<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAS Token Authentication - launch credential must be group account? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247076#M3966</link>
    <description>&lt;P&gt;The lasradm would have to be an account that is known to the operating system (so cannot be a SAS internal account) as it will be the process owner of your&amp;nbsp;SAS Token Authentication configured workspace servers. It can still be used to sign in to metadata but will take on a group identity rather than a user identity. This is the same as the pooled workspace servers and stored process servers - when they initialize they connect to the metadata server as&amp;nbsp;sassrv, are identified as the SAS General Servers group, and have that group's access during initialization to pre-assign metadata libraries etc (later on in their&amp;nbsp;life the connecting user identities&amp;nbsp;will&amp;nbsp;used for access but sassrv is used early on). The identity for sassrv&amp;nbsp;has to be group (instead of a user) so that the SAS Trusted User can be a member of the group to get the necessary access to&amp;nbsp;the same metadata-stored credentials to start the servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try this out yourself if you know the password for sassrv. Log in to SAS MC using sassrv and, looking on the status bar at the bottom of the window, you will see you are identified as SAS General Servers (group not user). You can do the same with lasradm. Create your lasradm account in the operating system (or AD/LDAP), add the user id and password&amp;nbsp;to the SAS General Servers group, restart/refresh the SAS Object Spawner, then log into SAS MC as lasradm and you will see the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One potential reason to use a group other than SAS General Servers is the shared group metadata identity with sassrv. When you grant the necessary metadata permissions for lasradm (via SAS General Servers) you will also be granting access to sassrv. If this is not what you want then consider creating another group similar to SAS General Servers just for lasradm then make SAS Trusted User a member of that group so it has acess to the credentials. Then ensure that group has appropriate effective permissions as required for lasradm.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Jan 2016 00:42:07 GMT</pubDate>
    <dc:creator>PaulHomes</dc:creator>
    <dc:date>2016-01-31T00:42:07Z</dc:date>
    <item>
      <title>SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247040#M3963</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup SAS Token Authentication on my workspace server.&lt;/P&gt;&lt;P&gt;I can't find it in the SAS documentation but it looks like the launch credential must be a metadata &lt;U&gt;&lt;STRONG&gt;group&lt;/STRONG&gt;&lt;/U&gt;'s account.&lt;/P&gt;&lt;P&gt;when i set it to a metadata &lt;U&gt;&lt;STRONG&gt;user&lt;/STRONG&gt;&lt;/U&gt;'s account, i get the message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;The application could not log on to the server "sasserver01:8591".
The user ID "sasadm@!*(generatedpassworddomain)*!" or the password is incorrect.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone confirm this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Bart&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2016 17:34:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247040#M3963</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2016-01-30T17:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247058#M3964</link>
      <description>&lt;P&gt;Hi Bart,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The launch credentials need to be available to the SAS Trusted User (sastrust@saspw) because that is the identity that the SAS Object Spawner uses for its connection to the metadata server. As with any user in metadata, the SAS Trusted User has access to any shared credentials on any of the groups it is a member of. In a standard SAS deployment the SAS General Servers group acts as a credential container for the SAS Trusted User. The SAS Trusted User is a member of that group (and usually the only member). You will find the sassrv userid and password already stored in that group (as used to launch stored process and pooled workspace servers). I would suggest you add&amp;nbsp;the new launch credential to the SAS General Servers group as that will then make it available to the SAS Trusted User.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2016 21:23:28 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247058#M3964</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2016-01-30T21:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247065#M3965</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your explanation.&lt;/P&gt;&lt;P&gt;So that means it can't work with a metadata user's account, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reason I am looking into this is that i want to use lasradm as the launch credential for the SASApp Workspace Server but i also want to run SAS VA autoload scripts and scheduled visual data builder scripts under&amp;nbsp;the lasradm linux account.&lt;/P&gt;&lt;P&gt;To run the linux scripts under the lasradm linux account, lasradm must be able to bind to the metadata server as a sas metadata &lt;EM&gt;user&amp;nbsp;&lt;/EM&gt;that has the lasradm@defaultauth account specified. but token authentication does not work with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have a way to get this working with just lasradm?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Bart&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2016 22:47:33 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247065#M3965</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2016-01-30T22:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247076#M3966</link>
