<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAS 9.4 GRID authentication with PAM in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237065#M3663</link>
    <description>&lt;P&gt;We are trying to configure PAM (with samba) with our SAS 9.4 installation in a RedHat x64 server.But &lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;when users try to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;enter and error appears:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;[Error] The launch of server SASApp - Workspace Server for user XXX failed.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;we noticed that this error appers because the users don´t have home directory.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;Does anyone has had the same problem&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;&lt;IMG src="https://communities.sas.com/t5/image/serverpage/image-id/12104i6526413FB6A91798/image-size/large?v=1.0&amp;amp;px=600" border="0" alt="grid.JPG" title="grid.JPG" /&gt;</description>
    <pubDate>Mon, 30 Nov 2015 22:26:44 GMT</pubDate>
    <dc:creator>Armando1</dc:creator>
    <dc:date>2015-11-30T22:26:44Z</dc:date>
    <item>
      <title>SAS 9.4 GRID authentication with PAM</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237065#M3663</link>
      <description>&lt;P&gt;We are trying to configure PAM (with samba) with our SAS 9.4 installation in a RedHat x64 server.But &lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;when users try to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;enter and error appears:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;[Error] The launch of server SASApp - Workspace Server for user XXX failed.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;we noticed that this error appers because the users don´t have home directory.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN class="hps"&gt;Does anyone has had the same problem&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;&lt;IMG src="https://communities.sas.com/t5/image/serverpage/image-id/12104i6526413FB6A91798/image-size/large?v=1.0&amp;amp;px=600" border="0" alt="grid.JPG" title="grid.JPG" /&gt;</description>
      <pubDate>Mon, 30 Nov 2015 22:26:44 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237065#M3663</guid>
      <dc:creator>Armando1</dc:creator>
      <dc:date>2015-11-30T22:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 GRID authentication with PAM</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237080#M3664</link>
      <description>&lt;P&gt;There are PAM modules that can create a home directory on demand when required. I have&amp;nbsp;oddjob-mkhomedir installed to do this, but there is also&amp;nbsp;pam_mkhomedir. I use realmd&amp;nbsp;for AD backed PAM authentication&amp;nbsp;and&amp;nbsp;&lt;SPAN&gt;oddjob-mkhomedir is installed along the way - if you are interested in that approach I wrote a blog post about it at &lt;A href="http://platformadmin.com/blogs/paul/2015/07/active-directory-authentication-for-sas-on-linux-with-realmd/" target="_blank"&gt;http://platformadmin.com/blogs/paul/2015/07/active-directory-authentication-for-sas-on-linux-with-realmd/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 00:14:33 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237080#M3664</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-12-01T00:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 GRID authentication with PAM</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237198#M3669</link>
      <description>&lt;P&gt;Hi Paul, thnx for your answer.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;I tried to make the configuration with the two PAM modules oddjob-mkhomedir and pam_mkhomedir, but all the test was unsuseful.&lt;BR /&gt;&lt;BR /&gt;I share with you the contents of my sasauth file&lt;BR /&gt;&lt;BR /&gt;#############################################&lt;BR /&gt;&lt;BR /&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; required&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_env.so&lt;BR /&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sufficient&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_winbind.so&lt;BR /&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sufficient&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_unix.so nullok try_first_pass&lt;BR /&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; requisite&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_succeed_if.so uid &amp;gt;= 500 quiet&lt;BR /&gt;auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; required&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_deny.so&lt;BR /&gt;&lt;BR /&gt;account&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; required&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_unix.so&lt;BR /&gt;account&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sufficient&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_succeed_if.so uid &amp;lt; 500 quiet&lt;BR /&gt;account&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; required&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_permit.so&lt;BR /&gt;&lt;BR /&gt;session&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; required&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pam_mkhomedir.so skel=/etc/skel umask 0022 silent&lt;BR /&gt;&lt;BR /&gt;########################################################&lt;BR /&gt;&lt;BR /&gt;in addition to this file, they we configured the ga_auth and the eauth_userpass in the directory /etc/pam.d according with this SAS notes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.sas.com/kb/49/724.html" target="_blank"&gt;http://support.sas.com/kb/49/724.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://support.sas.com/kb/49/732.html" target="_blank"&gt;http://support.sas.com/kb/49/732.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 16:36:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237198#M3669</guid>
