Symantec Privileged Access Management

 View Only
  • 1.  CA PAM 3.2 client login issue, keystore was tampered with,or password was incorrect

    Posted Dec 02, 2019 05:29 AM
    Hi,

    When i login to CA PAM 3.2 client its giving below error:

    Error occured during the update. Reason: keystore was tampered woth, or password was incorrect

    ramesh.dara@locuz.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADdjZjU5NDdmLTU4N2YtNDkxMC05NzI2LWEwNGI0ZjBkNWIxNABGAAAAAAAjTqxzLI7nSKqmgpGDxpDyBwDLSdFd6r6ySLADThCFeCpdAAAARv%2FuAABgpsmdaWwoQq8nK1nBNiB3AAXFuvrSAAABEgAQALAT7VZWu6VFgmqlIxdl3jg%3D&thumbnailType=2&owa=outlook.office.com&scriptVer=2019112502.04&X-OWA-CANARY=8puAT5IPZ0m0LLCpa1tBaqDhvP8Qd9cYawX1s3zxVHs8O7lmTT-pwjfocnQJ1S5iTO2dQGC71Ws.&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjA2MDBGOUY2NzQ2MjA3MzdFNzM0MDRFMjg3QzQ1QTgxOENCN0NFQjgiLCJ4NXQiOiJCZ0Q1OW5SaUJ6Zm5OQVRpaDhSYWdZeTN6cmciLCJ0eXAiOiJKV1QifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInZlciI6IkV4Y2hhbmdlLkNhbGxiYWNrLlYxIiwiYXBwY3R4c2VuZGVyIjoiT3dhRG93bmxvYWRAZDQ3NTI1YmYtNjAyZC00ZWQ3LThjNjAtM2RiMGVjMzdlMjY2IiwiaXNzcmluZyI6IldXIiwiYXBwY3R4Ijoie1wibXNleGNocHJvdFwiOlwib3dhXCIsXCJwcmltYXJ5c2lkXCI6XCJTLTEtNS0yMS05NjQ1OTI0MTktMzI0MjQyNzgyMy01OTkwMzA5MzQtODQ2Njg2XCIsXCJwdWlkXCI6XCIxMTUzNzY1OTMxNzg3NjA4Mjg0XCIsXCJvaWRcIjpcIjkxOGM0ZGRjLTViZDYtNGM1Ni1hYTZlLWNkMjI5NjRmNDcyZVwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCJ9IiwibmJmIjoxNTc1MjgxNzMzLCJleHAiOjE1NzUyODIzMzMsImlzcyI6IjAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEBkNDc1MjViZi02MDJkLTRlZDctOGM2MC0zZGIwZWMzN2UyNjYiLCJhdWQiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvYXR0YWNobWVudHMub2ZmaWNlLm5ldEBkNDc1MjViZi02MDJkLTRlZDctOGM2MC0zZGIwZWMzN2UyNjYifQ.b3gBIxMwNOe25YMBCST_atN2uu-IBwqrEBMEh1C_l8SFDa8jPRxdUTVCXOxPv1xu_l3nYPVX-wONEoMGWJ_dtABHyj11WZWYrSueTxbdoxjU3yv1S2SxIKWz9bGhEoqM1ia4Zqim5vi5FiCkHKNBOz733ahdr1o1nswT2l7PkO-GzIjRXxCEr46KiB6SQkkT7q-osT2aTIMCSefXFx1agPQIV69cxFT2PoQfG4xEq8h0_Li6kJqj5-zFSex_QC6TN2IQlRz7Veg0XgVRjlvMCKJM2Wd3dxB0BQjNuSQ7tNyGHPa2zhJo3tlqS6BwTs36KxzrPdSDPszi8yDGKuUwDA&animation=true" class="img-responsive" data-mce-hlimagekey="a1ac249a-7856-3666-3b84-b5f5f37702c4" data-mce-hlselector="#MainCopy_ctl02_TinyMCEEditor_TinyMCEContent">

    Please suggest why this issue getting to me.

    regards
    Ramesh


  • 2.  RE: CA PAM 3.2 client login issue, keystore was tampered with,or password was incorrect

    Broadcom Employee
    Posted Dec 02, 2019 03:11 PM
    Hi,

    It looks like you are running into the following defect:

    DE363356 - "CA PAM randomly disables user accounts with the following associated session log message: "PAM-CMN-1167: A potential tampering attempt has been detected, the end-user's local system may be compromised. Account deactivated."

    This defect has been resolved in PAM 3.2.5 and PAM 3.3.1:

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-privileged-access-management/privileged-access-manager/3-3-1/release-information/resolved-issues-in-3-3_1.html

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-privileged-access-management/privileged-access-manager/3-3-1/release-information/resolved-issues-in-3-2-5.html





  • 3.  RE: CA PAM 3.2 client login issue, keystore was tampered with,or password was incorrect

    Posted Dec 24, 2019 06:08 PM
      |   view attached
    Hello Kevin,

    I have a user running into the same issueon 3.2.4 CA PAM Client. As you suggested I have viewed the error DE363356; however, user is not Disabled in the system. We are not in any condition to update the system at the moment, so I was wondering if there are any fixes for this issue? 

    Cheers,

    Toygan



  • 4.  RE: CA PAM 3.2 client login issue, keystore was tampered with,or password was incorrect

    Broadcom Employee
    Posted Dec 27, 2019 05:12 PM
    No hotfix was created for 3.2.4.  At this point your options are as Kevin described.  You may also upgrade directly to 3.2.6.

    ------------------------------
    Principal Support Engineer
    Broadcom
    ------------------------------



  • 5.  RE: CA PAM 3.2 client login issue, keystore was tampered with,or password was incorrect
    Best Answer

    Broadcom Employee
    Posted Feb 26, 2020 04:00 PM
    I just came across this discussion. The responses are incorrect. This error does not refer to PAM detecting tampered data in communication between PAM client and PAM server, which is what the mentioned defect and user deactivation were concerned with. Rather this refers to the cacerts keystore in the PAM client installation folder. We've had occasional reports of this problem. The cacerts file must have gotten corrupted somehow, possibly AV software is involved. In all cases I am aware of, either reinstalling the PAM client, or copying a cacerts file over from a working client resolved the problem.