<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New VM asks for password using SSH in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533827#M1837</link>
    <description>&lt;P&gt;we are having s simlier issue, with or without management swap at instance launch state, firewall still asking for password. Launched almost 10 firewalls (BYOL, bundle2) and same behavior. tried to change the pem key aswell, no luck. this is really frustrating, I have launched couple of paloalto firewalls in the past but never experienced like this. anyone found the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 19:05:46 GMT</pubDate>
    <dc:creator>RPendela</dc:creator>
    <dc:date>2023-03-09T19:05:46Z</dc:date>
    <item>
      <title>New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/298364#M700</link>
      <description>&lt;P&gt;I;ve installed a new firewall using Bundle 1, I get this error with a new VM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of them worked correctly, but after I killed it, I started to get these issues. Any idea what can be wrong?&lt;/P&gt;&lt;P&gt;The PEM key is the proper one, created when I launched the machine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to happen after I killed the first "bundle 1 machine" and it said trial expired, I re subscribed (hourly rate) but I still can;t get to the machines&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;➜  Downloads ssh -i paloalto.pem admin@REDACTEDIP -v
OpenSSH_7.9p1, LibreSSL 2.7.3
debug1: Reading configuration data /Users/xxx/.ssh/config
debug1: /Users/xxx/.ssh/config line 1: Applying options for *
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 48: Applying options for *
debug1: Connecting to REDACTEDIP [REDACTEDIP] port 22.
debug1: Connection established.
debug1: identity file paloalto.pem type -1
debug1: identity file paloalto.pem-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_7.9
debug1: Remote protocol version 2.0, remote software version OpenSSH_12.1
debug1: match: OpenSSH_12.1 pat OpenSSH* compat 0x04000000
debug1: Authenticating to REDACTEDIP:22 as 'admin'
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: ecdh-sha2-nistp256
debug1: kex: host key algorithm: ssh-rsa
debug1: kex: server-&amp;gt;client cipher: aes128-ctr MAC: umac-64-etm@openssh.com compression: none
debug1: kex: client-&amp;gt;server cipher: aes128-ctr MAC: umac-64-etm@openssh.com compression: none
debug1: sending SSH2_MSG_KEX_ECDH_INIT
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ssh-rsa SHA256:+qi4tx18hKBnH3R12SYeAF2XtsL1df+A+3EHsabgYi0
debug1: Host 'REDACTEDIP' is known and matches the RSA host key.
debug1: Found key in /Users/xxx/.ssh/known_hosts:40
debug1: rekey after 4294967296 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey after 4294967296 blocks
debug1: Will attempt key: paloalto.pem  explicit
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,password,keyboard-interactive
debug1: Next authentication method: publickey
debug1: Trying private key: paloalto.pem
debug1: Authentications that can continue: publickey,password,keyboard-interactive
debug1: Next authentication method: keyboard-interactive
Password: &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 21:49:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/298364#M700</guid>
      <dc:creator>nronica</dc:creator>
      <dc:date>2019-11-13T21:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/298372#M702</link>
      <description>&lt;P&gt;In all honestly, waiting longer and reconnect your SSH session.&amp;nbsp; You will get the password prompt during the firewall start-up which could take 10-15 minutes.&amp;nbsp; Once you log in with the pem file you should set a password and commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure&lt;/P&gt;&lt;P&gt;set mgt-config users admin password&lt;/P&gt;&lt;P&gt;commit&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 21:51:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/298372#M702</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2019-11-13T21:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/511786#M1645</link>
      <description>&lt;P&gt;Running into this same issue. We've let it sit for days, re-spun it up with a different AMI (10.1.3, and 10.1.6), and still the same issue. It worked once, and now will not again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 20:54:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/511786#M1645</guid>
      <dc:creator>jwainwright</dc:creator>
      <dc:date>2022-08-12T20:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/511787#M1646</link>
      <description>&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 20:54:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/511787#M1646</guid>
      <dc:creator>jwainwright</dc:creator>
      <dc:date>2022-08-12T20:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533827#M1837</link>
      <description>&lt;P&gt;we are having s simlier issue, with or without management swap at instance launch state, firewall still asking for password. Launched almost 10 firewalls (BYOL, bundle2) and same behavior. tried to change the pem key aswell, no luck. this is really frustrating, I have launched couple of paloalto firewalls in the past but never experienced like this. anyone found the solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 19:05:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533827#M1837</guid>
      <dc:creator>RPendela</dc:creator>
      <dc:date>2023-03-09T19:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533831#M1838</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71965"&gt;@RPendela&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our issue turned out that you cannot turn off the ec2 instance metadata, or force HTTPS tokens on the ec2 instance metadata endpoint. This is because the palo uses this endpoint to grab the public key to add to the user at launch. They should code the bootstrap process to use the IMDBS tokens.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 19:24:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533831#M1838</guid>
      <dc:creator>jwainwright</dc:creator>
      <dc:date>2023-03-09T19:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533832#M1839</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-options.html" target="_blank"&gt;https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-options.html&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 19:25:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533832#M1839</guid>
      <dc:creator>jwainwright</dc:creator>
      <dc:date>2023-03-09T19:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: New VM asks for password using SSH</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533839#M1840</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71965"&gt;@RPendela&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does the prompt say?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 20:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/new-vm-asks-for-password-using-ssh/m-p/533839#M1840</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-09T20:36:31Z</dc:date>
    </item>
  </channel>
</rss>

