A localized space to talk about EPM, specifically for Unix & Linux.
Recently active
The following articles were published last week. New Knowledge Base Articles: KB0021676 - Error: pbguid Exiting failed to read settings file /etc/pb.settings - general SQL error "
Hi All,I’m trying to add clients/servers to the RNS Service Hosts but I’m not able to do it and I couldn't find relevant documentation around it. Can you please help. It is a dev environment, and I currently have 2 servers. First one is hosting all components and RNS. When I try to add servers or clients to the service groups. I don't find the other host. When I try to install the components using any of the default client registration profiles. Installation getting failed. Below is the installation error:
Hi All,Could you please clarify whether REST API port 24351 (pbrestport) needs to be configured for bidirectional communication between BIUL and all hosts (including the policy server and endpoints), or if it should be set up as unidirectional—from BIUL to all hosts, or from all hosts to BIUL? Thanks
The following articles were published last week. New Knowledge Base Articles: KB0022889 - SSH connections fail using pbrun in profile.d scripts (VSCode) KB0022904 - EPM-UL install fails "Error this installation is for Privilege Management for Unix & Linux package creation"
The following articles were published last week. New Knowledge Base Articles: KB0021256 - EPM-UL pbbench fails with error 8523 Client failure in SSL_connect - Unable to initilize SSL to policy server KB0021403 - EPM-UL error - 3811.3 This server is not a License Server KB0021407 - How identify roles contains specific hostgroup for EPM-UL KB0021421 - 3802.2 Invalid parameter - must supply reason message KB0021475 - REST (Pbconfigd) processes not running on hosts after upgrading from BIUL 21.1 to 23.1
How to install EPM-UL agent on AIX using package installer Listed below is a summary of steps for installing the Endpoint Privilege Management for Unix and Linux (EPM-UL) agent on an AIX server using the package installer. In this article EPM-UL version 22.2 is used however, these steps are good for other versions of EPM-UL as well. In the below example, a runhost and submithost are set up and there is already a primary policy server setup that will be specified.For further install instructions, please review AIX Install Procedure. Copy the following files to the /opt/ directory AIXSRV client PMUL_aix_22.2.0-07.tar.Z PMUL_aix_22.2.0-07_pkg.tar.Z Uncompress the files gunzip PMUL_aix_22.2.0-07.tar.Z gunzip PMUL_aix_22.2.0-07_pkg.tar.Z Make sure you are in /opt directory and extract the tar files: cd /opt/ tar -xvf PMUL_aix_22.2.0-07.tar tar -xvf PMUL_aix_22.2.0-07_pkg.tar This will create the powerbroker directory. Change the directory to the following: cd /opt/powerbroker/v22.2/PMUL_a
The following articles were published last week. New Knowledge Base Articles: KB0022740 - pbrun fails with error "Cannot access sharedlibsolarisprojects /usr/lib/libproject.so" KB0022781 - "3430 Insecure operation" error when installing epml-cachedclient or epm-client packages KB0022785 - Linux Server with Palo Alto firewall fail to connect with error 3003.01 Could not connect to a policy server daemon KB0022793 - Is EPM-UL vulnerable to libssl and libcurl CVE-2024 vulnerabilities ? KB0022800 - Is YK38 compatible with EPM-UL? Are there any risks? KB0022807 - Does CVE-2025-7425 Use-After-Free vulnerability in libxslt affect EPM-UL?
The following articles were published last week. New Knowledge Base Articles: KB0021406 - Is EPM-UL affected by CVE-2022-41556?
Onboarding Linux/Unix Servers and Local Linux/Unix Accounts. There are specific deployment steps required to onboard Linux or Unix systems, as well as local Linux accounts. See details below Pre-deployment steps to be done on the Linux or Unix machine You must create an account to be used as the functional account. This account can be a local account or an Active Directory account that can login to the Linux or Unix system. A functional account must be set up to change passwords and have elevated privileges. Elevated privileges can be set up for the functional account to use sudo, pbrun or pmrun. You will need to create a scan account. Check the machine to see if there are any custom prompts or banners with the prompt character in them. If there is then you will need to make changes to the custom platform. Workflow to add Systems and Accounts Create Address Group Login to Web console as a BeyondTrust administrator Navigate to Configuration > DISCOVERY MANAGEMENT > Addre
The following articles were published last week. New Knowledge Base Articles: KB0021379 - Does CVE-2024-6387 affect Endpoint Privilege Management? KB0022672 - pbevent.log is not updating
The following articles were published last week. New Knowledge Base Articles: KB0022671 - EPM Cloud for Linux (EPM-L SaaS) clients do not show in the console after pbactivate has been run
EPM Unix & Linux (UL) Supported Versions Lifecycle and OS Compatibility Information The tables below detail the operating systems that are fully supported and actively maintained for Endpoint Privilege Management for Unix and Linux (EPM-UL). These EPM-UL versions will be updated if necessary to fix problems with functionality and enhancements. In line with the other BeyondTrust products, EPM-UL releases are supported for 2 years from the initial Certified date. File names are structured as <Release Identifier>.tar.Z where the <Release Identifier> is pmul_<OS Version>-<Release Number>. Important: Before any clients are upgraded to the latest release, it's recommended that the license, policy, and log servers are upgraded to the latest release. EPM-L (SaaS) - Non-cached clients EPM-UL Version Certified Date End of Support 25.1.4 May 2025 Apr 2027 25.1.3 Apr 2025 Apr 2027 25.1.2 Mar
The following articles were published last week. New Knowledge Base Articles: KB0022541 - Constrains violation when installing PMUL with RNS "4012.01 Failed set Host in Registry Name Service" KB0022544 - Is it possible to manage the password for pblight? KB0022549 - Why does the pblighttpd.log file need execute permissions?
