We have a 9.4 and Viya 3.5 environment on Linux, we would like to setup Single Sign on on Midtier (9.4 and Viya3.5) and IWA for desktop apps. Appreciate any help to refer me to documentations to achieve this.
Also Is it required for the user to be able to ssh to the linux servers (like configure pam/sssd)?
The relevant documentation is below. If you want a process to be owned by the authenticating user, their user ID must be valid on the compute server and potentially the CAS host in Viya (i.e. configure PAM/SSSD), but this does not necessarily mean they need to be able to SSH to the server. Alternatively the SAS/CAS process can be owned by a shared account, but this prevents using file system authorization to be used to limit access.
The relevant documentation is below. If you want a process to be owned by the authenticating user, their user ID must be valid on the compute server and potentially the CAS host in Viya (i.e. configure PAM/SSSD), but this does not necessarily mean they need to be able to SSH to the server. Alternatively the SAS/CAS process can be owned by a shared account, but this prevents using file system authorization to be used to limit access.
Just to clarify, PAM/SSSD is really not required to achieve SSO, this is just optional if we wanted the SAS process be owned by the authenticating user in 9.4 and Viya 3.5?
-- Greg Wootton | Principal Systems Technical Support Engineer
The SAS Users Group for Administrators (SUGA) is open to all SAS administrators and architects who install, update, manage or maintain a SAS deployment.