CA PAM Client - Failed to start access agent
search cancel

CA PAM Client - Failed to start access agent


Article ID: 95080


Updated On:


CA Privileged Access Manager - Cloakware Password Authority (PA) CA Privileged Access Manager (PAM)


When connecting to the CA PAM a message is returned "Failed to start access agent". The IE web browser session is opened, but no Java applets are loaded. The same message is displayed when using a browser or the PAM Client. The error also occurs when using the PAM client on Windows or MAC. This  does not appear to be network related 


CA PAM 3.x, 4.0.x, 4.1.x


The basic reason for this error message is that the Java components in the CA PAM GUI cannot load. In this particular case it was because there was an error with the custom signing certificate applied to the applets in CA PAM. Since Java could not validate the certificate it could not start the applets.


If there was an error applying the new certificate, then Either set back to the original (gkcert) Default Applet Certificate and reboot the appliance, then test, if this works, then reset back to the new certificate reboot and test.

If the second test does not work, then there is a problem with the certificate and it needs to be recreated.

For more troubleshooting on this topic please try viewing

Additional Information

Confirm the System Certificate is set (Config / Security / Certificates / Set)