vault failures with message authentication failed after migrating the vault database

1,307 views
Skip to first unread message

tirumalesh killamsetty

unread,
Feb 12, 2018, 12:28:33 AM2/12/18
to Vault
Hi Team,

I am using vault with couchdb storage and after migrating my vault including its database from system A to system B , I am seeing below errors.

==> Vault server configuration:

                     Cgo: disabled
              Listener 1: tcp (addr: "0.0.0.0:8200", cluster address: "0.0.0.0:8201", tls: "enabled")
               Log Level: info
                   Mlock: supported: true, enabled: true
                 Storage: couchdb
                 Version: Vault v0.8.3
             Version Sha: 6b29fb2b7f70ed538ee2b3c057335d706b6d4e36

==> Vault server started! Log data will stream in below:

2018/02/09 19:35:06.229103 [INFO ] core: vault is unsealed
2018/02/09 19:35:06.231922 [ERROR] core: failed to get cluster details: error=decryption failed: cipher: message authentication failed
2018/02/09 19:35:06.231955 [ERROR] core: cluster setup failed: error=decryption failed: cipher: message authentication failed
2018/02/09 19:35:06.231974 [WARN ] core: vault is sealed
2018/02/09 19:35:13.228887 [INFO ] core: vault is unsealed
2018/02/09 19:35:13.230798 [ERROR] core: failed to get cluster details: error=decryption failed: cipher: message authentication failed
2018/02/09 19:35:13.230870 [ERROR] core: cluster setup failed: error=decryption failed: cipher: message authentication failed
2018/02/09 19:35:13.230909 [WARN ] core: vault is sealed

Vishal Nayak

unread,
Feb 12, 2018, 6:06:12 AM2/12/18
to vault...@googlegroups.com
Hi Tirumalesh,

Vault is successfully getting unsealed but is failing to read the
`core/cluster/local/info` path. By the looks of it, the cluster
information file is being detected but not able to be decrypted. I'd
check if the migration has not resulted in any data loss.

Regards,
Vishal
> --
> This mailing list is governed under the HashiCorp Community Guidelines -
> https://www.hashicorp.com/community-guidelines.html. Behavior in violation
> of those guidelines may result in your removal from this mailing list.
>
> GitHub Issues: https://github.com/hashicorp/vault/issues
> IRC: #vault-tool on Freenode
> ---
> You received this message because you are subscribed to the Google Groups
> "Vault" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to vault-tool+...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/vault-tool/950d11e6-c15b-460d-a779-99886fca4e91%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.



--
vn
Reply all
Reply to author
Forward
0 new messages