Description

This article explains why and provides solution for when a Juniper Networks switch shows the error message "pam_unix pam_sm_authentication refused" after software upgrade/downgrade while trying to authenticate remotely with non-root account that relies on remote server.

Symptoms

This happens because the previously committed configuration (prior to upgrade/downgrade) is not compatible with newly installed software version or simply contains errors that must be corrected before committing while running on the new version. As consequence of this, the authentication fails, and you may have to access the switch through console.

Solution

With console access, enter configuration mode and perform "commit check" to identify which must be rectified before successful commit. Then commit the configuration already corrected. This could restore remote authentication through external servers and everything should be operating as expected as configuration is fully applied/committed.

Modification History

09/14/2023 - KB created.