Known Issues
The following is a list of all the known issues since version 10.1.
Links for versions prior to 12.0 no longer work. If you click the link, you will go to https://cyberark-customers.force.com/s/search-results, and then you must apply the appropriate filters. |
Version 12.2
Known Issues
You can view the most updated select Core PAS known issues online in our community.
You can view the most updated select AAM Credential Providers known issues online in our community.
Version 12.1
Known Issues
You can view the most updated select Core PAS known issues online in our community.
You can view the most updated select AAM Credential Providers known issues online in our community
Version 12.0
Known Issues
You can view the most updated select Core PAS known issues online in our community.
You can view the most updated select AAM Credential Providers known issues online in our community
Version 11.7
Known Issues
You can view the most updated select Core PAS known issues online in our community.
You can view the most updated select AAM Credential Providers known issues online in our community.
Known Limitations
Following are known limitations for this version.
PVWA
# |
Area |
Description |
---|---|---|
1 |
OIDC Authentication |
OIDC Authentication is not supported with a second factor authentication |
Version 11.6
Known Issues
You can view the most updated select Core PAS known issues online in our community.
You can view the most updated select AAM Credential Providers known issues online in our community.
Known limitations
The following are known limitations for this version.
PSM
# |
Area |
Description |
---|---|---|
1 |
Licenses |
PSM sessions on Windows 2019 machines with a per-user RDS license are disconnected after 60 minutes due to new RDS license enforcement in Windows 2019. You can either work with per-device RDS licenses, or move the local PSM users to the domain level as described in PSMConnect and PSMAdminConnect Domain Users |
PTA
# |
Area |
Description |
---|---|---|
1 |
Generic plugin infrastructure |
Suspicious Password Change detection does not work for a Unix password change. |
AAM DAP
# |
Area |
Description |
---|---|---|
1 |
Upgrade |
Upgrades to version 11.6 can be performed by CyberArk Professional Services or certified partner engineers only. |
Version 11.5
Known Issues
You can view the most updated select Core PAS known issues online in our community.
You can view the most updated select AAM Credential Providers known issues online in our community.
Known limitations
The following are known limitations for this version.
PTA
# |
Area |
Description |
---|---|---|
1 |
PTA for Azure Detection |
Account uniqueness identification is based on username and ActiveDirectoryID. Only Azure accounts with ActiveDirectoryID on the account level, and not on the platform level, will be counted in PTA |
2 |
PTA for Azure Detection |
When upgrading PVWA to version 11.5, Suspected Credential Theft in Azure portal detection will be presented in the UI only after hard refresh / clear cache in the Browser |
3 |
PTA for Azure Detection |
Generic Infrastructure is not supported with Cloud based detections |
Version 11.4
Known Issues
Starting with this release, you can view the most updated select known issues online in our community.
Following is a list of select known issues as of April 20:
ID |
Area |
Description |
---|---|---|
1 |
Solaris | CPasswordSDK32 on Solaris is not supported. The application receives the password but crashes afterward (core dump) |
ID |
Area |
Description |
---|---|---|
1 |
Audits |
Sending a direct message in Twitter does not result in an audit log in the PVWA monitoring page |
2 |
Audits |
When reviewing the audits for Twitter in PVWA monitoring, new tweets and comments for a tweet are monitored as the same "posted new tweet" action |
3 |
Login |
When logging in to a web application using PSM for Web, the account name is case sensitive and must be identical to the name of the account stored in the CyberArk Vault |
4 |
Login |
In some cases, the login process to AWS cannot be completed. The user is unable to enter a password, and will get a "Bad request" error message. This is a result of historic login data |
Known Limitations
Following are known limitations for version 11.4
ID |
Area |
Description |
---|---|---|
1 |
PVWA Authentication | IdP initiated flow is supported only in the v10 UI. Customers using v9 SAML authentication cannot use IdP initiated flow or the new SAML login REST API |
2 |
PVWA Onboarding |
Since v11.2, new customers running the discovery process cannot view or manage private SSH keys discovered by the scanner and onboarded manually |
ID |
Area |
Description |
---|---|---|
1 |
Upgrade | All old PSM for Web system logs are deleted from the system during an upgrade |
2 |
Universal Connector | Connectors created using the Universal Connector Generator in version 11.4 will not be compatible with older versions |
ID |
Area |
Description |
---|---|---|
1 |
