Kind Regards,&lt;BR /&gt;Siddhu1&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Jul 2025 17:05:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971323#M30156</guid>
      <dc:creator>siddhu1</dc:creator>
      <dc:date>2025-07-22T17:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971468#M30160</link>
      <description>The Metadata Server and Object Spawner use the service principal SAS/hostname by default, though this can be overridden using the "SAS_SERVICE_PRINCIPAL_NAME" environment variable, which would be required if the SPN and UPN do not match. That would be the case if you were assigning multiple SPNs to a single AD identity.</description>
      <pubDate>Fri, 25 Jul 2025 12:48:54 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971468#M30160</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2025-07-25T12:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971666#M30164</link>
      <description>&lt;P&gt;Hi Greg,&lt;BR /&gt;Thanks for your response.&lt;BR /&gt;I have created the SPN's for the one meta and three compute servers.&amp;nbsp;&lt;BR /&gt;Could you please let me know whether we need one keytab file for all servers or separately required for each server.&lt;BR /&gt;&lt;BR /&gt;Kind Regards,&lt;BR /&gt;&lt;SPAN&gt;Siddhu1&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2025 05:13:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971666#M30164</guid>
      <dc:creator>siddhu1</dc:creator>
      <dc:date>2025-07-30T05:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: implementation of SSO for SAS Fat clients SAS EG, SAS DI Studio &amp; SMC</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971724#M30166</link>
      <description>You could use a single keytab for all, the process will search for the SPN it wants within the keytab file.</description>
      <pubDate>Wed, 30 Jul 2025 17:42:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/implementation-of-SSO-for-SAS-Fat-clients-SAS-EG-SAS-DI-Studio/m-p/971724#M30166</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2025-07-30T17:42:41Z</dc:date>
    </item>
  </channel>
</rss>

