Applying the PAM SSH debug patch and enabling SSH debug services
search cancel

Applying the PAM SSH debug patch and enabling SSH debug services

book

Article ID: 198587

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

When troubleshooting an issue, Broadcom Support may need to access the PAM appliance through SSH. This KB article will explain how to upload the patch and enable debug services to prepare for SSH access request from Broadcom Support. This article discusses steps to undertake when you are requested by Broadcom Support to SSH access PAM nodes.

Resolution

To obtain the newest SSH debug patch, contact Broadcom Support. Once the file has been downloaded from the support case, perform the following steps to apply it and enable SSH debug services.

  1. Log in to the PAM GUI.
  2. Navigate to Configuration > Diagnostics > System.
  3. Ensure Remote Symantec PAM Debugging Services is turned OFF.
    • Note: If debugging services are on when the SSH debug patch is applied, they must be disabled and re-enabled after the patch is applied.
  4. Go to Configuration > Upgrade.
  5. Click Choose File, browse to the .p.bin file provided by Support, and click Upload.
    • For PAM 4.2.1 and newer: Use PAM_SUPPORT_SSH_DEBUG.p.bin
    • For PAM 4.2.0 and older: Use PAM_SUPPORT_SSH_DEBUG_420-.p.bin
  6. Select  the SSH debug patch from the list of available patches, then Click APPLY.
    • Note: If the wrong patch is applied, the error PAM-CMN-1344: Error verifying the authenticity of the upgrade package! will occur.
  7. Verify that once the installation of the SSH Debug patch is completed, it is listed in the Upgrade History.
    • Note: The Upgrade History will list PAM_SUPPORT_SSH_DEBUG regardless of which patch is applied
  8. Return to Diagnostics > System and turn ON the Debugging Services. Set the duration for the SSH debug service to remain on (up to 30 days) and click Submit to save the changes.

Additional Information

Though a new SSH debug patch is created monthly, it is not required to obtain a new one every month. The SSH debug patch is valid for 180 days after creation.