Symantec Privileged Access Management

 View Only
  • 1.  SSH Agent Forwarding

    Posted Feb 25, 2020 08:21 AM
    It seems SSH agent forwading is not supported by default. We would want to connect to a remote Linux server via CAPAM SSH session and then, from there, connect to other hosts using SSH agent forwarding (SSH -A ).

    Is there a way to configure CAPAM to support SSH Agent forwarding for ssh access via public/private key pair?

    Thanks,


  • 2.  RE: SSH Agent Forwarding
    Best Answer

    Broadcom Employee
    Posted Feb 26, 2020 09:53 AM
    Hi Sanjeev, The PAM SSH client does not include an SSH agent component and therefore cannot support what you are looking for. You can raise an idea on the ideation page. Keep in mind that in general PAM is more about restricting leap frogging rather than facilitating it.


  • 3.  RE: SSH Agent Forwarding

    Posted Feb 26, 2020 10:50 AM
    Hi Ralf,

    Thanks for the update.

    How about using putty as a tcp service for this use case?

    Thanks,



  • 4.  RE: SSH Agent Forwarding

    Broadcom Employee
    Posted Feb 26, 2020 11:53 AM
    Hi Sanjeev, This can work with application protocol Disabled, in which case PAM just routes the connection w/o interfering with it. If you need to use the SSH protocol, to be able to record the sessions, then it won't work, because in that case it is an SSH proxy on the PAM appliance that makes the SSH connection to the target device, and that proxy again doesn't have an SSH agent component.