Password verification and update attempts for a local Windows account managed by a Privileged Access Manager (PAM) Windows Proxy agent both fail.
A password verification attempt from the PAM UI results in the following error:
PAM-CM-0759: Failed to verify password with target. If this problem persists then please ask your Administrator to investigate.
Any attempt to update the password fails with error:
PAM-CM-3468: Error updating account credentials.
Here is the environment setup:
With the <loglevel> parameter set to FINE in the Windows Proxy's cspm_agent\cloakware\config\cspm_client_config.xml configuration file, the following errors are observed in the Windows Proxy log file cspm_agent\cloakware\log\cspm_client_log.txt:
On password verification attempts:
FINE: Fri March 05 01:58:00.404 UTC 2021 CSPMAgentService::verifyWindowsAccountPassword. Agent's own hostname: winproxy.example.com
FINE: Fri March 05 01:58:00.404 UTC 2021 CSPMAgentService::verifyWindowsAccountPassword. User: exampleuser, domain: cspm_dummy_value, server: ##.##.##.##
FINE: Fri March 05 01:58:00.420 UTC 2021 CSPMAgentService::verifyWindowsAccountPassword. verifying account on remote host
WARNING: Fri March 05 01:58:21.441 UTC 2021 CSPMAgentService::verifyWindowsAccountPassword. Operation not successful, message: 53-ERROR_BAD_NETPATH
INFO: Fri March 05 01:58:21.441 UTC 2021 CSPMAgentService::verifyWindowsAccountPassword. Complete verify account password
INFO: Fri March 05 01:58:21.441 UTC 2021 CSPMAgentServlet::processTask. Message to send: <?xml version="1.0" ?><eventReponse><eventId>1</eventId><statusCode>440</statusCode><errorMessage>53-ERROR_BAD_NETPATH</errorMessage><content><extended_status></extended_status></content></eventReponse>
On password update attempts:
FINE: Fri March 05 01:58:21.488 UTC 2021 CSPMAgentService::updateWindowsAccountPasswordWithServices. Agent's own hostname: winproxy.example.com
FINE: Fri March 05 01:58:21.488 UTC 2021 CSPMAgentService::updateWindowsAccountPasswordWithServices. Admin user: CSPM_Agent_Account_32, user: exampleuser, domain: cspm_dummy_value, server: ##.##.##.##, services: []
FINE: Fri March 05 01:58:21.488 UTC 2021 CSPMAgentService::updateWindowsAccountPasswordWithServices. Start update user account as admin
WARNING: Fri March 05 01:58:21.504 UTC 2021 CSPMAgentService::updateWindowsAccountPasswordWithServices. Operation not successful, message: 1722-RPC_S_SERVER_UNAVAILABLE
INFO: Fri March 05 01:58:21.504 UTC 2021 CSPMAgentService::updateWindowsAccountPasswordWithServices. Complete account password update
INFO: Fri March 05 01:58:21.504 UTC 2021 CSPMAgentServlet::processTask. Message to send: <?xml version="1.0" ?><eventReponse><eventId>1</eventId><statusCode>440</statusCode><errorMessage>1722-RPC_S_SERVER_UNAVAILABLE</errorMessage><content><extended_status></extended_status></content></eventReponse>
CA Privileged Access Manager (PAM) Windows Proxy managing local accounts on remote Windows servers.
Access to TCP port 445 from the Windows Proxy host to the Windows target server is blocked by a Windows firewall.
Check if a Windows firewall or any external firewall between the Windows Proxy host and the target device blocks TCP port 445 and rectify the firewall configuration.
You can launch "Windows PowerShell ISE" on the Windows Proxy server and run the following command to check if the port is open on the target device:
Test-NetConnection -ComputerName <Target Device hostname/IP> -Port 445You should see the following if the port is not blocked:
TcpTestSucceeded : True
A change in the <loglevel> parameter in the cspm_client_config.xml configuration file requires a restart of service "PAM proxy". Once done with troubleshooting set the log level back to the default WARNING and restart the service again. There is no automatic log file rotation and the log can grow quickly at log level FINE.