The following articles were published last week. New Knowledge Base Articles: KB0022138 - Deploying Beyondinsight for Unix and Linux (BIUL)
How to Activate Policy Caching for EPM-UL Below are the steps to activate policy caching for Endpoint Privilege Management for Unix and Linux (EPM-UL) , to convert clients to cached clients. These steps are specific to clients and not servers and can only be performed on on-premise versions of EPM-UL. The SaaS version (EPM-L) requires a full build on the clients if switching. Note: These steps cannot be performed on the SaaS version (EPM-L, this will result in a conflict error"{noformat}# rpm -Uv ./epml-cachedclient.x86_64.rpmerror: Failed dependencies:epml-client conflicts with epml-cachedclient-25.1.0.04-1.x86_64epml-cachedclient conflicts with (installed) epml-client-25.1.0.04-1.x86_64{noformat}"the non-cached client will need to be uninstalled and reinstalled as a cached client. Warning: It is strongly recommended to test this in a non-production environment first. Ensure the EPM-UL server is set to allow caching. This can be confirmed by checking the /etc/pb.settings file . R
The following articles were published last week. New Knowledge Base Articles: KB0022371 - Unable to elevate with EPM-UL and sudo - Error 8523 Client failed to contact remote host
Introducing Pathfinder BeyondTrust is introducing Pathfinder, our new unified interface that brings together our powerful security solutions under a single login and integrated experience for operational agility that brings shared context across all our products. This interface will enable organizations to better manage identity security across their heterogeneous environments and ensure critical assets are protected from all angles. Security teams will benefit with a unified platform for faster incident response, intelligent recommendations, and streamlined workflows to reduce risks and gain operational efficiency. Managing cybersecurity in today’s complex threat landscape requires a comprehensive, integrated approach that enables security teams to effectively find, control, and protect all paths to privilege. For more information, please check out our press release and platform page:BeyondTrust Pathfinder Delivers a One-Platform Approach to…Pathfinder Platform | BeyondTrust Latest A
The following articles were published last week. New Knowledge Base Articles: KB0022130 - Unable to use Sudo commands. Client licensing error - No space left on device KB0022139 - pbrun24.1.4-05[2730476]: Could not connect to run host
The following articles were published last week. New Knowledge Base Articles: KB0021293 - Session not authorized due to licensing constraints KB0022177 - Unable to to use pbrun after upgrade to OEL 8.9 "8057.01 PAM SESSION Error: PAM session start failure"
The following articles were published last week. New Knowledge Base Articles: KB0021479 - Could not create any of the 1 tasks requested Received "expected installer was not found"
The following articles were published last week. New Knowledge Base Articles: KB0021979 - How to activate policy caching for EPM-UL
Greetings! I'm Phillip Lehner, the Senior Director of Education at BeyondTrust, and I'm thrilled to lead our efforts in delivering exceptional learning experiences. I'm excited to share how we're elevating your journey with a new, streamlined method of accessing training: Success Included with BeyondTrust University. At BeyondTrust University, we believe our customers deserve nothing short of excellence in the tools they use. That’s why we’ve launched 'Success Included' — to elevate your learning experience and ensure you achieve success with BeyondTrust’s solutions. Success Included is an education program that makes foundational knowledge accessible to customers at no additional cost. It features easy-to-follow, self-paced eLearning courses that empower system administrators to configure and manage BeyondTrust products using industry best practices. Our goal is to equip learners with the knowledge needed to maximize the value of their investment with BeyondTrust. Because your
EPM-L and EPM-UL have extensive ability to log privilege access and sessions. You can use the pbsh and pbksh to log and record unprivileged session, however the problems with that are twofold. Firstly, the pb-shell environments are incompatible with Advanced Control and Audit rules, and secondly, the shell environments are out-of-date compared to modern shell environments. They lack modern features like command argument completion, wildcard completion, directory history stack and others due to their age. Maybe a modern shell environment like bash, zsh or fish will get integrated into the product.The first issue is easily taken care of by normal DAC file system permissions, they are unprivileged users after all. The second issue is more complex and could be solved by just forcing people to use pbksh, but there is a method of logging which is secure, and respects the users choice of shell. That is by using a combination of PAM (the Linux Pluggable Authentication Modules) and auditd.Audit
Hi Team, I am trying PMUL and want to ask if i can block any standard command without pbrun. Example:I want to block the standard ping but without using pbrun ping.ping 8.8.8.8 should be rejected. But for now, i can only reject if user executed pbrun ping 8.8.8.8.Can we do that in PMUL? (right now, i am using role-based policies)I have a case from end-user, they want to block all kind of command except 2 or 3 specific commands.Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.