Symantec Privileged Access Management

  • 1.  RDP freezing and connection lost in CA PAM

    Posted Aug 31, 2016 08:07 AM

    Hello Everyone,

     

    We're facing two problems we don't have if we connect directly to some windows servers.

     

    First is around 30 minutes RDP freezes and we can't interact with the server viaCA PAM RDP client.

     

    Second is if we leave a RDP session open for a few days, let's say 2 days (starting friday) when we arrive on monday the connections were lost with following errors:

    Error RDP connection.

     

    Logs inside box:

     

    Error type: RdpException.
    Error message: Unable to connect to backend device. Please contact Administrator..
    Stack trace:
       com.ca.xsuite.app.rdp3.client.handler.TCPStreamHandler.read(Unknown Source)
       com.ca.xsuite.app.rdp3.core.layer.channel.BaseITULayer.receive(Unknown Source)
       com.ca.xsuite.app.rdp3.core.layer.ITULayer.mainLoop(Unknown Source)
       com.ca.xsuite.app.rdp3.client.app.RDesktop.main(Unknown Source)
       com.ca.xsuite.launcher.a.n.run(Unknown Source)
       java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
       java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
       java.lang.Thread.run(Unknown Source)
    Cause:
    Error type: EOFException.
    Error message: .
    Stack trace:
       com.ca.xsuite.app.rdp3.core.impl.RDPInputStream.readFully(Unknown Source)
       com.ca.xsuite.app.rdp3.client.handler.TCPStreamHandler.read(Unknown Source)
       com.ca.xsuite.app.rdp3.core.layer.channel.BaseITULayer.receive(Unknown Source)
       com.ca.xsuite.app.rdp3.core.layer.ITULayer.mainLoop(Unknown Source)
       com.ca.xsuite.app.rdp3.client.app.RDesktop.main(Unknown Source)
       com.ca.xsuite.launcher.a.n.run(Unknown Source)
       java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
       java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
       java.lang.Thread.run(Unknown Source)
    Any idea?


  • 2.  Re: RDP freezing and connection lost in CA PAM

    Broadcom Employee
    Posted Sep 01, 2016 10:09 AM

    Hello Ellery,

     

    Can you please also let us know the version of CA PAM and the Windows OS to which you are connecting to is producing this Error message?

     

    Thanks,
    Reatesh.



  • 3.  Re: RDP freezing and connection lost in CA PAM

    Posted Sep 01, 2016 12:28 PM
    FilenameDate Applied
    XS_2.600:31:08 05/17/16
    XS_SUPPORT_SSH_DEBUG
    XS_2.5.420:19:44 02/29/16
    XS_2.5.211:04:28 02/04/16
    XS_2.5.114:04:43 01/20/16

     

    Windows Servers 2008 R2.



  • 4.  Re: RDP freezing and connection lost in CA PAM

    Broadcom Employee
    Posted Sep 02, 2016 09:13 AM

    Hello Ellery,

     

    Do you also have the PAM agent installed on the Windows Server or are you performing RDP using the Administrator Account?

     

    One more thing, can you upgrade Java on your desktop / host from where you are accessing the PAM application the latest release 8.101 ( Java™ SE Development Kit 8, Update 101) and let us know the result.

     

    Thanks,

    Reatesh.



  • 5.  Re: RDP freezing and connection lost in CA PAM
    Best Answer

    Broadcom Employee
    Posted Sep 02, 2016 09:55 AM

    Hello Ellery,

     

    I did a small test with Windows 10, and I am connecting to this host using the in build Administrator account.

     

    The RDP happens fine, and after almost 18 to 20 minutes of inactivity on the Windows 10 host, I see the following error message..

    ====================

    Error type: RdpException.
    Error message: This computer can not connect to the remote computer.
    Try connecting again. If the problem continues, contact the owner of the remote computer or your network administrator..

    Stack trace:
    com.ca.xsuite.app.rdp3.client.handler.TCPStreamHandler.read(Unknown Source)
    com.ca.xsuite.app.rdp3.core.layer.channel.BaseITULayer.receive(Unknown Source)
    com.ca.xsuite.app.rdp3.core.layer.ITULayer.mainLoop(Unknown Source)
    com.ca.xsuite.app.rdp3.client.app.RDesktop.main(Unknown Source)
    com.ca.xsuite.launcher.a.n.run(Unknown Source)
    java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
    java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
    java.lang.Thread.run(Unknown Source)

    Cause:
    Error type: IOException.
    Error message: Internal TLS error, this could be an attack.

    Stack trace:
    com.ca.xsuite.app.rdp3.core.common.libs.org.bouncycastle.crypto.tls.TlsProtocol.failWithError(Unknown Source)
    com.ca.xsuite.app.rdp3.core.common.libs.org.bouncycastle.crypto.tls.TlsProtocol.safeReadRecord(Unknown Source)
    com.ca.xsuite.app.rdp3.core.common.libs.org.bouncycastle.crypto.tls.TlsProtocol.readApplicationData(Unknown Source)
    com.ca.xsuite.app.rdp3.core.common.libs.org.bouncycastle.crypto.tls.TlsInputStream.read(Unknown Source)
    com.ca.xsuite.app.rdp3.core.impl.TLS12InputStream.readFully(Unknown Source)
    com.ca.xsuite.app.rdp3.client.handler.TCPStreamHandler.read(Unknown Source)
    com.ca.xsuite.app.rdp3.core.layer.channel.BaseITULayer.receive(Unknown Source)
    com.ca.xsuite.app.rdp3.core.layer.ITULayer.mainLoop(Unknown Source)
    com.ca.xsuite.app.rdp3.client.app.RDesktop.main(Unknown Source)
    com.ca.xsuite.launcher.a.n.run(Unknown Source)
    java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
    java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
    java.lang.Thread.run(Unknown Source)

    ================

     

    Along with the error message one more small pop-up window shows this message 

     

     

    This pop-up is basically hidden under the mail error message.

     

    I am as well using R 2.6 PAM version.

     

    Thanks,

    Reatesh.



  • 6.  Re: RDP freezing and connection lost in CA PAM

    Posted Sep 02, 2016 01:14 PM

    That's bad.

     

    I hope this is solved on 2.7.

     

    Best,

    Ellery



  • 7.  Re: RDP freezing and connection lost in CA PAM

    Broadcom Employee
    Posted Sep 15, 2016 10:17 AM

    Hello @Ellery,

     

    We would need to wait and check.

     

    Thanks,

    Reatesh.



  • 8.  Re: RDP freezing and connection lost in CA PAM

    Posted Sep 20, 2016 07:54 AM

    The message is due to applet inactivity.

     

    With PAM 2.6 you get the above error message.

    With PAM 2.7 you get an EOFException.

     

    It is better and not as dramatic as with 2.6.

     

    Best regards

    Claus



  • 9.  Re: RDP freezing and connection lost in CA PAM

    Posted Sep 21, 2016 09:20 AM

    I was told by CA PAM support to try changinf Applet Timeout to a number that represents for example, 5 days! 7200! I'll test it.



  • 10.  Re: RDP freezing and connection lost in CA PAM

    Broadcom Employee
    Posted Apr 21, 2017 04:53 PM

    Hi Ellery,

    Did you try to reset "Applet Timeout"? You can also set it as "0" which means there will be no timeout.

    Thanks!

     

    Yong