ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

Failing to connect to AIX on PAM 2.8.3


Article ID: 103371


Updated On:


CA Privileged Access Manager - Cloakware Password Authority (PA) PAM SAFENET LUNA HSM CA Privileged Access Manager (PAM)


Customer upgraded AIX to 7.2
PAM is also upgraded to 2.8.3

They are having issues in verifying and changing password for accounts that requires the follow settings. (Change on Behalf with Update/Verify Credentials Script enabled)

From the tomlogs (7.2AIX), it shows this error message 
WARNING: **** ACCOUNT VERIFICATION FAILED: targetAccount ID: 1125' due to 'Error Code: 15212


PAM 2.8.3 (upgraded from PAM 2.6.x)
AIX 7.2


Secure connection could not be established from PAM to AIX, as a result the password verification could not be performed.

Caused by: com.jcraft.jsch.JSchException:
Algorithm negotiation fail at com.jcraft.jsch.Session.receive_kexinit(
at com.jcraft.jsch.Session.connect(
at com.jcraft.jsch.Session.connect(
at com.cloakware.cspm.server.plugin.SSHConnector.connect(

The issue is resolved after applying PAM