Symptom
External user authentication through SSH will fail for Firepower Device Manager managed virtual FTD devices if a SSH AAASetting with a RadiusIdentitySourceGroup was configured prior to a major upgrade.
Conditions
User will hit this bug if they have SSH AAASetting configured to use a RadiusIdentitySourceGroup and perform a major upgrade
Workaround
On Firepower Device Manager, navigate to Management Access. Change the SSH AAASetting to point to the LocalIdentitySource and click save. Then change the SSH AAASetting to point to the RadiusIdentitySourceGroup and save.
Further Problem Description
In order to get SSH External Authentication working on Firepower Device Manager after a major upgrade, the customer will have to re-apply the RadiusIdentitySourceGroup to the SSH AAASetting and save. After the save, the customer should be able to login to the device with external RADIUS users.