Users are unable to log in to Privileged Access Manager (PAM) via RADIUS authentication, receiving the error: "Bad username and password"
search cancel

Users are unable to log in to Privileged Access Manager (PAM) via RADIUS authentication, receiving the error: "Bad username and password"

book

Article ID: 452769

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Users are unable to log in to Privileged Access Manager (PAM) via RADIUS authentication, receiving the error: "Bad username and password".

  • The authentication test for the user in VIP Manager or VIP Gateway is successful.
  • PAM logs show authentication failures despite correct credentials being mapped.
  • The issue may occur in specific environments (e.g., Production) while others work, or across the entire integration.

Environment

  • CA Privileged Access Manager (PAM)
  • Symantec VIP Enterprise Gateway
  • RADIUS Authentication with VIP VIP/Load Balancer

Cause

This issue is frequently caused by a certificate mismatch or an invalid/expired certificate on the Radius VIP (Virtual IP) or Load Balancer sitting in front of the Radius servers. Even if the VIP Gateway itself passes a local test, the communication path from PAM through the VIP to the Radius server fails if the certificate trust is broken.

Resolution

To resolve this issue, follow these steps:

  1. Verify Radius VIP Certificate:

    • Check the certificates installed on the Radius VIP/Load Balancer.
    • Ensure the certificate is valid, not expired, and matches the expected FQDN.
    • If using a private CA, ensure the Root and Intermediate certificates are correctly imported into the VIP Enterprise Gateway Trusted CA store.
  2. Import Missing Certificates:

    • Use OpenSSL or a browser to fetch the Root and Intermediate CAs from the Radius server/VIP.
    • Save them in PEM format.
    • Import them into the VIP EG Trusted CA Certificate store.
  3. Restart Services:

    • Restart the VIP Enterprise Gateway services and the Radius service to ensure the new certificate trust is active.
  4. Test Authentication:

    • Attempt a login through PAM to verify the "Bad username and password" error is resolved.

If you need to speak with a customer representative or a Support Engineer, see . Scroll to the bottom of the page and click on your respective region.