PTA Security Event UI | A direct link to the managed account from the Security Events page is not shown for a “Suspicious activities detected in a privileged session” event |
Version 11.3
ID |
Area |
Description |
---|---|---|
1 |
Installation |
If you install CPM from a folder with a space in its path, the engines certificate import fails. To solve this issue, manually add the certificate to the CPM server |
ID |
Area |
Description |
---|---|---|
1 |
PTA Outbound |
Customers with PVWA earlier then 10.3 that configured detections with the new outbound configuration will receive a syslog information with a broken link to the PVWA security event UI, instead of the old PTA Interface |
ID |
Area |
Description |
---|---|---|
1 |
Compatibility |
PVWA 11.2 is not compatible with CyberArk Vault 10.9 and 10.10 |
Version 11.2
ID |
Area |
Description |
---|---|---|
1 |
PAS on Cloud - AWS |
Manual documentation for Vault installation has been temporarily removed due to data inaccuracy. The updated documentation will be uploaded as part of the 11.3 release |
ID |
Area |
Description |
---|---|---|
1 |
PAS Installer |
PAS Installer version 11.2 cannot be used with previous versions of the PVWA, CPM, and PSM components, only with version 11.2 of these components |
ID |
Area |
Description |
---|---|---|
1 |
Salesforce |
In Salesforce lightning experience, in some cases window-title actions will produce duplicated auditing for the same action in PVWA monitoring page |
2 |
Universal Connector Generator |
Universal Connector – When creating a connector with proxy chaining, its domain is not identified correctly. Workaround: In the PSM for Web console, manually edit the domain field |
3 |
PAC file |
When using IE and the PSM for Web PAC file is configured in the browser, you cannot access your personal Gmail account or Google drive |
4 |
Universal Connector Generator | Universal Connectors are not supported to work with reverse proxy |
5 |
Universal Connector Generator | Universal connectors created before v11.2 must be re-created in order to appear in PSM for Web console's connectors list and to be able to be hardened |
6 |
PSM for Web Console | The Reverse proxy domain field must be lower-case only |
7 |
When using IE, login to Facebook fails. Facebook declared EoL for running on IE | |
8 |
Azure |
No audit log of Azure activities is available |
ID |
Area |
Description |
---|---|---|
1 |
Installation | Installations on SUSE Linux Enterprise Server 12 might fail due to a SUSE bug on Intel CPU servers. If you encounter this bug, follow the solution provided by SuSe |
ID |
Area |
Description |
---|---|---|
1 |
Installation | Installations on SUSE Linux Enterprise Server 12 might fail due to a SUSE bug on Intel CPU servers. If you encounter this bug, follow the solution provided by SuSe |
ID |
Area |
Description |
---|---|---|
1 |
PTA Agent configuration | When upgrading the PTA agent, parameters that were manually added by the customer to the PTA Agent configuration file are deleted |
2 |
Unmanaged Privileged Account detection |
Receiving non-mapped information from the SIEM for mandatory fields like Accounts Security ID can result in a False Positive alert. Unmanaged Privileged Access is alerted on an incorrect account, sending it to PVWA for automatic onboarding |
3 |
PTA - PVWA Connectivity |
Setting the CyberArk PTA platform to enforce exclusive access in the PVWA Master Policy can result in connectivity issues between PTA and PVWA |
Version 11.1
ID |
Area |
Description |
---|---|---|
1 |
Vault installation |
Repair/ Uninstall options that are available from both the Vault install wizard and the programs and features view in Windows are not supported. Do not use them |
2 |
Distributed Vaults installation |
Once the option to install the RabbitMQ has been enabled, the following known issues apply with regards to the Vault installation:
|
ID |
Area |
Description |
---|---|---|
1 |
PVWA URL |
PVWA URL for the new interface will show v10. For example, for the Accounts page the URL will be: '.../PasswordVault/v10/Accounts' |
2 |
Copy Password Chrome Extension |
To copy passwords using the Chrome extension, customers must install the extension from the Google Chrome Extensions store and not from the PVWA |
3 |
AdHoc Access |
AdHoc Access is not supported in Active/Active architecture when CPM scanner is connected to a PVWA that works with a Satellite Vault |
4 |
SAML authentication |
SAML authentication supports only one signed assertion |
5 |
Delete Account REST |
Customers that are using the Delete Account REST API (DELETE /api/Accounts/{ID}) must use it with a Vault version 11.1 or higher. In any other case, the following error might occur: ITATS768E Invalid value 4 for ServiceBehaviourOptions |
6 |
Change only in the Vault |
REST API and UI do not support the following capabilities supported in the classic UI:
|
ID |
Area |
Description |
---|---|---|
1 |
Installation |
When the CPM is installed on a different machine than PVWA, TLS 1.2 must be enabled on the CPM machine |
