One PAM user cannot connect to a Linux server
search cancel

One PAM user cannot connect to a Linux server

book

Article ID: 401561

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Privileged Access Management (PAM) Admin just upgraded PAM from 4.1.1 to 4.2.2 and one user cannot connect to multiple Linux systems.

They get the following error while using our internal (Mindterm) applet:

unknown kex algorithm: curve25519-sha256 

Cause

End-user was still using their old PAM 4.1.1 client.

Resolution

Performed an upgrade of their client to 4.2.2.  After this the issue was no longer reproducible.

Additional Information

Note:  All other users were able to successfully connect to the same server.

Additionally, in the PAM UI >> Configuration >> Security >> Cryptography >> SSH Mindterm >> the "Use Default" was checked off in the SSH Mindterm Tab, which the curve25519-sha2 is one of the listed defaults in Key Exchange section.