<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN OS 10.2.3-h4 Issue SSH CLI disconnect after user AD auth success in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/562066#M1965</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we downgrade to 10.1.x, will it work ? please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 12:13:45 GMT</pubDate>
    <dc:creator>Bharath_A</dc:creator>
    <dc:date>2023-10-17T12:13:45Z</dc:date>
    <item>
      <title>PAN OS 10.2.3-h4 Issue SSH CLI disconnect after user AD auth success</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/547999#M1447</link>
      <description>&lt;P&gt;Anyone facing the same issue like us, PAN OS 10.2.3-h4, SSH CLI session got disconnected after we login as user AD auth (User Authentication Successful). Is it bug not yet reported?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 09:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/547999#M1447</guid>
      <dc:creator>Yoekleng</dc:creator>
      <dc:date>2023-07-03T09:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 10.2.3-h4 Issue SSH CLI disconnect after user AD auth success</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/548187#M1459</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Yoekleng,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is a limitation in 10.2 where for security reasons centos have disallowed usernames with numbers only and PANOS depends on that Centos functionality to store usernames for authorization purposes. --&amp;gt;&amp;gt; "Fully numeric usernames and usernames . or .. are also disallowed" is the CentOS behavior change by&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.webconn.tech/kb/are-all-numeric-usernames-allowed-in-almalinux-8:" target="_blank" rel="noopener nofollow noreferrer" data-aura-rendered-by="8109:0"&gt;https://www.webconn.tech/kb/are-all-numeric-usernames-allowed-in-almalinux-8:&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Usernames may contain only lower and upper case letters, digits, underscores, or dashes. They can end with a dollar sign. Dashes are not allowed at the beginning of the username. Fully numeric usernames and usernames. or .. are also disallowed. It is not recommended to use usernames beginning with. character as their home directories will be hidden in the ls output. In regular expression terms: [a-zA-Z0-9_.][a-zA-Z0-9_.-]*[$]? --&amp;gt;&amp;gt; There are good reasons to enforce it:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://unix.stackexchange.com/questions/287077/why-cant-linux-usernames-begin-with-numbers" target="_blank" rel="noopener nofollow noreferrer" data-aura-rendered-by="8109:0"&gt;https://unix.stackexchange.com/questions/287077/why-cant-linux-usernames-begin-with-numbers&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So this behavior is per design and functionality. --&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;WORKAROUND: We can add a symbol along with letters to the numbers the Admin Username then works. For example, 12345676890_A&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 05:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/548187#M1459</guid>
      <dc:creator>sawjain</dc:creator>
      <dc:date>2023-07-05T05:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 10.2.3-h4 Issue SSH CLI disconnect after user AD auth success</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/562066#M1965</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we downgrade to 10.1.x, will it work ? please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 12:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/562066#M1965</guid>
      <dc:creator>Bharath_A</dc:creator>
      <dc:date>2023-10-17T12:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 10.2.3-h4 Issue SSH CLI disconnect after user AD auth success</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/562854#M1992</link>
      <description>&lt;P&gt;Hi Bharath,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try and test at your end. However, It is not recommended to downgrade since the latest release fixed a bug and vulnerabilities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Yoekleng.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 07:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-os-10-2-3-h4-issue-ssh-cli-disconnect-after-user-ad-auth/m-p/562854#M1992</guid>
      <dc:creator>Yoekleng</dc:creator>
      <dc:date>2023-10-24T07:12:05Z</dc:date>
    </item>
  </channel>
</rss>