      <dc:creator>Armando1</dc:creator>
      <dc:date>2015-12-01T16:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 GRID authentication with PAM</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237518#M3673</link>
      <description>&lt;P&gt;I looked into this further today and did some testing and it seems that pam_oddjob_mkhomedir is not&amp;nbsp;firing from the sasauth PAM&amp;nbsp;config. &amp;nbsp;Whilst I can succesfully have home directories auto-created,&amp;nbsp;via&amp;nbsp; pam_oddjob_mkhomedir, when using ssh and su, it is not working for sasauth. Digging into this further it looks like&amp;nbsp;perhaps sasauth as used by the object spawner is not triggering the &lt;EM&gt;session&lt;/EM&gt;&amp;nbsp;initialization where&amp;nbsp;pam_oddjob_mkhomedir does its work (as does pam_mkhomedir).&amp;nbsp;There are 2 things that&amp;nbsp;seem to suggest this: 1) All of the PAM config samples I have seen in the SAS documentation and usage notes only include the &lt;EM&gt;auth&lt;/EM&gt; and &lt;EM&gt;account&lt;/EM&gt; groups (I have&amp;nbsp;session in my config for testing) 2) the sasauth.conf file has a section related to PAM_SETCREDENTIALS and Centrify where it&amp;nbsp;says: "&lt;EM&gt;Centrify requires that pam_setcred be called. sasauth traditionally has not done this, since there's no "session" like an interactive login&lt;/EM&gt;." Perhaps it is not using pam_open_session either? Whilst I can understand that there might not be&amp;nbsp;a&amp;nbsp;session&amp;nbsp;when sasauth is used by the SAS Metadata Server, when it is used by the SAS Object Spawner to spawn sas processes as that user, that sounds like a session to me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An alternative to auto-creating the home directories via PAM is to create them during any enterprise directory identity synchronization process you may have set up&amp;nbsp;(e.g. Active Directory to SAS metadata).&amp;nbsp;Having shared home directories via&amp;nbsp;NFS or clustered&amp;nbsp;file system will help here too.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 03:24:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237518#M3673</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2015-12-03T03:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 GRID authentication with PAM</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237972#M3689</link>
      <description>&lt;P&gt;That not working of generic PAM modules makes sense as SAS did rewrite the SSH method by their own&amp;nbsp;and missing a lot of all low level settings to adjust those for common Unix administration.&amp;nbsp;Did you know the metdata login process is single threaded and can be compromised by wait delays as set by those low level ones? Having weird effects of logins delaying for a long time that is a possible cause.&amp;nbsp;Why would you delay logins? It is a protection against mass tries for passwords.&amp;nbsp; Don't use the delay setting of SAS as that is their own internal delay not the one of the OS (another cause of confusing).&lt;BR /&gt;&lt;BR /&gt;By the way Samba is often adviced for a quick connection between Unix/Windows. It&amp;nbsp; is not&amp;nbsp; very sensible as of security issues.&lt;BR /&gt;The reason is the limit as of auth_sys being hard on 16. &lt;A href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Storage_Administration_Guide/s1-nfs-security.html&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;" target="_blank"&gt;https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Storage_Administration_Guide/s1-nfs-security.html&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2015 20:25:54 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/237972#M3689</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-12-05T20:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 GRID authentication with PAM</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/352817#M8366</link>
      <description>&lt;P&gt;I'd forgotten this comment I posted back in 2015 and only remembered it after seeing it in some Google results whilst researching the very same issue today! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I spent some more time looking into it and found a solution that I described in a blog post at &lt;A href="https://platformadmin.com/blogs/paul/2017/04/sas-user-linux-home-dir-auto-creation/&amp;nbsp;" target="_blank"&gt;https://platformadmin.com/blogs/paul/2017/04/sas-user-linux-home-dir-auto-creation/&amp;nbsp;&lt;/A&gt; I'm adding a link here in case someone else has this problem in future and finds this thread.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 12:41:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-GRID-authentication-with-PAM/m-p/352817#M8366</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2017-04-24T12:41:53Z</dc:date>
    </item>
  </channel>
</rss>

