Skip to main content
Trailblazer
August 5, 2026
Question

Password rotation on Linux and AIX servers failing

  • August 5, 2026
  • 3 replies
  • 103 views

Hello everyone,

After reinstalling the resource brokers in our environment, I began noticing intermittent failures during automatic password rotations on managed Linux and AIX systems.

Error recorded in the resource broker logs and console:
"The connection was closed by the server. Make sure you are connecting to an SSH or SFTP server."

Error recorded in the managed systems' sshd logs:
"Jul 28 04:30:43 Server01 sshderror: kex_exchange_identification: Connection closed by remote host"

Both errors occurred at the same date and time.

Has anyone else encountered this behavior?
Could this be resolved using the "Enable legacy algorithms for SSH account management tasks" option found under Configuration > Privileged Access Management > Miscellaneous?
According to KB0017016, "The option Enable legacy algorithms for SSH account management tasks enables legacy encryption, MAC, and key exchange (Kex) algorithms that were previously enabled in Password Safe".

If anyone has experienced this, I would greatly appreciate any insights that could help me resolve the issue.

Currently I’m on version 25.3.

3 replies

tclowater
BeyondTrust Employee
BeyondTrust Employee
August 14, 2026

Hey ​@rgkessel - just for sanity checking - you’ve also submitted this to support, correct? While we do appreciate digging in before reaching out to support, a lot of my time discussing troubleshooting involves trying to encourage people to go to support sooner rather than later in the investigation process. 

rgkesselAuthor
Trailblazer
August 14, 2026

Hello ​@tclowater.

Yes, I opened a support ticket before bring the question here. However, the response I received didn't give me the confidence to proceed with activating this option.

So, I decided to ask here if anyone else had activated it and what the result was.

tclowater
BeyondTrust Employee
BeyondTrust Employee
August 21, 2026

Totally fair! Sorry it’s taken a bit to get back to you. The only last item I’d check in on is with the systems administrators to validate the key exchanges they use, and if they are anticipating this encryption requirement. While I can’t for certain state it’s going to fix everything to enable that, it’s something I’d like to have had a heads up on when I was the linux admin.