BookmarkSubscribeRSS Feed
bmsampath
Quartz | Level 8

Hi All,

I'm looking for some guidance on an issue we're experiencing in a Linux-based SAS 9.4 environment integrated with Quest Authentication Services (VAS) and Active Directory.

Issue Summary

A user has been added to a local UNIX group (local_admin_group), and Linux correctly recognises the membership.

Running the id command from a normal Linux session shows the user belongs to both the primary group and the local UNIX group. Likewise, getent group local_admin_group correctly lists the user as a member.

The target directory permissions are similar to:

drwxrws---+ sas local_admin_group

SAS Studio Behaviour

When the same user logs in through SAS Studio and executes the id command via a PIPE statement, the output shows the correct user ID and primary group, along with AD/VAS groups, but the local UNIX group (local_admin_group) is missing.

As a result, the user cannot access directories that rely on membership of the local UNIX group.

Troubleshooting Performed

Quest VAS Configuration

Updated /etc/opt/quest/vas/vas.conf by adding:

[vas_vasd]
merge-local-groups = true

Restarted the VAS daemon afterwards.

PAM Configuration

Updated /etc/pam.d/sasauth to include:

session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session sufficient pam_vas3.so
session required pam_unix.so

NSS Configuration

Updated /etc/nsswitch.conf to include:

initgroups: files vas4 sss

Service Restarts

  • Restarted VAS services.
  • Restarted SAS services.
  • Created completely new SAS Studio sessions after making the changes.
Current Status
  • Linux shell sessions correctly show membership in local_admin_group.
  • getent group local_admin_group returns the expected membership.
  • SAS Studio sessions still do not show the local_admin_group membership.
  • SAS Studio appears to inherit the primary group and AD/VAS groups, but not the local UNIX supplementary group.
Questions
  1. Has anyone seen SAS Studio or Workspace Server sessions fail to inherit local UNIX supplementary groups while standard Linux login sessions work correctly?

  2. Does the SAS Object Spawner or Workspace Server use a different mechanism for group resolution compared to a normal Linux login session?

  3. Is there any known configuration required for sasauth, elssrv, PAM, or Quest VAS to ensure local UNIX group memberships are included in SAS Studio sessions?

  4. Has anyone successfully used local UNIX groups for folder access in SAS Studio when the environment is integrated with Active Directory and Quest VAS?

  5. Are there additional logs or diagnostics that can help identify where the local UNIX group membership is being lost during SAS session creation?

Any suggestions, troubleshooting ideas, or similar experiences would be greatly appreciated.

Thanks in advance.

suga badge.PNGThe SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment. 

Join SUGA 

Get Started with SAS Information Catalog in SAS Viya

Learn how to explore data assets, create new data discovery agents, schedule data discovery agents, and much more.

Find more tutorials on the SAS Users YouTube channel.

Discussion stats
  • 0 replies
  • 253 views
  • 0 likes
  • 1 in conversation