I am working on setting up Integrated Windows Authentication (IWA) for SAS Studio and related web applications. Before proceeding further, I would like to confirm some prerequisites regarding SPNs and delegation configuration in Active Directory.
We plan to use three separate domain service accounts for SAS services:
Below are the SPNs currently registered:
ACCOUNT1_META
SAS/aSASSTU-met.XXX.xx
SAS/aSASSTU-met
ACCOUNT2_MID
HTTP/aSASSTU-mid.XXX.xx
HTTP/aSASSTU-mid
ACCOUNT3_COMP
SAS/aSASSTU-comp.XXX.xx
SAS/aSASSTU-comp
Since our deployment spans multiple machines, is it acceptable to use different service accounts and register SPNs only for their respective hosts? Specifically:
Your guidance on best practices for SPN registration and delegation in this multi-tier SAS environment would be greatly appreciated.
We have also three separate accounts.
And we have implemented AllowToDelegateTo:
@LinusH do you mean this delegation
Midtier account should delegate to midtier host as well compute host? and compute account to own and http as well?
Also, I have a question regarding the point where mentioned in document for midtier configuration about SPNEGO option and as the auth-method in the web.xml file for SAS Logon Manager.
SAS Help Center: Support for Integrated Windows Authentication
do we need to configure browser settings when we go with SPNEGO option? as per below suggestions. For example, we have MS Edge.
Configure Google Chrome and Microsoft Edge to Use SPNEGO
@LinusH have you done this configuration Configure Google Chrome and Microsoft Edge to Use SPNEGO additionally to allow SPNEGO option.
The SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment.
Learn how to explore data assets, create new data discovery agents, schedule data discovery agents, and much more.
Find more tutorials on the SAS Users YouTube channel.