vault auth failure

573 views
Skip to first unread message

govindaraj

unread,
Sep 13, 2016, 3:32:43 PM9/13/16
to vault...@googlegroups.com
Hi All,

I initialized Vault (3 servers) on newly built Datacenter. I unsealed vault. But when i try to auth it is throwing the error as shown below. For some reason leader election is not happening. We have consul to store the Key/Value.Thoughts?


```
vault: 2016/09/13 19:29:29 [INFO] core: acquired lock, enabling active operation
vault: 2016/09/13 19:29:29 [WARN]: consul: Concurrent state change notify dropped
vault: 2016/09/13 19:29:29 [INFO] core: post-unseal setup starting
vault: 2016/09/13 19:29:29 [INFO] core: mounted backend of type generic at secret/
vault: 2016/09/13 19:29:29 [INFO] core: mounted backend of type cubbyhole at cubbyhole/
vault: 2016/09/13 19:29:29 [INFO] core: mounted backend of type system at sys/
vault: 2016/09/13 19:29:29 [INFO] rollback: starting rollback manager
vault: 2016/09/13 19:29:29 [INFO] core: pre-seal teardown starting
vault: 2016/09/13 19:29:29 [INFO] rollback: stopping rollback manager
vault: 2016/09/13 19:29:29 [INFO] core: pre-seal teardown complete
2016/09/13 19:29:29 [ERR] core: post-unseal setup failed: error fetching default policy from store: failed to read policy: decryption failed: cipher: message authentication failed
```

```
# vault auth
Token (will be hidden):
Error validating token: Error making API request.

Code: 503. Errors:

* no active Vault instance found
```


--

Thanks & Regards
Govindaraj Venkatesan

Jeff Mitchell

unread,
Sep 13, 2016, 3:34:50 PM9/13/16
to vault...@googlegroups.com
Hi Govind,

It appears something has tampered with your data, because decryption
is failing due to MAC failure. How was this set up? Where did the data
come from?

Best,
Jeff
> --
> This mailing list is governed under the HashiCorp Community Guidelines -
> https://www.hashicorp.com/community-guidelines.html. Behavior in violation
> of those guidelines may result in your removal from this mailing list.
>
> GitHub Issues: https://github.com/hashicorp/vault/issues
> IRC: #vault-tool on Freenode
> ---
> You received this message because you are subscribed to the Google Groups
> "Vault" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to vault-tool+...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/vault-tool/CAPnj__hXqeTCGQS_vCZRdDf_4CjV%3D0n7xAg-jELe5ZNMa3Tuog%40mail.gmail.com.
> For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages