Symantec Privileged Access Management

  • 1.  Vaulting password issue!

    Posted May 17, 2019 01:43 AM

    I am getting the issue to vaulting the password within the respective account. But that same password I can log in directly with the devices. Can anyone suggest why this issue occurs?
    I got such issue which is given below:
    "PAM-CM-1341: Failed to establish a communications channel to the remote host. "
    PAM-CM-3478: Failed to update the account credentials. The password may not meet the minimum requirements for the Linux system. Review the log file for further information or else contact your Administrator.



  • 2.  Re: Vaulting password issue!

    Broadcom Employee
    Posted May 17, 2019 10:39 AM

    Hi Sudip, Such errors have been observed in the past when the target application and accounts were not configured right. In the UNIX target application you have to make sure that the correct UNIX variant is selected in the Script Processor section. Target applications for Linux target servers should use variant "Linux".

    In the target accounts you have to make sure that the privilege elevation setting is right. See knowledge doc https://comm.support.ca.com/kb/proper-use-of-privilege-elevation-settings-for-pam-target-accounts-of-type-unix/kb000123217 for details. If you use another account to manage the problem account's password, the setting of this other account would be what matters.

    If you can't get it to work, set the Tomcat Log Level on the Configuration > Diagnostics > Diagnostic Logs page to Info, reproduce the problem, then download the tomcat log (same configuration page, Download tab). Possibly you understand what the problem is by looking at the log entries at the time the problem is observed. Otherwise open a support case, attach the log and document target application name, account name and time at which the error was observed.