      <description>&lt;P&gt;The lasradm would have to be an account that is known to the operating system (so cannot be a SAS internal account) as it will be the process owner of your&amp;nbsp;SAS Token Authentication configured workspace servers. It can still be used to sign in to metadata but will take on a group identity rather than a user identity. This is the same as the pooled workspace servers and stored process servers - when they initialize they connect to the metadata server as&amp;nbsp;sassrv, are identified as the SAS General Servers group, and have that group's access during initialization to pre-assign metadata libraries etc (later on in their&amp;nbsp;life the connecting user identities&amp;nbsp;will&amp;nbsp;used for access but sassrv is used early on). The identity for sassrv&amp;nbsp;has to be group (instead of a user) so that the SAS Trusted User can be a member of the group to get the necessary access to&amp;nbsp;the same metadata-stored credentials to start the servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try this out yourself if you know the password for sassrv. Log in to SAS MC using sassrv and, looking on the status bar at the bottom of the window, you will see you are identified as SAS General Servers (group not user). You can do the same with lasradm. Create your lasradm account in the operating system (or AD/LDAP), add the user id and password&amp;nbsp;to the SAS General Servers group, restart/refresh the SAS Object Spawner, then log into SAS MC as lasradm and you will see the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One potential reason to use a group other than SAS General Servers is the shared group metadata identity with sassrv. When you grant the necessary metadata permissions for lasradm (via SAS General Servers) you will also be granting access to sassrv. If this is not what you want then consider creating another group similar to SAS General Servers just for lasradm then make SAS Trusted User a member of that group so it has acess to the credentials. Then ensure that group has appropriate effective permissions as required for lasradm.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 00:42:07 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247076#M3966</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2016-01-31T00:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247078#M3967</link>
      <description>&lt;P&gt;SAS best practice is to use&amp;nbsp;lasradm as the OS account for the VA Data Administrators group and use that as the launch credential for token authentication.&lt;/P&gt;&lt;P&gt;But like i wrote before, if i do this i can no longer use lasradm on the OS to run autoload or visual data builder scripts, since not every VA Data Administrator is allowed to load all LASR data anywhere.&amp;nbsp;hm..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 01:05:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247078#M3967</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2016-01-31T01:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247082#M3968</link>
      <description>&lt;P&gt;If you already have lasradm on the Accounts tab of the VA Data Administrators group, then if you test a&amp;nbsp;login with lasradm using SAS MC then you should see it identified as the&amp;nbsp;&lt;SPAN&gt;VA Data Administrators group.&amp;nbsp;If this is how you have it configured, when you run jobs in the OS as lasradm and connect to metadata as lasradm then that metadata connection will be identified as the&amp;nbsp;&lt;SPAN&gt;VA Data Administrators group (for access control purposes). &amp;nbsp;Furthermore, if the lasradm account is&amp;nbsp;&lt;SPAN&gt;on the Accounts tab of the VA Data Administrators group and also has it's password stored there, if the SAS Trusted User were made a member of the&amp;nbsp;&lt;SPAN&gt;VA Data Administrators group, then the SAS Object Spawner through the SAS Trusted User (along with everyone else who is already a&amp;nbsp;member of that group) would have access to those credentials. That would enable the&amp;nbsp;&lt;SPAN&gt;SAS Object Spawner to start SAS Token Authentication configured workspace servers using those lasradm credentials. I just tested it and it works for me.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;But as you say, that would mean (at the metadata layer) the lasradm identity could not have any more access than any other members of the&amp;nbsp;&lt;SPAN&gt;VA Data Administrators group - because it is the group. I haven't had a need to try it myself, but in this situation I would consider moving lasradm credentials into another group (with SAS Trusted User as a member) and making that group a member of&amp;nbsp;&lt;SPAN&gt;VA Data Administrators. The lasradm account keeps the access it had before&amp;nbsp;because of its&amp;nbsp;&lt;SPAN&gt;VA Data Administrators group membership but now has it's own identity which could be granted&amp;nbsp;additional access beyond the&amp;nbsp;&lt;SPAN&gt;VA Data Administrators group. It does however mean that the existing members of&amp;nbsp;&lt;SPAN&gt;VA Data Administrators would lose access to the lasradm credentials which they might be using for other purposes. Alternatively perhaps those existing members of&amp;nbsp;&lt;SPAN&gt;VA Data Administrators that need less access could be extracted into a different lower privileged&amp;nbsp;group?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;I'm only throwing ideas out there. I don't know if they will work for you or cause problems for you because I don't have a deep understanding of your implementation and usage patterns (which is beyond the scope of this thread). However, I hope it still helps in some way.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 01:58:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/247082#M3968</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2016-01-31T01:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357009#M8540</link>
