<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAS 9.4 M8 WebAuthentication : SASServer2_1 Issue in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991054#M30862</link>
    <description>In addition, look at this piece:&lt;BR /&gt;&lt;BR /&gt;org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136&lt;BR /&gt;&lt;BR /&gt;Do you know what those are? It seems as may be one of the many causes why it’s not working, in CAS. Should I assume one is web and the other is your compute?</description>
    <pubDate>Sat, 18 Jul 2026 15:48:20 GMT</pubDate>
    <dc:creator>JuanS_OCS</dc:creator>
    <dc:date>2026-07-18T15:48:20Z</dc:date>
    <item>
      <title>SAS 9.4 M8 WebAuthentication : SASServer2_1 Issue</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/990996#M30860</link>
      <description>&lt;P&gt;I am configuring Windows server 2022 SAS 9.4 M8 new environment with IWA connections. Got all the required delegation privileges, SPN, , Keytabs created. IWA is working fine with compute and SASLogon, I do get Signin message with the&amp;nbsp; SAS Logon URL&amp;nbsp;&lt;A href="https://dsasas.hsb.hrsa.gov/SASLogon/login," target="_blank" rel="noopener"&gt;https://midtier/SASLogon/login,&lt;/A&gt;&amp;nbsp;However SASStudio is giving an issue where my kerberos token is not being passed to compute/objectspawner to authenticate and I am getting no user credentials exists on the controller when tried to login with SASStudio URL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do have the below entries in the jass.conf file under&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN&gt;SASServer1_1\conf &amp;amp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;SASServer2_1\conf&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "idpropagation"="sspi" &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sspisecuritypackagelist"="KERBEROS"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; ;&lt;/P&gt;
&lt;P&gt;also below at end of the file:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;com.sun.security.jgss.krb5.initiate {&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; doNotPrompt=true&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/midtier.com@COMPANY.COM"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; keyTab="C:/Windows/&amp;lt;keytabfile&amp;gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; storeKey=true;&lt;/P&gt;
&lt;P&gt;};&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;com.sun.security.jgss.krb5.accept {&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; doNotPrompt=true&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/midtier.com@COMPANY.COM"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; keyTab="C:/Windows/&amp;lt;keytabfile&amp;gt;"&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &amp;nbsp;storeKey=true;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;};&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;server.xml has been updated with below&lt;/P&gt;
&lt;P&gt;Replaced below&lt;/P&gt;
&lt;P&gt;&amp;lt;Realm className="org.apache.catalina.realm.UserDatabaseRealm"&lt;BR /&gt;resourceName="UserDatabase"/&amp;gt;&lt;/P&gt;
&lt;P&gt;with this:&lt;/P&gt;
&lt;P&gt;&amp;lt;Realm className="com.sas.vfabrictcsvr.realm.GSSContextEstablishedRealm"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; allRolesMode="authOnly"/&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Metadata login has two entries for the user with respective authdomains one with Defaultauth (&lt;A href="mailto:user@doamin" target="_blank" rel="noopener"&gt;user@doamin&lt;/A&gt;) and one with "web" (user)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We do have the other environment working with the same configuration but this is not authenticating me and throwing sspi errors,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSPI error on SASStudio3.82 log&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV&gt;2026-07-16 20:57:03,721 ERROR [tomcat-http--8] auth.AuthenticationProviderWIP (AuthenticationProviderWIP.java:96) - Unable to connect to workspace.&lt;/DIV&gt;
&lt;DIV&gt;java.lang.IllegalStateException: com.sas.security.sspi.SSPIAuthException&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; at com.sas.iom.orb.brg.SecurityPackageBase.getDelegatedAuth(SecurityPackageBase.java:187)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; at com.sas.iom.orb.brg.SecurityPackageBase.initClient(SecurityPackageBase.java:56)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; at com.sas.iom.orb.brg.Engine.createSecurityPackage(Engine.java:5551)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; at com.sas.iom.orb.brg.Engine.flowSendAuth(Engine.java:4319)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; at com.sas.iom.orb.brg.Engine.flow(Engine.java:724)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; at com.sas.iom.orb.brg.Engine.initClient(Engine.java:683)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SASLogon log reporting the below main error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;2026-07-16 20:56:53,560 [tomcat-http--41] WARN&amp;nbsp; javax.persistence.spi - javax.persistence.spi::No valid providers found.