Auto Light Dark
Auto Light Dark

Troubleshooting

Common Issues and How to Resolve Them

Issue

Possible Cause

Resolution

External Vault cannot be created or verified

The External Vault URL, Private Endpoint, or OAuth configuration is incorrect or the external KMS is not reachable from OCI.

Verify the External Vault URL, Private Endpoint, and OAuth configuration. Verify that the external KMS is accessible through the configured Private Endpoint and that the required CA bundle is correct.

OAuth authentication failure

The OAuth client credentials or Identity Provider configuration are invalid or do not correspond to the OCI Identity Domain configured for the integration.

Verify the Client ID, Client Secret, Identity Domain URL, and OAuth configuration in both OCI and the external KMS. Verify that the configured OAuth scope is correct.

Private Endpoint connection failure

The VCN, subnet, destination IP/FQDN, port, or CA bundle configured for the Private Endpoint is incorrect, or the external KMS is not reachable through the configured network.

Verify the VCN, Subnet, KMS IP/FQDN, and Port configured for the Private Endpoint. Verify that the external KMS is listening on the configured port and that the required CA certificate is valid.

Key Reference cannot be created or used

The external key identifier is incorrect, the key does not exist in the external KMS, or the external KMS configuration does not allow OCI to access the key.

Verify the External Key ID in the external KMS and ensure that the key is available and enabled. Verify the tenancy, Identity Provider, OAuth client, and External Vault configuration.

Key Reference rotation fails

The specified external key version does not exist or the latest key version is not available to OCI through the external KMS.

Verify that the required key version exists in the external KMS and is available for use. If no External Key Version ID is specified, verify that the latest key version is available in the external KMS.

Cryptographic operation fails

The HYOK key is disabled or unavailable in the external KMS, or the External Vault/Key Reference configuration is incorrect.

Verify the status of the key in the external KMS and ensure that it is enabled and available. Verify the External Vault and Key Reference configuration and check the ESKM logs for the corresponding request.


Log Locations and Interpretation

You can verify the logs from Utimaco ESKM by following the steps below:

  1. In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > REST.

  2. In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > Audit.

  3. In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > System.

  4. Review the REST, Audit and System logs for operations performed during the OCI-HYOK integration.

  5. Verify that the OCI requests and corresponding key management operations are completed successfully.