When troubleshooting an issue, Broadcom Support may need to access the PAM appliance through SSH. As of 4.x PAM, a new SSH debug patch is created monthly. Even though the patch is created monthly, the SSH debug patch will last for 180 days before expiring.
This KB article will explain how to upload the patch and enable debug services to prepare for SSH access request from Broadcom Support. This article discusses steps to undertake when you are requested by Broadcom Support to SSH access PAM nodes.
All supported versions of CA PAM
The newest SSH debug patch will be provided by Broadcom through a support case; it is not published to any page on the Broadcom Support site. Once the file has been downloaded from the support case, perform the following steps to apply it and enable SSH debug services.
Configuration > Diagnostics > System.Configuration > Upgrade.CHOOSE FILE and select the .p.bin file provided by Support:PAM_SUPPORT_SSH_DEBUG.p.binPAM_SUPPORT_SSH_DEBUG_420-.p.binUPLOAD AND APPLY.Diagnostics > System and turn ON the Debugging Services. Set the duration for the maximum required (up to 30 days) and click Submit to save the changes.Connection > SSH > Auth > Credentials.Browse for the 'Private key file for authentication' field and select the private key file (.ppk) that was provided with the debug patch.Session, enter a name in Saved Sessions, and click Save.Open to establish the connection.root).As of January 2025, there are now the following two versions of the SSH debug patch for PAM due to the encryption/decryption method change starting with the 4.2.1 release.
Applicable for the 4.2.0 release and older: PAM_SUPPORT_SSH_DEBUG_420-.p.bin
Applicable for the 4.2.1 release and newer: PAM_SUPPORT_SSH_DEBUG.p.bin
If the wrong version of the SSH debug is applied to a PAM appliance, there will be a PAM-CMN-1344 error with detailed message “Error verifying the authenticity of the upgrade package!”
Please note that the Upgrade History will list PAM_SUPPORT_SSH_DEBUG regardless of which patch is applied.