Hi All,
I'm looking for some guidance on an issue we're experiencing in a Linux-based SAS 9.4 environment integrated with Quest Authentication Services (VAS) and Active Directory.
Issue Summary
A user has been added to a local UNIX group (local_admin_group), and Linux correctly recognises the membership.
Running the id command from a normal Linux session shows the user belongs to both the primary group and the local UNIX group. Likewise, getent group local_admin_group correctly lists the user as a member.
The target directory permissions are similar to:
drwxrws---+ sas local_admin_group
SAS Studio Behaviour
When the same user logs in through SAS Studio and executes the id command via a PIPE statement, the output shows the correct user ID and primary group, along with AD/VAS groups, but the local UNIX group (local_admin_group) is missing.
As a result, the user cannot access directories that rely on membership of the local UNIX group.
Troubleshooting Performed
Quest VAS Configuration
Updated /etc/opt/quest/vas/vas.conf by adding:
[vas_vasd]
merge-local-groups = true
Restarted the VAS daemon afterwards.
PAM Configuration
Updated /etc/pam.d/sasauth to include:
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session sufficient pam_vas3.so
session required pam_unix.so
NSS Configuration
Updated /etc/nsswitch.conf to include:
initgroups: files vas4 sss
Service Restarts
- Restarted VAS services.
- Restarted SAS services.
- Created completely new SAS Studio sessions after making the changes.
Current Status
- Linux shell sessions correctly show membership in local_admin_group.
getent group local_admin_group returns the expected membership.- SAS Studio sessions still do not show the local_admin_group membership.
- SAS Studio appears to inherit the primary group and AD/VAS groups, but not the local UNIX supplementary group.
Questions
Has anyone seen SAS Studio or Workspace Server sessions fail to inherit local UNIX supplementary groups while standard Linux login sessions work correctly?
Does the SAS Object Spawner or Workspace Server use a different mechanism for group resolution compared to a normal Linux login session?
Is there any known configuration required for sasauth, elssrv, PAM, or Quest VAS to ensure local UNIX group memberships are included in SAS Studio sessions?
Has anyone successfully used local UNIX groups for folder access in SAS Studio when the environment is integrated with Active Directory and Quest VAS?
Are there additional logs or diagnostics that can help identify where the local UNIX group membership is being lost during SAS session creation?
Any suggestions, troubleshooting ideas, or similar experiences would be greatly appreciated.
Thanks in advance.