When authenticating to Linux systems joined with Safeguard Authentication Services (SAS/VAS), the first login attempt may fail with an “invalid password” message. A second, immediate attempt succeeds with the same credentials and no changes.
This may be observed during SSH login or other PAM-based authentication workflows, including automation or job execution tools that authenticate through PAM.
The issue is tracked under defect 695296.
A product defect (ID: 695296) in SAS can cause the initial SSH login to fail even when the credentials are valid. The failure occurs during service ticket acquisition (after TGT issuance). It is not caused by incorrect passwords, access control configuration, or group membership changes.
Defect 695296 has been addressed in Safeguard Authentication Services 7.0.
Upgrade the affected systems to Safeguard Authentication Services 7.0 or later.
The Safeguard Authentication Services 7.0 Release Notes list defect 695296 as resolved. The fix updates vasd so that during the initial login it retries the ticket request with the implicit and explicit Service Principal Names (SPNs).
Workaround (until upgrade) :
Retry the SSH login. The second attempt should succeed.
If using automation/orchestration tools (for example, Ansible),the following can be tried : configure a single authentication retry to mitigate user impact until the product fix is applied.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center