PAM-UI-2203: Error deleting proxy.
search cancel

PAM-UI-2203: Error deleting proxy.

book

Article ID: 280838

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

You replaced an old Windows proxy host with a new one and want to remove the old proxy entry from the Credentials > Manage Targets > Proxies page. But an attempt to delete it runs into error

PAM-UI-2203: Error deleting proxy. Proxy cannot be deleted because it is in use.

You confirmed that this proxy is not configured in any current windows target application, and also not used to update services or tasks passwords associated with Windows or AD target accounts.

Environment

Observed on 4.1.1, but could potentially be seen in other releases as well.

Cause

The one time this was observed, the cause was an "orphaned" target application, for which the target server had been marked as deleted at one point in the past. The time of target server deletion is not recorded in the PAM database and was not known. It could have happened at an older PAM release. The application had been created several years prior to the problem being noticed. The PAM UI does not list target applications whose target server is marked as deleted. Remote CLI calls wouldn't retrieve them either. But a query run to see if a Windows Proxy is in use only checks for attributes associated with target applications that are not marked as deleted. It does not look at the delete flag of the target servers to which the applications belong.

Resolution

You will need to engage PAM Support to get this type of problem fixed. Support can access the PAM server via SSH, once you temporarily enable remote debugging services on the Configuration > Diagnostics > System page, run DB queries to find such obsolete orphaned target applications and then mark them as deleted.