Symantec Privileged Access Management

  • 1.  Auto Login is not happening for SSH access method ?

    Posted May 24, 2018 07:08 AM

    Hello All,

     

    I am trying to integrate Linux servers in CA PAM. Team uses 2 different ways to access the Linux servers, i.e.,

    GUI and CLI

    GUI is web portal and we configured it and its working as expected.

    CLI is configured but Auto Login is not happening, when we click on SSH its prompting for credentials even though we added target accounts to it.

    can anyone faced the same issue and provide us guidance to solve.



  • 2.  Re: Auto Login is not happening for SSH access method ?

    Broadcom Employee
    Posted May 24, 2018 09:36 AM

    Hi Ashwini,

     

    The most likely problem here would be mis-configuration. Please check your Policy to ensure that the target account has been added specifically for the SSH Access Method (or TCP/UDP Service used for SSH). We have seen issues in the past where users put the target account in the Policy under "Passwords" but this is not used for auto connect, it is only for actually 'viewing' the password.

     

    This KB doc explains the steps required for auto-connect:

    PAM 2.X: HOW-TO: Set up a device for RDP or SSH with automa - CA Knowledge 

    PAM 3.X: HOW-TO: Set up a device for RDP or SSH with automa - CA Knowledge 

     

    If this doesn't help, it is also possible that your appliance/cluster is in a bad state. You should check for a message box at the top of the page when you login to see if there are any reported cluster problems, Credential Manager problems, or the DB is locked. If you see any messages like this, they are likely the cause. If you do find a message, you can post it here and we can try to provide advice on moving forward.

     

    Regards,

    Christian Lutz

    Sr. Support Engineer

    CA Technologies - North America 



  • 3.  Re: Auto Login is not happening for SSH access method ?

    Posted May 25, 2018 07:09 AM

    SSH autologin is not happening, its prompting for credentials.

     

    Thanks for your reply Christian.

    Target account is added to SSH Access Method and appliance/cluster is also in good state. We have on boarded other servers with SSH and its working as expected. Only for this application we are facing this issue. I have attached the screen shot above, please check and suggest.



  • 4.  Re: Auto Login is not happening for SSH access method ?

    Posted May 25, 2018 12:12 PM

    Hi Ashwini.  Thanks for sharing that screen capture.  That message is not one with which I am familiar.  It appears to be coming from the server, or from some device in your network.  Is there something preventing access to that device, based on the address of the requesting system?  If you remove the credentials added to the policy can you login if you type the userid and password.  I'm suggesting this as  a data point, not a solution.



  • 5.  Re: Auto Login is not happening for SSH access method ?
    Best Answer

    Broadcom Employee
    Posted May 25, 2018 02:16 PM

    Ashwini,

     

    Discussing with the team, and also additional context. The SSH connection here in question is to a Datapower system. Reviewing additional support forums, other users experienced this same issue. The Datapower SSH connection does not accept inputs from a regular SSH command entry. This would apply to both the native PAM SSH Applet along with Putty connections. We'll need to post this as an Idea within Communities as an enhancement for support of this with the Native SSH Applet along with the Management of the account through a connector. Optionally for a vaulted credential, you could leverage a Published SSH client and pass through a Transparent Login XML the login information for the system to broker the session and record activities.

     

    Adam



  • 6.  Re: Auto Login is not happening for SSH access method ?

    Broadcom Employee
    Posted May 27, 2018 09:47 PM

    When you raise the idea, I think it is better to paste the URL here. Someone will reach this thread in future, the person also may expect to vote it.



  • 7.  Re: Auto Login is not happening for SSH access method ?

    Posted Jun 05, 2018 11:12 AM

    Thanks Adam,

    Let me try to do publish RDP:-)