      <description>&lt;P&gt;Hi Paul,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to setup LDAP direct authentication and when i try to validate the workspace server &amp;nbsp;i see the same error as described in this track.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAS General services have the sassrv account and SAS Trusted user is part of the Member for it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you said i cannot add&amp;nbsp;&lt;SPAN&gt;sastrust@saspw to the&amp;nbsp;SAS General services.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am missing anything here. can you help me on this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 20:19:13 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357009#M8540</guid>
      <dc:creator>ravi15</dc:creator>
      <dc:date>2017-05-08T20:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357123#M8544</link>
      <description>&lt;P&gt;I assume you have configured direct LDAP authentication with the SAS metadata server and want to use SAS Token Authentication for the SAS Workspace Server because you don't want to, or cannot, setup the operating system to do LDAP authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that case you will need to ensure that 1) the logical workspace server configuration is&amp;nbsp;changed, in metadata, to SAS Token Authentication; 2) appropriate launch credentials (such as sassrv) are stored in metadata so that the SAS Trusted User has access to them (usually by adding the userid and password to the SAS General Servers group); 3) the workspace server is configured to use those launch credentials; and 4) the SAS Object Spawner is restarted or refreshed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More information is provided in the &lt;A href="https://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p06o3ymf2cuw16n1cmyi47t9icsn.htm" target="_self"&gt;How to Configure SAS Token Authentication&lt;/A&gt;&amp;nbsp;section of the&amp;nbsp;&lt;EM&gt;SAS 9.4 Intelligence Platform: Security Administration Guide.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 11:14:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357123#M8544</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2017-05-09T11:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357344#M8555</link>
      <description>&lt;P&gt;The launch credential is not required to be a group account. I would suggest reviewing the bullet points for selecting a login under the topic " Criteria for a Designated Launch Credential. "&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p18wh3fg2jlhegn0zm24njz1lz7e.htm#n0gvk8m21gslxln16zo7mruves51" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p18wh3fg2jlhegn0zm24njz1lz7e.htm#n0gvk8m21gslxln16zo7mruves51&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 00:34:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357344#M8555</guid>
      <dc:creator>Madelyn_SAS</dc:creator>
      <dc:date>2017-05-10T00:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357349#M8557</link>
      <description>&lt;P&gt;Noted, however I do notice that the&amp;nbsp;SAS documentation has:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;You can choose to configure variations (for example, create a group other than the SAS General Servers group to hold logins for launch credentials). In general, such variations are not recommended because they unnecessarily increase complexity and reduce consistency.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I only recommend adding any additional&amp;nbsp;launch credentials to the SAS General Servers group on the basis that, being consistent with the pre-configured setup of a new SAS installation, it would be immediately familiar to many&amp;nbsp;SAS administrators.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 01:00:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357349#M8557</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2017-05-10T01:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357357#M8558</link>
      <description>Thank you very much issue solved.</description>
      <pubDate>Wed, 10 May 2017 02:00:15 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357357#M8558</guid>
      <dc:creator>ravi15</dc:creator>
      <dc:date>2017-05-10T02:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357358#M8559</link>
      <description>Thank you very much.</description>
      <pubDate>Wed, 10 May 2017 02:00:39 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/357358#M8559</guid>
      <dc:creator>ravi15</dc:creator>
      <dc:date>2017-05-10T02:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/386780#M9996</link>
      <description>&lt;P&gt;The message that was marked as a solution should not be marked as a solution because it is not the solution to the original question.&lt;/P&gt;&lt;P&gt;I have seen&amp;nbsp;the documentation but when I set the launch account to a metadata user account; it does not work.&lt;/P&gt;&lt;P&gt;I get the error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;The application could not log on to the server "sasserver01:8591".
