After a clean install of SAS 7.0 on RHEL 10.2, running vastool status returns a warning result similar to the following:
Host: <hostname, Red Hat Enterprise Linux 10.2 (Coughlan)>
SAS: <7.0.0.8900>
Domain: <example.domain>
INFO: SELinux enabled (Permissive), vasd policy is NOT installed.
FAILURE: 608 Pam <switchable-auth><auth> not configured for SAS.
INFO: 634 pam_access found in pam configuration, this might prevent SAS users from logging in
Result: <Test(s) reported warnings> (2 seconds)(v0.9.3)
# authselect select AuthenticationServices with-switchable-auth
[error] Unknown profile feature [with-switchable-auth]
[error] Unable to activate profile [AuthenticationServices] Invalid argument
authselect feature called with-switchable-auth, which is included in the RHEL default (sssd) profile via a switchable-auth PAM stack file:/usr/share/authselect/default/sssd/switchable-auth
AuthenticationServices vendor profile shipped in SAS 7.0 does not yet contain an equivalent switchable-auth file:/usr/share/authselect/vendor/AuthenticationServices/ ← missing switchable-auth
Because the file is not present in the SAS vendor profile, vastool status reports the missing PAM stack as FAILURE 608, and authselect cannot activate the with-switchable-auth feature against the SAS profile.
Upgraded hosts (6.x → 7.0) are not impacted because the pre-existing PAM/authselect layout satisfies the check.
This behavior has been confirmed as a product defect and is being tracked internally by One Identity R&D:
A fix is planned to be addressed in a future release of Safeguard Authentication Services. At this time, no ETA is available for the corrected build. This article will be updated once release information is confirmed
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center