PAM email notification option upon password view send email also on autologin
search cancel

PAM email notification option upon password view send email also on autologin

book

Article ID: 400808

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

We have enabled the email notification option upon password view.

* Email Notification -> upon password view

I added my account to the "Selected Users" so that I can see if people are requesting to view a password.

However, it seems to have the side effect where when we connect via SSH or PuTTY, I receive and email that I've viewed the password - but we didn't. 

We want to know if this is working as expected

Cause

As per PAM point of view, when you use the password you are viewing it, so with autologin password is viewed and notification email is sent.

Resolution

PAM has to read the password in order to provide it for auto-logon. Within the credential management part of PAM every read is a password view. Over the years the password view policy feature has been enhanced to separate direct views from views/reads for auto-connect for actions like re-authenticate and reason-required, but the email notification part of the PVP does not have that split (yet).