I am configuring Windows server 2022 SAS 9.4 M8 new environment with IWA connections. Got all the required delegation privileges, SPN, , Keytabs created. IWA is working fine with compute and SASLogon, I do get Signin message with the SAS Logon URL https://midtier/SASLogon/login, However SASStudio is giving an issue where my kerberos token is not being passed to compute/objectspawner to authenticate and I am getting no user credentials exists on the controller when tried to login with SASStudio URL.
I do have the below entries in the jass.conf file under
SASServer1_1\conf & SASServer2_1\conf
"idpropagation"="sspi"
"sspisecuritypackagelist"="KERBEROS"
;
also below at end of the file:
com.sun.security.jgss.krb5.initiate {
com.sun.security.auth.module.Krb5LoginModule required
doNotPrompt=true
principal="HTTP/[email protected]"
useKeyTab=true
keyTab="C:/Windows/<keytabfile>"
storeKey=true;
};
com.sun.security.jgss.krb5.accept {
com.sun.security.auth.module.Krb5LoginModule required
doNotPrompt=true
principal="HTTP/[email protected]"
useKeyTab=true
keyTab="C:/Windows/<keytabfile>"
storeKey=true;
};
server.xml has been updated with below
Replaced below
<Realm className="org.apache.catalina.realm.UserDatabaseRealm"
resourceName="UserDatabase"/>
with this:
<Realm className="com.sas.vfabrictcsvr.realm.GSSContextEstablishedRealm"
allRolesMode="authOnly"/>
Metadata login has two entries for the user with respective authdomains one with Defaultauth (user@doamin) and one with "web" (user)
We do have the other environment working with the same configuration but this is not authenticating me and throwing sspi errors,
SSPI error on SASStudio3.82 log
SASLogon log reporting the below main error:
@JuanS_OCS : Original issue was with the service account delegation privileges , IAM misconfigured these privileges and I got them corrected.
I saw No person records fetched entries in SASLogon9.4.log that gave me a hint of SASServer1_1 also not working well even though it gives me the message (you are signed in) - its a false positive message.
Issue got resolved after correcting delegation properties on the service account.
@JuanS_OCS : Original issue was with the service account delegation privileges , IAM misconfigured these privileges and I got them corrected.
I saw No person records fetched entries in SASLogon9.4.log that gave me a hint of SASServer1_1 also not working well even though it gives me the message (you are signed in) - its a false positive message.
Issue got resolved after correcting delegation properties on the service account.
The SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment.
Learn how to explore data assets, create new data discovery agents, schedule data discovery agents, and much more.
Find more tutorials on the SAS Users YouTube channel.