The user ID "sasadm@!*(generatedpassworddomain)*!" or the password is incorrect.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please unmark the message as a solution.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 19:28:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/386780#M9996</guid>
      <dc:creator>bheinsius</dc:creator>
      <dc:date>2017-08-09T19:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/386790#M9997</link>
      <description>&lt;P&gt;It looks like you are trying to use sasadm@saspw to launch the workspace server. Internal accounts cannot be used for that purpose.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 19:44:44 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/386790#M9997</guid>
      <dc:creator>Madelyn_SAS</dc:creator>
      <dc:date>2017-08-09T19:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/386875#M10000</link>
      <description>&lt;P&gt;I get the same error when, logged in as the SAS Administrator (sasadm@saspw), I try to launch a SAS Workpsace Server that has been configured for&amp;nbsp;SAS Token Authentication&amp;nbsp;when the launch credentials are inaccessible to the metadata identity used by the SAS Object Spawner. The following is also seen in the SAS Object Spawner log file:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2017-08-10T16:33:01,079 ERROR [00000993] :sasadm@saspw - No host credentials exist to start this server. Either the client needs to send in host credentials, or credentials need to be specified for the server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To replicate this I did the following as SAS Administrator (sasadm@saspw) in SAS Management Console:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In User Manager, for a user identity in metadata (Alice), I made sure a valid user id and password were specified in the Accounts tab (demoalice + password).&lt;/LI&gt;
&lt;LI&gt;In Server Manager, modified the SAS Logical Workspace Server to select SAS Token Authentication&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In Server Manager,&amp;nbsp;m&lt;/SPAN&gt;odified the SAS Workspace Server to select demoalice as the Launch Credentials&lt;/LI&gt;
&lt;LI&gt;In Server Manager, expand Object Spawner, Connect to the host and Refresh Spawner.&lt;/LI&gt;
&lt;LI&gt;Validate the&amp;nbsp;&lt;SPAN&gt;SAS Logical Workspace Server - it fails with Bart's error (and the above in the object spawner log file).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;The problem lies in the fact that the SAS Object Spawner logs into the SAS Metadata Server as the SAS Trusted User (sastrust@saspw) identity which doesn't have access to any credentials that are not in it's identitiy hierarchy (SAS Trusted User, SAS System Services, SAS General Services, SASUSERS, PUBLIC) - i.e it cannot get acess to the credentials&amp;nbsp;on the Alice user identity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Move the credentials to the SAS Trusted Identity and it works.&amp;nbsp;A&lt;/SPAN&gt;s SAS Administrator (sasadm@saspw) in SAS Management Console:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In User Manager, edit the Alice user identity in metadata and remove the credentials from the Accounts tab (demoalice + password).&lt;/LI&gt;
&lt;LI&gt;In User Manager, edit the&lt;SPAN&gt;&amp;nbsp;SAS Trusted User&amp;nbsp;&lt;/SPAN&gt;identity in metadata and add&amp;nbsp;the demoalice credentials in&amp;nbsp;the Accounts tab (demoalice + password).&lt;/LI&gt;
&lt;LI&gt;In Server Manager,&amp;nbsp;modify the SAS Workspace Server to (re)select demoalice as the Launch Credentials.&lt;/LI&gt;
&lt;LI&gt;In Server Manager, expand Object Spawner, Connect to the host and Refresh Spawner.&lt;/LI&gt;
&lt;LI&gt;Validate the&amp;nbsp;&lt;SPAN&gt;SAS Logical Workspace Server and it now works with the following seen in the SAS Object Spawner log file:&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;2017-08-10T16:36:28,494 INFO [00001059] :sasadm@saspw - New client connection (116) accepted from server port 8591 for SAS token user sasadm@saspw. Encryption level is Credentials using encryption algorithm AES. Peer IP address and port are [192.168.22.1]:40096 for APPNAME=ConnectionService 904400.&lt;BR /&gt;2017-08-10T16:36:28,510 INFO [00001059] :sasadm@saspw - Created process 9170 using credentials demoalice for user sasadm@saspw (child id 32).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Of course, with this config it also means that if someone logs into metadata using the demoalice user id and password then they take on the SAS Trusted User identity, a highly privileged user. It is safer to put the demoalice credentials on a group&amp;nbsp;that the SAS Trusted User is a member of, such as SAS General Servers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bart, does this help describe the issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Paul&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 06:56:39 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/386875#M10000</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2017-08-10T06:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/387009#M10004</link>
