<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAS Studio Session Not Inheriting Local UNIX Group Membership in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Studio-Session-Not-Inheriting-Local-UNIX-Group-Membership/m-p/992652#M30894</link>
    <description>&lt;DIV&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm looking for some guidance on an issue we're experiencing in a Linux-based SAS 9.4 environment integrated with Quest Authentication Services (VAS) and Active Directory.&lt;/P&gt;Issue Summary&lt;P&gt;A user has been added to a local UNIX group (&lt;STRONG&gt;local_admin_group&lt;/STRONG&gt;), and Linux correctly recognises the membership.&lt;/P&gt;&lt;P&gt;Running the &lt;CODE&gt;id&lt;/CODE&gt; command from a normal Linux session shows the user belongs to both the primary group and the local UNIX group. Likewise, &lt;CODE&gt;getent group local_admin_group&lt;/CODE&gt; correctly lists the user as a member.&lt;/P&gt;&lt;P&gt;The target directory permissions are similar to:&lt;/P&gt;&lt;P&gt;drwxrws---+ sas local_admin_group&lt;/P&gt;SAS Studio Behaviour&lt;P&gt;When the same user logs in through SAS Studio and executes the &lt;CODE&gt;id&lt;/CODE&gt; command via a PIPE statement, the output shows the correct user ID and primary group, along with AD/VAS groups, but the local UNIX group (&lt;STRONG&gt;local_admin_group&lt;/STRONG&gt;) is missing.&lt;/P&gt;&lt;P&gt;As a result, the user cannot access directories that rely on membership of the local UNIX group.&lt;/P&gt;Troubleshooting Performed&lt;P&gt;&lt;STRONG&gt;Quest VAS Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Updated &lt;CODE&gt;/etc/opt/quest/vas/vas.conf&lt;/CODE&gt; by adding:&lt;/P&gt;&lt;P&gt;[vas_vasd]&lt;BR /&gt;merge-local-groups = true&lt;/P&gt;&lt;P&gt;Restarted the VAS daemon afterwards.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PAM Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Updated &lt;CODE&gt;/etc/pam.d/sasauth&lt;/CODE&gt; to include:&lt;/P&gt;&lt;P&gt;session optional pam_keyinit.so revoke&lt;BR /&gt;session required pam_limits.so&lt;BR /&gt;-session optional pam_systemd.so&lt;BR /&gt;session sufficient pam_vas3.so&lt;BR /&gt;session required pam_unix.so&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NSS Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Updated &lt;CODE&gt;/etc/nsswitch.conf&lt;/CODE&gt; to include:&lt;/P&gt;&lt;P&gt;initgroups: files vas4 sss&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Service Restarts&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Restarted VAS services.&lt;/LI&gt;&lt;LI&gt;Restarted SAS services.&lt;/LI&gt;&lt;LI&gt;Created completely new SAS Studio sessions after making the changes.&lt;/LI&gt;&lt;/UL&gt;Current Status&lt;UL&gt;&lt;LI&gt;Linux shell sessions correctly show membership in &lt;STRONG&gt;local_admin_group&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;CODE&gt;getent group local_admin_group&lt;/CODE&gt; returns the expected membership.&lt;/LI&gt;&lt;LI&gt;SAS Studio sessions still do not show the &lt;STRONG&gt;local_admin_group&lt;/STRONG&gt; membership.&lt;/LI&gt;&lt;LI&gt;SAS Studio appears to inherit the primary group and AD/VAS groups, but not the local UNIX supplementary group.&lt;/LI&gt;&lt;/UL&gt;Questions&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Has anyone seen SAS Studio or Workspace Server sessions fail to inherit local UNIX supplementary groups while standard Linux login sessions work correctly?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Does the SAS Object Spawner or Workspace Server use a different mechanism for group resolution compared to a normal Linux login session?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there any known configuration required for &lt;CODE&gt;sasauth&lt;/CODE&gt;, &lt;CODE&gt;elssrv&lt;/CODE&gt;, PAM, or Quest VAS to ensure local UNIX group memberships are included in SAS Studio sessions?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Has anyone successfully used local UNIX groups for folder access in SAS Studio when the environment is integrated with Active Directory and Quest VAS?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there additional logs or diagnostics that can help identify where the local UNIX group membership is being lost during SAS session creation?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any suggestions, troubleshooting ideas, or similar experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 27 Aug 2026 10:51:26 GMT</pubDate>
    <dc:creator>bmsampath</dc:creator>
    <dc:date>2026-08-27T10:51:26Z</dc:date>
    <item>
