<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrated Windows Authentication (IWA) - single sign-on failed in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250921#M4203</link>
    <description>&lt;P&gt;The Spawner and the Web App Server run under service accounts.&amp;nbsp; Under the Delegation tab in the domain controller the radio button&amp;nbsp; "Trust this user for delegation to any service (Kerberos only) is checked for both service accounts but I am still getting the error in SMC when I check IWA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2016 19:00:23 GMT</pubDate>
    <dc:creator>kdjamboe</dc:creator>
    <dc:date>2016-02-18T19:00:23Z</dc:date>
    <item>
      <title>Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250882#M4199</link>
      <description>&lt;P&gt;Has anyone gone through the configuration of IWA for windows using Kerberos?&amp;nbsp; I went through the steps but when I tested in SAS Management Console switching to use IWA I got the error below.&amp;nbsp; Anyone encounted this error?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unexpected error in function AcceptSecurityContext.&amp;nbsp; Error -2146893048 (The token supplied to the function is invalid ).&lt;BR /&gt;Access denied.&lt;BR /&gt;The application could not log on to the server "vbavd2appdev1.vba.va.gov:8564". Integrated Windows authentication failed.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 16:39:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250882#M4199</guid>
      <dc:creator>kdjamboe</dc:creator>
      <dc:date>2016-02-18T16:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250910#M4200</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a Windows domain administrator, under &lt;STRONG&gt;Start&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Control Panel&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Administrative Tools&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Active Directory Users and Computers&lt;/STRONG&gt;, access the properties dialog box for the relevant account and grant the privilege.&lt;/P&gt;
&lt;P&gt;For example, if the spawner runs under the local system account, select the spawner host machine under Computers. On the Delegation tab (or the General tab), select the Trust this computer for delegation check box.&lt;/P&gt;
&lt;P&gt;Or, if the spawner runs under a service account, select that account under Users. On the Delegation tab (or the Accounts tab), select the Account is trusted for delegation check box. This setting is available only for service accounts that have registered service principal names.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Information source:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/65011/PDF/default/bisecag.pdf" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/65011/PDF/default/bisecag.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Chapître 2 page 18 : Trusted for Delegation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 18:32:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250910#M4200</guid>
      <dc:creator>tlk</dc:creator>
      <dc:date>2016-02-18T18:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250921#M4203</link>
      <description>&lt;P&gt;The Spawner and the Web App Server run under service accounts.&amp;nbsp; Under the Delegation tab in the domain controller the radio button&amp;nbsp; "Trust this user for delegation to any service (Kerberos only) is checked for both service accounts but I am still getting the error in SMC when I check IWA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 19:00:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250921#M4203</guid>
      <dc:creator>kdjamboe</dc:creator>
      <dc:date>2016-02-18T19:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250965#M4211</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SMC connect to the metadata server, is this server trusted for delegation ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so then I guess this is one for Tech support&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Laurent&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 21:18:25 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250965#M4211</guid>
      <dc:creator>tlk</dc:creator>
      <dc:date>2016-02-18T21:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250968#M4214</link>
      <description>&lt;P&gt;Below&amp;nbsp;is the update I did in the SAS\Config\Lev1\SASMeta\MetadataServer\sasv9_usermods.cfg&amp;nbsp;file.&amp;nbsp; Is this all that is required to trust the server for delegation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Specify -secpackagelist "Kerberos" in your equivalent of the following locations:&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;SAS\Config\Lev1\SASMeta\MetadataServer\sasv9_usermods.cfg (for the metadata server) Also, make sure that the –sspi setting is present.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Restart the metadata server.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 18 Feb 2016 21:28:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250968#M4214</guid>
      <dc:creator>kdjamboe</dc:creator>
      <dc:date>2016-02-18T21:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250970#M4215</link>
      <description>&lt;P&gt;If your SAS Metadata server is on a separate machine, I guess you have to go through the process I posted first.&amp;nbsp;&amp;nbsp; All the pointer I gave you came from the SAS professional($) who help with our installation.&amp;nbsp; Our problem were the "Trusted for delegation" thing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm sorry I'm out of idea on how to help you with this, but then techsupport at SAS is usually quick and easy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Laurent&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 21:38:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/250970#M4215</guid>
