BookmarkSubscribeRSS Feed
☑ This topic is solved. Need further help from the community? Please sign in and ask a new question.
mkiran
Quartz | Level 8

I am configuring Windows server 2022 SAS 9.4 M8 new environment with IWA connections. Got all the required delegation privileges, SPN, , Keytabs created. IWA is working fine with compute and SASLogon, I do get Signin message with the  SAS Logon URL https://midtier/SASLogon/login, However SASStudio is giving an issue where my kerberos token is not being passed to compute/objectspawner to authenticate and I am getting no user credentials exists on the controller when tried to login with SASStudio URL.

 

I do have the below entries in the jass.conf file under 

SASServer1_1\conf & SASServer2_1\conf

 

        "idpropagation"="sspi"

        "sspisecuritypackagelist"="KERBEROS"

  ;

also below at end of the file:

 

com.sun.security.jgss.krb5.initiate {

   com.sun.security.auth.module.Krb5LoginModule required

   doNotPrompt=true

   principal="HTTP/[email protected]"

   useKeyTab=true

   keyTab="C:/Windows/<keytabfile>"

   storeKey=true;

};

 

com.sun.security.jgss.krb5.accept {

   com.sun.security.auth.module.Krb5LoginModule required

   doNotPrompt=true

   principal="HTTP/[email protected]"

   useKeyTab=true

   keyTab="C:/Windows/<keytabfile>"

 storeKey=true;

};

 

server.xml has been updated with below

Replaced below

<Realm className="org.apache.catalina.realm.UserDatabaseRealm"
resourceName="UserDatabase"/>

with this:

<Realm className="com.sas.vfabrictcsvr.realm.GSSContextEstablishedRealm"
       allRolesMode="authOnly"/>


Metadata login has two entries for the user with respective authdomains one with Defaultauth (user@doamin) and one with "web" (user) 


We do have the other environment working with the same configuration but this is not authenticating me and throwing sspi errors, 

 

SSPI error on SASStudio3.82 log 

2026-07-16 20:57:03,721 ERROR [tomcat-http--8] auth.AuthenticationProviderWIP (AuthenticationProviderWIP.java:96) - Unable to connect to workspace.
java.lang.IllegalStateException: com.sas.security.sspi.SSPIAuthException
at com.sas.iom.orb.brg.SecurityPackageBase.getDelegatedAuth(SecurityPackageBase.java:187)
at com.sas.iom.orb.brg.SecurityPackageBase.initClient(SecurityPackageBase.java:56)
at com.sas.iom.orb.brg.Engine.createSecurityPackage(Engine.java:5551)
at com.sas.iom.orb.brg.Engine.flowSendAuth(Engine.java:4319)
at com.sas.iom.orb.brg.Engine.flow(Engine.java:724)
at com.sas.iom.orb.brg.Engine.initClient(Engine.java:683)

 

 

SASLogon log reporting the below main error:

 

 

2026-07-16 20:56:53,560 [tomcat-http--41] WARN  javax.persistence.spi - javax.persistence.spi::No valid providers found.
2026-07-16 20:56:54,374 [tomcat-http--41] WARN  org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136
2026-07-16 20:56:54,375 [tomcat-http--41] WARN  org.apereo.cas.web.support.gen.CookieRetrievingCookieGenerator - InvalidCookieException
DefaultCasCookieValueManager.java:obtainValueFromCompoundCookie:102
EncryptedCookieValueManager.java:obtainCookieValue:51
CookieValueManager.java:obtainCookieValue:35
 
2026-07-16 20:56:54,386 [tomcat-http--41] WARN  org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136
2026-07-16 20:56:54,387 [tomcat-http--41] WARN  org.apereo.cas.web.support.gen.CookieRetrievingCookieGenerator - InvalidCookieException
DefaultCasCookieValueManager.java:obtainValueFromCompoundCookie:102
EncryptedCookieValueManager.java:obtainCookieValue:51
CookieValueManager.java:obtainCookieValue:35
 
2026-07-16 20:56:54,421 [tomcat-http--41] WARN  org.apereo.cas.authentication.attribute.PrincipalAttributeRepositoryFetcher - No person records were fetched from attribute repositories for [{principal=user, credentialClass=[PrincipalBearingCredential], credentialId=[user], username=user}]
2026-07-16 20:56:54,427 [tomcat-http--41] INFO  org.apereo.cas.authentication.DefaultAuthenticationManager - Authenticated principal [user] with attributes [{}] via credentials [[PrincipalBearingCredential(super=AbstractCredential(), principal=SimplePrincipal(id=user, attributes={}))]].
2026-07-16 20:56:54,681 [tomcat-http--41] WARN  org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136
2026-07-16 20:56:54,682 [tomcat-http--41] WARN  org.apereo.cas.web.support.gen.CookieRetrievingCookieGenerator - InvalidCookieException
DefaultCasCookieValueManager.java:obtainValueFromCompoundCookie:102
EncryptedCookieValueManager.java:obtainCookieValue:51
CookieValueManager.java:obtainCookieValue:35
 
1 ACCEPTED SOLUTION

Accepted Solutions
mkiran
Quartz | Level 8

@JuanS_OCS : Original issue was with the service account delegation privileges , IAM misconfigured these privileges and I got them corrected.

I saw No person records fetched entries in SASLogon9.4.log that gave me a hint of SASServer1_1 also not working well even though it gives me the message (you are signed in) - its a false positive message.

Issue got resolved after correcting delegation properties on the service account.

View solution in original post

3 REPLIES 3
JuanS_OCS
Azurite | Level 17
Hi there,
It seems to me you got SSO working well in SASServer1_1 via IWA/Kerberos.
However: did you configure it as well what is needed in SASServer2_1, where SASStudio lives? And, did you configure SSO with IWA/Kerberos in your SAS Metadata and Object Spawner/Workspace and Pooled Workspace servers?
Mind:
You need to prioritize IWA via Kerberos rather than NTLM (maybe just remove NTLM)
Depending on your configuration if it’s GRID, SASStudio may launch 2 sas.exe sessions per SASStudio session: an “spawner” or “launcher” and your actual Workspace. Both need the SSO via Kerberos/IWA.
Pleas search for @StuartRogers entries about Kerberos and SSO in SAS 9.4 or the advanced authentication and security topics for 9.4 in SAS VLE site, they are priceless.
mkiran
Quartz | Level 8

@JuanS_OCS : Original issue was with the service account delegation privileges , IAM misconfigured these privileges and I got them corrected.

I saw No person records fetched entries in SASLogon9.4.log that gave me a hint of SASServer1_1 also not working well even though it gives me the message (you are signed in) - its a false positive message.

Issue got resolved after correcting delegation properties on the service account.

JuanS_OCS
Azurite | Level 17
In addition, look at this piece:

org.apereo.cas.web.support.mgmr.DefaultCasCookieValueManager - Invalid cookie. Required remote address 10.158.237.138 does not match 10.158.237.136

Do you know what those are? It seems as may be one of the many causes why it’s not working, in CAS. Should I assume one is web and the other is your compute?

suga badge.PNGThe SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment. 

Join SUGA 

Get Started with SAS Information Catalog in SAS Viya

Learn how to explore data assets, create new data discovery agents, schedule data discovery agents, and much more.

Find more tutorials on the SAS Users YouTube channel.

Discussion stats
  • 3 replies
  • 235 views
  • 0 likes
  • 2 in conversation