It seems like steps 8-11 slipped through the cracks and I never got to posting those. It'll take me a while to write up my notes into a blog post and, given I have lots of customer work which naturally has a higher priority, I can't see me getting to it anytime soon. However, in the time since I wrote that post there's now lots of other resources which will help you. One of the ones that may help you the most is SAS Global Forum 2016 Paper SAS3443-2016 Kerberos Delegation with SAS® 9.4 by Stuart Rogers. Most of the keytab management commands and environment variable settings you'll need are in there along with lots of other very useful info.
If you haven't already seen it all of my other IWA blog posts are listed under the IWA tag: https://platformadmin.com/blogs/paul/tag/iwa/
Some specific ones I'll call out:
SAS & IWA: Check the Logs: https://platformadmin.com/blogs/paul/2012/06/sas-and-iwa-check-the-logs/ Always check the logs (metadata, object spawner) to make sure the connections you think are IWA are indeed IWA Kerberos and not using SAS token, cached credentials, NTLM etc.
SAS & IWA: Host Name Aliases and SPNs: https://platformadmin.com/blogs/paul/2012/04/sas-and-iwa-host-name-aliases-spns/ SAS & IWA: Reviewing SPNs: https://platformadmin.com/blogs/paul/2012/04/sas-and-iwa-reviewing-spns/ If you are using host name DNS aliases and not the physical host name then you will need to ensure all required SPNs are registered in AD
SAS and IWA: Two Hops: https://platformadmin.com/blogs/paul/2012/01/sas-and-iwa-two-hops/ SAS & IWA: Verifying Trusted for Delegation Status: https://platformadmin.com/blogs/paul/2012/03/sas-and-iwa-verify-trusted-for-delegation/ If you want to use IWA to a workspace server, and are not using SAS Token Authentication, then you'll need to get your domain admins to mark the servers as Trusted for Delegation.
Another document to read is, of course, the How to Configure Integrated Windows Authentication section of SAS® 9.4 Intelligence Platform: Security Administration Guide.
I wholeheartedly recommend building up the config methodically from the metadata server, to compute tier, to mid-tier, carefully verifying each step along the way (e.g. checking the logs) before moving on to the next steps. Trying to do everything in one go will be harder to troubleshoot.
See how you go with those resources. If you have any specific questions post them and I'll try to answer them if they can be done in a few minutes (and others here may be able to help too). If you need anything more in-depth, then it's probably best to get help from SAS Professional Services or a local SAS Partner. Setting this up across the board can be quite challenging and time-consuming (albeit very rewarding) - getting professional help from people that have done it before will be very cost effective.
... View more