2 |
Installation |
When using silent installation on a hardened PVWA machine on Windows 2016, the installation will fail |
3 |
Scanner log |
Archive files are never deleted from the archive folder |
ID |
Area |
Description |
---|---|---|
1 |
Playing Video recording |
When using Firefox web browser to play large PSM session recordings, there are potential interruptions. Users can switch to the V9 UI if needed |
ID |
Area |
Description |
---|---|---|
1 |
Upgrades |
Upgrade to v11.1 from the OVF released in 10.9.1, 10.10, or 11.0 results in the appliance not meeting the minimum CPU and memory requirements as documented in the Online Help center. Customers can fix this issue by following the instructions published in the following Knowledge Base article: https://cyberark-customers.force.com/s/article/PSM-for-WEB-OVF-Under-specs Note: A clean install of v11.1 OVF meets the minimal system requirements |
2 |
Upgrades |
All old PSM for Web system logs will be deleted from the system during an upgrade of PSM for Web |
3 |
Universal connectors |
Connectors created using the Universal Connector Generator in versions prior to 11.0 are not compatible with version 11.1. After upgrading to version 11.1, use the Universal Connector Generator to record the application connector again, and overwrite the existing connectors by creating the connectors with the same Web Application ID values as the existing ones |
4 |
Universal connectors |
Connectors can only be generated through the PSM for Web Console using the Chrome browser. Internet Explorer is not supported |
5 |
Universal connectors |
Creating a connector for applications that are accessed using an IP address and not a hostname requires an additional manual change that is documented in Connector Generator (Beta) |
6 |
|
Link previews are not available to users who access the corporate twitter account through PSM for Web. Note: External users reading tweets with links that are posted by the corporate account are not affected, and the preview will be available for them |
7 |
PSM for Web Console |
User who fails to change a password, due to entering an incorrect current password, will not be able to exit the 'Change password' screen unless logging out and logging back in with the old password |
ID |
Area |
Description |
---|---|---|
1 |
Distributed Vaults |
Automatic response to a risky session while suspending or terminating the session is not supported in a distributed environment |
2 |
PTA Plugins |
Uploading a new generic plugin to PTA requires a manual step to allow replication permissions on the plugin file between Primary PTA and Secondary PTA |
3 |
Detection |
When a domain group is added to a local privileged group, PTA will not detect this as part of the new use case for Unmanaged Privileged Account detection |
4 |
PTA Hostname |
PTA Hostname can be changed only when using a CA certificate |
Version 10.10
ID |
Area |
Description |
---|---|---|
1 |
REST API |
The Add Discovered Accounts REST API does not support SSH Keys as dependencies or as a newly discovered account |
2 |
Copy Password Chrome Extension |
To copy passwords using the Chrome extension, customers must install the extension from the Chrome Extensions store and not from the PVWA |
3 |
AdHoc Access |
AdHoc Access is not supported in Active-Active architecture when CPM Scanner is connected to a PVWA that works with a Satellite Vault |
ID |
Area |
Description |
---|---|---|
1 |
Installation |
When the CPM is installed on a different machine from PVWA, TLS 1.2 must be enabled on the CPM machine |
2 |
Installation |
When performing a silent installation of the CPM using the credentials file, automatic import of platforms from the ExtensionsInstallationPlatforms folder will fail. They must be imported manually after the installation using the PVWA |
ID |
Area |
Description |
---|---|---|
1 |
PSM Installation | The following error appears in the PSM Trace file: “Error: PSMSR1257E Failed to initialize CAR sdk”. Despite this error, the PSM works as expected and the error can be ignored |
ID |
Area |
Description |
---|---|---|
1 |
Detections |
These are the limitations for the new addition to the Unmanaged Privileged Account detection:
|
2 |
Generic plugins Infrastructure | SIEM solutions that are sending Bulk messages in TCP protocol are not supported as part of the PTA generic plugins infrastructure |
ID |
Area |
Description |
---|---|---|
1 |
Installation |
|
ID |
Area |
Description |
---|---|---|
1 |
Synchronizer |
When configuring the Synchronizer to sync all properties, the maximum number of accounts recommended to sync into Conjur decreases to 60000 accounts (instead of 150000) |
Version 10.9
ID |
Area |
Description |
---|---|---|
1 |
REST API |
Add Discovered Accounts REST API does not support SSH Keys as dependencies or as a newly discovered account. |
2 |
AdHoc Access |
When PVWA 10.9 works with CPM 10.6 or 10.7, the newly added AdHoc time period configuration will be enforced correctly, yet the audit log will indicate 4 hours. |