      <description>&lt;P&gt;Note that SAS does not recommend modifying the membership of the SAS General Servers group.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n07km0roa3fnpfn1oibcl5kkik9a.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n07km0roa3fnpfn1oibcl5kkik9a.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, SAS Trust is a highly privileged user and SAS does not recommend modifying this user either&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n1wyid30nrcynhn1q1okc7z8jmcs.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#n1wyid30nrcynhn1q1okc7z8jmcs.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should be able to select an account to use for token authentication by choosing an account that meets the criteria for a launch credential.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p18wh3fg2jlhegn0zm24njz1lz7e.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/69827/HTML/default/viewer.htm#p18wh3fg2jlhegn0zm24njz1lz7e.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most customers would use the Login for the SAS General Servers group (SASSRV, by default) as the account to use for token authentication for the standard workspace server.&amp;nbsp;This account is already used by the Stored Process Server and the Pooled Workspace Server, so it meets the criteria.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a reason why you do not want to use the SASSRV account?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 14:11:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/387009#M10004</guid>
      <dc:creator>Madelyn_SAS</dc:creator>
      <dc:date>2017-08-10T14:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/387012#M10005</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all for your help. Issue is resolved. I am using SASSRV account to launch the work space server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i noticed that all the Sessions and files in work directory are now owned with SASSRV account. is there a way which directories in SASWork are associated to which SAS Session. We have SAS Grid and all the jobs are have SASSRV user as owner. I cannot find which job is related to the SASWORK director in case if any one consuming more space in SASWORK location i cannot kill the corresponding JOB.Any thoughts on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for all your responses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ravi.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 14:17:58 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/387012#M10005</guid>
      <dc:creator>Teja</dc:creator>
      <dc:date>2017-08-10T14:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/387233#M10013</link>
      <description>&lt;P&gt;The process number of the process owning a WORK directory is coded into the directory name, in hexadecimal notation. Use a converter like&amp;nbsp;&lt;A href="https://www.easycalculation.com/hex-converter.php" target="_blank"&gt;https://www.easycalculation.com/hex-converter.php&lt;/A&gt; to show the decimal values of the portions of the directory name.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 06:32:33 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/387233#M10013</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-08-11T06:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/389958#M10160</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the directory name i see in the saswork&lt;/P&gt;&lt;P&gt;SAS_workBDE70000148D_usflsas1.wst.corproot.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BDE70000148D if this is the HEX value when i convert it to decimal&amp;nbsp;208799835100301. this is too big for the JOBID.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anything i am missing here.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 18:15:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/389958#M10160</guid>
      <dc:creator>ravi15</dc:creator>
      <dc:date>2017-08-22T18:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: SAS Token Authentication - launch credential must be group account?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/389981#M10162</link>
      <description>&lt;P&gt;It's either the first or second half of the hex-coded part. Just play around a little with the values till you get a valid existing process number.&lt;/P&gt;
&lt;P&gt;(I have no access to the SAS server at the moment)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 18:58:39 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-Token-Authentication-launch-credential-must-be-group-account/m-p/389981#M10162</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-08-22T18:58:39Z</dc:date>
    </item>
  </channel>
</rss>

