Error PAM-CM-5054: Unsupported crypto algorithms specified HMAC:[hmac-sha2-256-etm@openssh.com]
search cancel

Error PAM-CM-5054: Unsupported crypto algorithms specified HMAC:[[email protected]]

book

Article ID: 427821

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Trying to configure PAM to access a given workstation, it fails to connect with a message that the peer is offering an algorithm that PAM is not proposing. Namely for instance:

However, if editing the list of algorithms enabled to add the missing one there is the following error:

Error PAM-CM-5054: Unsupported crypto algorithms specified  XXXX: <Algorithm_name>

 

Resolution

This is working as designed. PAM will only support the algorithms which are listed in the corresponding page and section (Cypher, Hash, Key Exchange...) under Security --> Cryptography (SSH Proxy & Gateway or SSH Mindterm). By default only a small set of those algorithms are available for connection, the most secure ones, but there is a constent list which can be detemined by unchecking option "use Default" checkbox and clicking on the eye near each section (Cypher, hash, etc...).

If the algorithm that the server offers for connection is not present in this full list, it cannot be added to the list of available options for connecting as the error depicted above will be obtained.