3 |
Copy Password Chrome Extension |
To copy a password using the Chrome extension, customers must install the extension from the Chrome Extensions store and not from the PVWA. |
ID |
Area |
Description |
---|---|---|
1 |
Interoperability |
There is a known limitation for CPM v10.7 working with PVWA v10.8. Customers who wish to upgrade only the PVWA must use CPM v10.6. |
2 |
Installation |
When the CPM is installed on a different machine from PVWA, TLS 1.2 needs to be enabled on the CPM machine. |
3 |
Installation |
When using silent installation of the CPM using the credentials file, the automatic import of platforms from the ExtensionsInstallationPlatforms folder will fail and will need to be imported manually using the PVWA after the installation. |
ID |
Area |
Description |
---|---|---|
1 |
Salesforce |
In some cases, when a user logs into the Salesforce Lightning experience, the monitored session in PVWA displays the Salesforce user ID instead of the username, both as the Vault user and the application account, so that the auditor cannot tell who the actual Vault user is who created the session. The audit of the user’s activity in the session is not affected by this issue. |
Version 10.8
ID |
Area |
Description |
---|---|---|
1 |
REST API |
Add Discovered Accounts REST API does not support SSH Keys as dependencies or as a newly discovered account |
2 |
AdHoc Access |
When PVWA 10.8 works with CPM 10.7/10.6, the newly added AdHoc time period configuration will be enforced correctly, yet the audit log will indicate 4 hours |
ID |
Area |
Description |
---|---|---|
1 |
Interoperability |
Due to a known limitation for CPM v10.7 working with PVWA v10.8, customers who want to upgrade only the PVWA must use CPM v10.6 |
2 |
Installation |
When the CPM is installed on a different machine from PVWA, TLS 1.2 must be enabled on the CPM machine |
ID |
Area |
Description |
---|---|---|
1 |
Salesforce |
In some cases, when a user logs in to Salesforce Lightning experience, the monitored session in PVWA displays the Salesforce user ID instead of the username, both as the vault user and the application account, so that the auditor will not be able to tell who is the actual vault user that created the session. The audit of the user’s activity in the session is not affected by this issue. This issue is being handled and will be resolved as soon as possible |
ID |
Area |
Description |
---|---|---|
1 |
Golden Ticket Detection |
Customers who upgraded their domain controller from Server 2003 to Server 2008 without modifying the default configuration of high port range, cannot configure a Golden Ticket detection As a solution, configure the Vault to allow an outbound connection to the Domain Controllers, with TCP ports 1025 - 5000 For more details, see https://docs.microsoft.com/en-us/previous- versions/windows/it-pro/windows-server-2008-R2-and-2008/dd772723(v=ws.10) |
2 |
PAS installer |
When installing PTA using the PAS installer, PTA fails to initiate automatic termination and suspension, due to missing permissions As a solution, run a manual step to configure PTA permissions for automatic termination and suspension, using the "Vault Permissions Validation" utility |
3 |
Security Events and Security Configuration |
Server-side errors are not presented in the PVWA UI. This impacts use cases of connectivity failures between PVWA and PTA, and permissions failure when trying to resume a session, without having the right permissions |
Version 10.7
ID |
Area |
Description |
---|---|---|
1 |
Files / Reports / Recordings |
In a Distributed Vaults environment, when retrieving files (such as Reports, Recordings) the following error message appears in ITALog – ITAPE281E Error while retrieving file (Code 8, 2, 0) – although the file is retrieved. This message can be ignored |
2 |
Distributed Vaults |
Authentication failure message in ITALog of a Satellite includes the IP of the Satellite Vault instead of the PVWA where the authentication failed |
ID |
Area |
Description |
---|---|---|
1 |
Accounts View |
The Copy Password function is not supported when using PVWA in the Microsoft Edge browser. Passwords can be copied from the Show Password window in the new UI. |
2 |
LDAP integration |
The new LDAP integration module supports the following (only):
|
3 |
Import Platform REST API |
Importing platform packages in v10.7 is limited to files lower than 700KB only when using the Import Platform REST. Importing such platforms from the Platforms page in PVWA has no issue. This will be fixed in an upcoming version. |
ID |
Area |
Description |
---|---|---|
1 |
Hardening |
While running the HardenTLS step as part of PSM hardening the following error appears in the PSMHardening<timestamp> log under c:\windows\temp: “ERR - Failed to add a registry entry with parameter: <param name> and value: 0 to the key: <param path>” |
ID |
Area |
Description |
---|---|---|
1 |
Salesforce |
