How to Apply the PAM SSH Debug Patch and Enable Debugging Services
search cancel

How to Apply the PAM SSH Debug Patch and Enable Debugging Services

book

Article ID: 198587

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

When troubleshooting an issue, Broadcom Support may need to access the PAM appliance through SSH. As of 4.x PAM, a new SSH debug patch is created monthly. Even though the patch is created monthly, the SSH debug patch will last for 180 days before expiring.

This KB article will explain how to upload the patch and enable debug services to prepare for SSH access request from Broadcom Support. This article discusses steps to undertake when you are requested by Broadcom Support to SSH access PAM nodes.

Environment

All supported versions of CA PAM

Resolution

The newest SSH debug patch will be provided by Broadcom through a support case; it is not published to any page on the Broadcom Support site. Once the file has been downloaded from the support case, perform the following steps to apply it and enable SSH debug services.

Apply the PAM SSH Debug Patch

  1. Log in to the PAM GUI.

  2. Navigate to Configuration > Diagnostics > System.

  3. Ensure Remote Symantec PAM Debugging Services is turned OFF.
    • Note: If services are already on, you must turn them off and then back on after the patch is applied.

  4. Go to Configuration > Upgrade.

  5. Click CHOOSE FILE and select the .p.bin file provided by Support:
    • For PAM 4.2.1 and newer: Use PAM_SUPPORT_SSH_DEBUG.p.bin
    • For PAM 4.2.0 and older: Use PAM_SUPPORT_SSH_DEBUG_420-.p.bin

  6. Click UPLOAD AND APPLY.

  7. Verify that once the installation of the SSH Debug patch is completed, it is listed in the Upgrade History.

  8. Return to Diagnostics > System and turn ON the Debugging Services. Set the duration for the maximum required (up to 30 days) and click Submit to save the changes.
     Before - Remote Symantec PAM Debugging Services are enabled 

     
 
    After enabling the Remote Symantec PAM Debugging Services 

   
 

Login to CA PAM Using SSH

  1. Launch PuTTY.

  2. Enter the IP address or hostname of the PAM appliance.

  3. Navigate in the left pane to Connection > SSH > Auth > Credentials.

  4. Click Browse for the 'Private key file for authentication' field and select the private key file (.ppk) that was provided with the debug patch.

  5. (Optional) Go back to Session, enter a name in Saved Sessions, and click Save.

  6. Click Open to establish the connection.

  7. Log in as the user requested by Support (typically root).

Additional Information

As of January 2025, there are now the following two versions of the SSH debug patch for PAM due to the encryption/decryption method change starting with the 4.2.1 release.

Applicable for the 4.2.0 release and older: PAM_SUPPORT_SSH_DEBUG_420-.p.bin
Applicable for the 4.2.1 release and newer: PAM_SUPPORT_SSH_DEBUG.p.bin

If the wrong version of the SSH debug is applied to a PAM appliance, there will be a PAM-CMN-1344 error with detailed message “Error verifying the authenticity of the upgrade package!”

Please note that the Upgrade History will list PAM_SUPPORT_SSH_DEBUG regardless of which patch is applied.