Layer 7 Privileged Access Management

Expand all | Collapse all

Unix terminal session terminated after launching from PAM

Jump to Best Answer
  • 1.  Unix terminal session terminated after launching from PAM

    Posted 08-23-2019 10:15 AM
    Hi ,

    Seems like when i try to launch the ssh for a specific account i gets terminated and the terminal closed.
    I have few other accounts, but only one account was having the issue.

    For yor  information, i have already check the account by running the pam_tally--user=userid just to check whether the id is locked. But the id is not locked.

    Any idea what might be the issue ?. is this something related on the endpoint side ?. if its on the endpoint side, where else can i checked ?

    PAM version is 3.2.2.

    Regards.

    Afrezal.


  • 2.  RE: Unix terminal session terminated after launching from PAM

    Posted 08-23-2019 02:52 PM
    Are you sure that the account is in sync with the Target Server?  What happens when you do an account verify for the Target Account in question?

    ------------------------------
    Principal Support Engineer
    Broadcom
    ------------------------------



  • 3.  RE: Unix terminal session terminated after launching from PAM

    Posted 08-26-2019 03:15 AM
    Hello Arezal,

    Apart from what Ed has asked do also check, if you can define Putty as a Service and login from PAM into the target device using the same target account?

    Thanks,
    Reatesh.

    ------------------------------
    Principal Support Engineer
    Broadcom
    ------------------------------



  • 4.  RE: Unix terminal session terminated after launching from PAM
    Best Answer

    Posted 08-26-2019 08:58 AM

    Hi Reatesh, Ed.

    Thanks again for responding to my issue. I've managed to resolved the issue. It looks like from the endpoint side we need to allow the accounts to use ssh by adding them to the /etc/ssh/ssh_allowed_users file. This is for the layer 7 servers.

    I've learned something today. Thanks again for helping out.

    Much appreciated.

    regards,

    Afrezal