Auditing of user activities within the classic mode is only for actions performed by SF administrators within the Setup area and not for actions performed by privileged business users within the business areas (such as Sales or Support) |
2 |
Social Media applications |
Capturing posted text is supported only for ASCII characters. Other text will be captured but presented unclear in PVWA |
3 |
Microsoft Azure |
Switching between privileged accounts using the Switch User option in Azure is disabled. To use Azure with a different privileged account, the user must log out and log in again with the new privileged account. |
4 |
Google Cloud Platform (GCP) |
Switching to a non-privileged account in a session is not supported. To use GCP with a non-privileged account, the user must log out and log in again with the non-privileged account, or use separate browsers for the different accounts. |
5 |
Login |
The application account password cannot contain double-quote (") or backslash (\) characters. Refer to the End User > Privileged Single Sign On > PSM for Cloud section in the Online Help Center |
6 |
Login |
The application username is case sensitive. Ensure that when logging in to an application, the <vault_user>:<application_account_user> is entered in the same way as defined for the account in the Vault. |
ID |
Area |
Description |
---|---|---|
1 |
PTA Agent |
Running the PTA Agent in parallel to the Microsoft Network Monitor agent will result in failures |
2 |
PTA Agent |
The procedure to import the PTA Server to a new PTA instance is not supported from version 10.5 |
Version 10.6
ID | Area | Description |
---|---|---|
1 |
Distributed Vaults |
When upgrading PVWA in a Distributed Vaults environment, the PVWA must be directed to the Primary Vault and not the Satellite Vault during the upgrade process. |
2 |
UI |
The Copy Password function is not supported when using PVWA in the Microsoft Edge browser. Passwords can be copied from the Show Password window in the new UI. |
3 |
Distributed Vaults |
If using PVWA version 10.6 with Vault version 10.5, when using Distributed Vaults administrative actions should be accessed only on a PVWA connected to the Master Vault. |
ID | Area | Description |
---|---|---|
1 |
Loosely Connected Devices platform |
Customer that are using the Loosely Connected Devices feature (versions 10.2 and above) and are managing 300 machines or above might encounter an issue where Accounts managed by the CPM in the Loosely Connected Devices platform are not rotated or are stuck in a status of pending rotation although the password was already changed on the target and in the vault. This was fixed in version v10.6 and we recommend anyone using LCD platform management to upgrade to this version. |
ID | Area | Description | ||
---|---|---|---|---|
1 |
Chrome-based connection components |
When using Google Chrome version higher than 64 on the PSM Server, Chrome-based connection components fail to connect. This can be fixed with a manual procedure. See ‘Appendix A - Support Google Chrome versions for Chrome- based PSM connectors'.
|
ID | Area | Description |
---|---|---|
1 |
Social Media applications |
Capturing posted text is supported only for ASCII characters. Other text is captured but presented unclear in PVWA. |
ID | Area | Description |
---|---|---|
1 |
Disaster Recovery |
|
2 |
Upgrade |
To upgrade to 10.5.1 and higher, the current PTA version must be 3.95 and higher |
Version 10.5
ID | Area | Description |
---|---|---|
1 |
Distributed Vaults |
When upgrading PVWA in a Distributed Vaults environment, the PVWA must be directed to the Primary Vault and not the Satellite Vault during the upgrade process. |
2 |
Upgrade |
After upgrading to v10.5, a new folder called ServerLogs appears. This folder contains the last Logic Container log file before the upgrade. This folder can be deleted after the upgrade if it is no longer needed. |
ID | Area | Description |
---|---|---|
1 |
PAS Deployment Scripts |
The new PVWA Deployment scripts are intended to be used only with new installations. These scripts should not be used in installations where a previous version of PVWA was installed. |
2 |
Translation |
Not all strings are translated, and are defaulted to English, This will be resolved with a language package that will be made available after the release. |
ID | Area | Description |
---|---|---|
1 |
Plugin |
Python based plugins (usages PMPasswordFile, SSHPrivateKey) do not work on Windows Server 2016 OOTB if run by PMTerminal. A workaround is available. |
ID | Area | Description | ||
---|---|---|---|---|
1 |
Syncing multiple LOBs |
The Synchronizer will fail to restart if more than 10 LOBs are defined in the Vault even if some of them were previously synced to Conjur. |
||
2 |
Syncing multiple LOBs |
When multiple LOBs are created simultaneously (usually during a first sync), the following error message may be seen in the logs. This error is recoverable and will be fixed in the next sync cycle.