&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,374 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,375 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.web.support.gen.CookieRetrievingCookieGenerator - InvalidCookieException&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; DefaultCasCookieValueManager.java:obtainValueFromCompoundCookie:102&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; EncryptedCookieValueManager.java:obtainCookieValue:51&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; CookieValueManager.java:obtainCookieValue:35&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,386 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,387 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.web.support.gen.CookieRetrievingCookieGenerator - InvalidCookieException&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; DefaultCasCookieValueManager.java:obtainValueFromCompoundCookie:102&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; EncryptedCookieValueManager.java:obtainCookieValue:51&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; CookieValueManager.java:obtainCookieValue:35&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,421 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.authentication.attribute.PrincipalAttributeRepositoryFetcher - No person records were fetched from attribute repositories for [{principal=user, credentialClass=[PrincipalBearingCredential], credentialId=[user], username=user}]&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,427 [tomcat-http--41] INFO&amp;nbsp; org.apereo.cas.authentication.DefaultAuthenticationManager - Authenticated principal [user] with attributes [{}] via credentials [[PrincipalBearingCredential(super=AbstractCredential(), principal=SimplePrincipal(id=user, attributes={}))]].&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,681 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136&lt;/DIV&gt;
&lt;DIV&gt;2026-07-16 20:56:54,682 [tomcat-http--41] WARN&amp;nbsp; org.apereo.cas.web.support.gen.CookieRetrievingCookieGenerator - InvalidCookieException&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; DefaultCasCookieValueManager.java:obtainValueFromCompoundCookie:102&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; EncryptedCookieValueManager.java:obtainCookieValue:51&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; CookieValueManager.java:obtainCookieValue:35&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 Jul 2026 02:27:41 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/990996#M30860</guid>
      <dc:creator>mkiran</dc:creator>
      <dc:date>2026-07-17T02:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M8 WebAuthentication : SASServer2_1 Issue</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991053#M30861</link>
      <description>Hi there,&lt;BR /&gt;It seems to me you got SSO working well in SASServer1_1 via IWA/Kerberos. &lt;BR /&gt;However: did you configure it as well what is needed in SASServer2_1, where SASStudio lives? And, did you configure SSO with IWA/Kerberos in your SAS Metadata and Object Spawner/Workspace and Pooled Workspace servers? &lt;BR /&gt;Mind:&lt;BR /&gt;You need to prioritize IWA via Kerberos rather than NTLM (maybe just remove NTLM)&lt;BR /&gt;Depending on your configuration if it’s GRID, SASStudio may launch 2 sas.exe sessions per SASStudio session: an “spawner” or “launcher” and your actual Workspace. Both need the SSO via Kerberos/IWA.&lt;BR /&gt;Pleas search for &lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/37179"&gt;@StuartRogers&lt;/a&gt; entries about Kerberos and SSO in SAS 9.4 or the advanced authentication and security topics for 9.4 in SAS VLE site, they are priceless.</description>
      <pubDate>Sat, 18 Jul 2026 15:43:25 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991053#M30861</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2026-07-18T15:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M8 WebAuthentication : SASServer2_1 Issue</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991054#M30862</link>
      <description>In addition, look at this piece:&lt;BR /&gt;&lt;BR /&gt;org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136&lt;BR /&gt;&lt;BR /&gt;Do you know what those are? It seems as may be one of the many causes why it’s not working, in CAS. Should I assume one is web and the other is your compute?</description>
      <pubDate>Sat, 18 Jul 2026 15:48:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991054#M30862</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2026-07-18T15:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M8 WebAuthentication : SASServer2_1 Issue</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991080#M30863</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;&amp;nbsp;: Original issue was with the service account delegation privileges , IAM misconfigured these privileges and I got them corrected.&lt;/P&gt;
&lt;P&gt;I saw No person records fetched entries in SASLogon9.4.log that gave me a hint of SASServer1_1 also not working well even though it gives me the message (you are signed in) - its a false positive message.&lt;/P&gt;
&lt;P&gt;Issue got resolved after correcting delegation properties on the service account.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 13:28:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M8-WebAuthentication-SASServer2-1-Issue/m-p/991080#M30863</guid>
      <dc:creator>mkiran</dc:creator>
      <dc:date>2026-07-20T13:28:16Z</dc:date>
    </item>
  </channel>
</rss>

