Common issues and how to resolve them
|
Issue |
Possible Cause |
Resolution |
|---|---|---|
|
Invalid OCID |
An incorrect or incomplete OCI OCID has been provided in the ESKM OCI-BYOK cloud instance configuration. |
Verify the Tenancy OCID, User OCID, Compartment OCID, and Vault OCID in the OCI Console and ensure that the values entered in ESKM are complete and correct. |
|
Failed to verify the HTTP(S) Signature |
The OCI API signing credentials configured in ESKM are invalid or do not correspond to the API signing key registered for the OCI user. |
Verify that the Private Key, User OCID, and Fingerprint configured in ESKM correspond to the same OCI API signing key. Verify that the corresponding public key is registered for the OCI user in OCI. |
|
Authentication or authorization failure |
The OCI user does not have the required permissions to access the configured Vault or perform the requested key management operation. |
Verify the IAM configuration and ensure that the OCI user used for the integration has the required permissions for the target Vault and key management operations. |
|
Vault cannot be accessed |
The configured Vault OCID, compartment, or region is incorrect, or the OCI user does not have access to the Vault. |
Verify the Vault OCID, Compartment OCID, and Region in the ESKM configuration and verify that the OCI user has access to the target Vault. |
Log locations and interpretation
You can verify the logs from Utimaco ESKM by following the steps below:
-
In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > REST.
-
In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > Audit.
-
In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > System.
-
Review the REST, Audit and System logs for operations performed during the OCI-BYOK integration.
-
Verify that the OCI requests and corresponding key management operations are completed successfully.