book
Article ID: 319341
calendar_today
Updated On:
Issue/Introduction
When attempting SSH connection to VCHA passive and witness, first password authentication could fail on VCSA has ever joined AD domain regardless of the correct password. The second authentication would be successful.
Two login prompts appear if VCSA which joins AD domain enables VCHA, one is for appliance management authentication, the other one is for unix_pam.so. The first login prompt for appliance management authentication will be failed since appliance management service does not start on both VCHA passive and witness. But if second login for pam_unix.so is succeed, you can login to the VCHA passive and witness, which is an expected behavior.
Resolution
This is expected behavior. Log in with the second authentication.