|
Version 10.4
ID | Area | Description |
---|---|---|
1 |
Restore |
Restoring one Safe from incremental backups may fail due to duplicate entries. (Error ITATS611E) In the meantime, using full backup to restore one Safe works. Full Vault restore works from either full or incremental backup. |
ID | Area | Description |
---|---|---|
1 |
System Health Monitoring |
When working in Distributed Vaults architecture, the System Health Monitoring page can only be viewed from the PVWA that is connected to the Master Vault. |
2 |
System Health Monitoring |
Does not support Cluster Vaults. |
3 |
Upgrade |
There is an issue upgrading from v9.9 There are two workarounds:
|
4 |
Windows Authentication |
When running on Windows Server 2016, Windows authentication will not work the first time it is clicked to authenticate returning an error message. On the second try the authentication will succeed. |
5 |
Internationalization |
The new user interface does not support internationalization. In version 10.4 the PVWA will always be displayed in English. Internationalization support will be added in future versions. |
ID | Area | Description |
---|---|---|
1 |
Plugin |
Python based plugins (usages PMPasswordFile, SSHPrivateKey) do not work on Windows Server 2016 if run by PMTerminal. |
2 |
Plugin |
Telnet 32 bit, utilized in Unix via SSH platform, does not work when excluding the CPM bin folder in DEP. Need to disable DEP to use this capability. |
ID | Area | Description |
---|---|---|
1 |
Recordings Player |
In Internet Explorer, when you click Play to play a recordings of a PSM session, session details on the v9 interface will appear and you can play the session recording there. To return to the v10 interface, use the back button on your browser. |
Version 10.3
ID | Area | Description |
---|---|---|
1 |
Restore |
Restore one safe from incremental backups may fail due to duplicate entries. (Error ITATS611E) In the meantime: Using full backup to restore one safe works Full Vault restore works from either full back or incremental backup. |
2 |
Network Configuration |
When running Vault on Windows 2016, the network adapter icons are not visible in the Control Panel > Networking and Internet\Network Connections. To make networking changes: In the Services window, enable and start the following services:
|
ID | Area | Description |
---|---|---|
1 |
Monitoring module – PSM recording player (classic interface) |
The new user interface is now supported on Internet Explorer 11 browser. Exception for that is the option to play a recording video, which is supported on Chrome browser only. Customers who require Internet Explorer for viewing the recordings can leverage the classic v9 user interface. A refresh is needed after playing a recording from 'recording sessions' grid when using Internet Explorer. |
2 |
System Health Monitoring |
When working in Distributed Vaults architecture, the System Health Monitoring page can be viewed from the PVWA that is connected to Master Vault. |
3 |
System Health Monitoring |
Does not support Cluster Vaults. |
4 |
Upgrade |
There is an issue upgrading from v9.9 There are two workarounds:
|
5 |
Windows Authentication |
When running on Windows Server 2016, Windows authentication will not work at the first time it is clicked to authenticate returning an error message. On the second try the authentication will succeed. |
ID | Area | Description |
---|---|---|
1 |
Plugin |
Python based plugins (usages PMPasswordFile, SSHPrivateKey) do not work on Windows Server 2016 if run by PMTerminal. |
2 |
Plugin |
Telnet 32 bit, utilized in Unix via SSH platform, does not work with only excluding CPM bin folder in DEP. Need to disable DEP to use this capability. |
ID | Area | Description |
---|---|---|
1 |
Secure file transfer through PSMP with WinSCP and other SFTP clients |
Error messages lack information of the exact issue that occurred. |
ID | Area | Description |
---|---|---|
1 |
Recording |
While using Vault 10.2, recording uploads might fail in previous versions of OPM on Solaris UltraSPARC. Upgrading to the latest version of OPM will solve the issue. |
ID | Area | Description | ||
---|---|---|---|---|
1 |
Upgrade to PTA 3.95 |
PTA 3.95 upgrade requires at least 50% of the machine storage capacity to be free, for the migration to a new DB structure. If there is not enough free space during the upgrade to 3.95, the upgrade stops.