      <dc:creator>tlk</dc:creator>
      <dc:date>2016-02-18T21:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251057#M4218</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that you are working with windows SAS servers. Please correct me if I am wrong here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would start from the basics, checking if IWA is set up ok on the servers (I guess they are, but if you have windows 2012, something could be missing):&amp;nbsp;&lt;A href="https://docs.secureauth.com/display/KBA/Integrated+Windows+Authentication+(IWA)+Troubleshooting&amp;nbsp;" target="_blank"&gt;https://docs.secureauth.com/display/KBA/Integrated+Windows+Authentication+(IWA)+Troubleshooting&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, if we could have some more details about your deployment, that would help. Information as: number of servers, which SAS tier on which server, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other hand, for the SAS Metadata server, Negotiate (NTLM, Kerberos) is not an option? I guess not, but I still ask, because it is simplier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Focusing on Kerberos:&lt;/P&gt;&lt;P&gt;My initial bet would go to missing SPNs (&lt;A href="https://platformadmin.com/blogs/paul/2012/04/sas-and-iwa-host-name-aliases-spns)," target="_blank"&gt;https://platformadmin.com/blogs/paul/2012/04/sas-and-iwa-host-name-aliases-spns),&lt;/A&gt; but I the same that I recommended to check the configuration of the Windows OS from the ground, regarding IWA, I would also recommend to theck the other configurations from SAS, from the ground:&amp;nbsp;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1d1zo1jsf2o0en1ehu4c4simfky.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/67045/HTML/default/viewer.htm#n1d1zo1jsf2o0en1ehu4c4simfky.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just as recommended reading, I always suggest a great SAS Paper created by&amp;nbsp;Stuart Rogers (&amp;nbsp;&lt;A href="http://support.sas.com/resources/papers/proceedings13/476-2013.pdf)" target="_blank"&gt;http://support.sas.com/resources/papers/proceedings13/476-2013.pdf)&lt;/A&gt; which also contains a lof of recommended documents to read.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 09:02:27 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251057#M4218</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2016-02-19T09:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251141#M4219</link>
      <description>&lt;P&gt;Thanks you for your help.&amp;nbsp; We are running SAS 9.4 M1 on windows 2000 R2 server.&amp;nbsp; Both mid-tier, metadata server and compute tier are all on the same machine.&amp;nbsp;&amp;nbsp; I will check out the links you included.&amp;nbsp; Thank you very much.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 14:37:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251141#M4219</guid>
      <dc:creator>kdjamboe</dc:creator>
      <dc:date>2016-02-19T14:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251142#M4220</link>
      <description>&lt;P&gt;Sorry we are running SAS 9.4 M1 on windows 2008 R2 server&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 14:38:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251142#M4220</guid>
      <dc:creator>kdjamboe</dc:creator>
      <dc:date>2016-02-19T14:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251146#M4221</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, in SAS Management Console, whow are set up the Authentication of your SAS metadata Server and your SAS workspace Server? Both Forced to Kerberos?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 14:42:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251146#M4221</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2016-02-19T14:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251167#M4222</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You asked&lt;/P&gt;&lt;P&gt;"And, in SAS Management Console, whow are set up the Authentication of your SAS metadata Server and your SAS workspace Server? Both Forced to Kerberos?"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't quite get the question.&amp;nbsp; You mean where in SMC did I set up authentication for my SAS metadata server?&amp;nbsp; In the Connection Profile I checked the IWA box, clicked on Advanced:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security Package&amp;nbsp; is Negotiate&lt;/P&gt;&lt;P&gt;SPN is Blank&lt;/P&gt;&lt;P&gt;Security package list is Kerberos,NTLM&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 15:43:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251167#M4222</guid>
      <dc:creator>kdjamboe</dc:creator>
      <dc:date>2016-02-19T15:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated Windows Authentication (IWA) - single sign-on failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251199#M4225</link>
      <description>&lt;P&gt;Thanks! That is what I needed.is good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can get a list of your registered spn with the command setspn -L your host&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you miss some spn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could try to fill the spn field that is now blank with your full qualified hostname, then restart the metadata server.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 16:29:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-Windows-Authentication-IWA-single-sign-on-failed/m-p/251199#M4225</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2016-02-19T16:29:56Z</dc:date>
    </item>
  </channel>
</rss>