      <title>SAS Studio Session Not Inheriting Local UNIX Group Membership</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Studio-Session-Not-Inheriting-Local-UNIX-Group-Membership/m-p/992652#M30894</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm looking for some guidance on an issue we're experiencing in a Linux-based SAS 9.4 environment integrated with Quest Authentication Services (VAS) and Active Directory.&lt;/P&gt;Issue Summary&lt;P&gt;A user has been added to a local UNIX group (&lt;STRONG&gt;local_admin_group&lt;/STRONG&gt;), and Linux correctly recognises the membership.&lt;/P&gt;&lt;P&gt;Running the &lt;CODE&gt;id&lt;/CODE&gt; command from a normal Linux session shows the user belongs to both the primary group and the local UNIX group. Likewise, &lt;CODE&gt;getent group local_admin_group&lt;/CODE&gt; correctly lists the user as a member.&lt;/P&gt;&lt;P&gt;The target directory permissions are similar to:&lt;/P&gt;&lt;P&gt;drwxrws---+ sas local_admin_group&lt;/P&gt;SAS Studio Behaviour&lt;P&gt;When the same user logs in through SAS Studio and executes the &lt;CODE&gt;id&lt;/CODE&gt; command via a PIPE statement, the output shows the correct user ID and primary group, along with AD/VAS groups, but the local UNIX group (&lt;STRONG&gt;local_admin_group&lt;/STRONG&gt;) is missing.&lt;/P&gt;&lt;P&gt;As a result, the user cannot access directories that rely on membership of the local UNIX group.&lt;/P&gt;Troubleshooting Performed&lt;P&gt;&lt;STRONG&gt;Quest VAS Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Updated &lt;CODE&gt;/etc/opt/quest/vas/vas.conf&lt;/CODE&gt; by adding:&lt;/P&gt;&lt;P&gt;[vas_vasd]&lt;BR /&gt;merge-local-groups = true&lt;/P&gt;&lt;P&gt;Restarted the VAS daemon afterwards.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PAM Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Updated &lt;CODE&gt;/etc/pam.d/sasauth&lt;/CODE&gt; to include:&lt;/P&gt;&lt;P&gt;session optional pam_keyinit.so revoke&lt;BR /&gt;session required pam_limits.so&lt;BR /&gt;-session optional pam_systemd.so&lt;BR /&gt;session sufficient pam_vas3.so&lt;BR /&gt;session required pam_unix.so&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NSS Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Updated &lt;CODE&gt;/etc/nsswitch.conf&lt;/CODE&gt; to include:&lt;/P&gt;&lt;P&gt;initgroups: files vas4 sss&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Service Restarts&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Restarted VAS services.&lt;/LI&gt;&lt;LI&gt;Restarted SAS services.&lt;/LI&gt;&lt;LI&gt;Created completely new SAS Studio sessions after making the changes.&lt;/LI&gt;&lt;/UL&gt;Current Status&lt;UL&gt;&lt;LI&gt;Linux shell sessions correctly show membership in &lt;STRONG&gt;local_admin_group&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;CODE&gt;getent group local_admin_group&lt;/CODE&gt; returns the expected membership.&lt;/LI&gt;&lt;LI&gt;SAS Studio sessions still do not show the &lt;STRONG&gt;local_admin_group&lt;/STRONG&gt; membership.&lt;/LI&gt;&lt;LI&gt;SAS Studio appears to inherit the primary group and AD/VAS groups, but not the local UNIX supplementary group.&lt;/LI&gt;&lt;/UL&gt;Questions&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Has anyone seen SAS Studio or Workspace Server sessions fail to inherit local UNIX supplementary groups while standard Linux login sessions work correctly?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Does the SAS Object Spawner or Workspace Server use a different mechanism for group resolution compared to a normal Linux login session?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there any known configuration required for &lt;CODE&gt;sasauth&lt;/CODE&gt;, &lt;CODE&gt;elssrv&lt;/CODE&gt;, PAM, or Quest VAS to ensure local UNIX group memberships are included in SAS Studio sessions?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Has anyone successfully used local UNIX groups for folder access in SAS Studio when the environment is integrated with Active Directory and Quest VAS?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there additional logs or diagnostics that can help identify where the local UNIX group membership is being lost during SAS session creation?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any suggestions, troubleshooting ideas, or similar experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Aug 2026 10:51:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Studio-Session-Not-Inheriting-Local-UNIX-Group-Membership/m-p/992652#M30894</guid>
      <dc:creator>bmsampath</dc:creator>
      <dc:date>2026-08-27T10:51:26Z</dc:date>
    </item>
  </channel>
</rss>