|
||
|
PAS bypass detections |
False positive / negative results can occur in the following use cases:
|
||
|
Automatic Password Reconciliation |
Configuring the automatic password reconciliation is available for customers with PVWA version 9.7, but it is only supported for customers with version 9.95 and above. |
Version 10.2
ID | Area | Description |
---|---|---|
1 |
Restore |
Restore one safe from incremental backups may fail due to duplicate entries. (Error ITATS611E) In the meantime: Using full backup to restore one safe works Full Vault restore works from either full back or incremental backup |
ID | Area | Description |
---|---|---|
1 |
Monitoring module – PSM recording player |
The new user interface is now supported on Internet Explorer 11 browser. Exception for that is the option to play a recording video, which is supported on Chrome browser only. Customers that require Internet Explorer for viewing the recordings can leverage the v9 user interface. |
2 |
System Health Monitoring |
When working in Distributed Vaults architecture, the System Health Monitoring page can be viewed from the PVWA that is connected to the Master Vault. |
3 |
System Health Monitoring |
Does not support Cluster Vaults. |
4 |
Upgrade |
There is an issue upgrading from 9.9 to 10.1 and 10.2. There are two workarounds:
|
ID | Area | Description |
---|---|---|
1 |
Recording |
While using Vault 10.2, recording uploads might fail in previous versions of OPM on Solaris UltraSPARC. Upgrading to the latest version of OPM will solve the issue. |
ID | Area | Description |
---|---|---|
1 |
Accounts fetching and loading |
Only accounts that have the required file categories are loaded to PTA ('Username', 'Address', 'DeviceType' for accounts of Operating Systems, and 'Username', 'Address', 'DeviceType', 'Database' for accounts of Databases) |
2 |
Managed Account detection |
When the database account username, address and instance name are the same for different databases on the same machine and only one of them is managed, PTA will not differentiate between the accounts |
3 |
Automatic Password Reconciliation |
Configuring the automatic password reconciliation is available for customers with PVWA version 9.7, but it's only supported for customers with version 9.95 and above. |
Version 10.1
ID | Area | Description |
---|---|---|
1 |
End user new interface |
The new interface is supported:
|
2 |
Auditor new interface: Monitoring |
The new interface for Monitoring does not support:
|
ID | Area | Description | ||
---|---|---|---|---|
1 |
Automatic Session Mitigation |
Terminate, suspend or resume session automatically (from PTA or from the external use of a REST API) is supported for PSM sessions only (not PSMP). |
||
2 |
New UI for PSM Connections |
The New Interface for Accounts supports:
|
||
3 |
PSM Connect |
While reason is optional and there are more user parameters defined with default values, the End User must enter a reason.
|
ID | Area | Description |
---|---|---|
1 |
Threat Detection policies |
No Block option for the following rules:
|
2 |
Inboxes |
Events triggered by files that have a policy that contains a Publisher, in some cases are filtered out from the Inbox, even if the Publisher has not been verified, or if the Publisher has failed the verification process. |
3 |
Policy creation |
Cannot create Policies based on copied macOS audit events. |
4 |
macOS Agent |
On High Sierra (10.13), the process to create a user with elevated system preference ends without the user being created. |
5 |
Agent configurations |
Customers with agent’s version prior to v6.4, when selecting AD user/group information in the agent configuration page need to use Browse option (EPM plugin) or type the user SID manually. |
6 |
Advanced Policy |
In Advanced Policy, configuring Parent Process condition for script files does not applied on them. |
7 |
One Time Run Authorization |
Entering a Public Certificate to the Agent Configuration can only be done in Chrome. Internet Explorer does not support multi line, causing the Public Certificate to be cut when it is pasted into the input box. Workaround to work with IE: Paste the copied Public Certificate to notepad, remove all enters (making it a single line) and then paste the single line Public Certificate to the Agent Configuration. |