Troubleshooting initialization issues for Dedicated Key Protect
Review solutions to common errors you might encounter while initializing a Dedicated IBM Key Protect instance.
Why do I get an Unable to obtain plug-in's metadata error?
Unable to obtain plug-in's metadata error during KP CLI plugin install or upgrade
If you receive the following error when you install the IBM Key Protect CLI plugin:
Installing binary...
FAILED
Unable to obtain plug-in's metadata. Error: exit status 1
Linux environment
Install or update the libstdc++ system library with GLIBCXX version 3.4.26 or later from your distribution's package manager. Use the following example installation commands:
- Ubuntu/Debian:
apt-get update && apt-get install libstdc++6 - RHEL/Fedora/CentOS:
yum install libstdc++ - Alpine:
apk add --no-cache gcompat libstdc++
If this does not resolve the error, contact Key Protect support.
Windows or macOS environment
Contact Key Protect support.
Why do I get a command failed with error code: e00bad05 error?
command failed with error code: e00bad05 error
If an ibmcloud kp crypto-unit command returns the following error:
FAILED
command failed with error code: e00bad05
This error might indicate that your system is not compatible with the ibmcloud kp crypto-unit feature. The recommended system requirements are:
- Windows: AMD64 (Windows 10 or later)
- Linux: AMD64 (Debian, Ubuntu, Red Hat)
- macOS: ARM64 (Apple Silicon)
Systems outside this list might still be compatible with the ibmcloud kp crypto-unit feature. If you want to confirm compatibility with your specific system, or if the e00bad05 error persists despite meeting the recommended
system requirements, contact Key Protect support.
Why do I get an HTTP 503 no healthy upstream error?
HTTP 503 no healthy upstream error
If calls to Key Protect operations return HTTP 503 with the message no healthy upstream: no crypto units are in kms-initialized state at this time, the following causes are possible:
- You have not yet completed the Dedicated initialization steps.
- You completed the Dedicated initialization steps, but need to wait a few minutes for Key Protect to recognize the newly
kms-initializedcrypto units. - You have only one crypto unit in
kms-initializedstate, and that crypto unit is down for maintenance. - You uploaded mismatched master key material to one or more crypto units.
Why do I get a context deadline exceeded error?
If CLI commands return the error context deadline exceeded (Client.Timeout exceeded while awaiting headers), you set KP_TARGET_ADDR to a private endpoint from a system that does not meet private endpoint requirements.
To resolve this error:
- Use the public endpoint from the Getting the endpoint and instance ID step.
- If you intend to use the private endpoint, see Private endpoints for information about making calls to the private endpoint.
Why do crypto unit commands fail to apply to all crypto units?
If the crypto-unit claim, crypto-unit master-key import, or crypto-unit user add --type kmsCryptoUser commands fail to apply to all crypto units, you might see output similar to the following example:
Executing operation Generate Master Key against CryptoUnit with ID fadedbee-0000-0000-0000-1234567890ab
OK
Executing operation Generate Master Key against CryptoUnit with ID addedace-0000-0000-0000-1234567890ab
FAILED
To resolve this issue:
-
By default, the
claim,master-key import, anduser addcommands attempt to apply to all crypto units. If these commands are only partially successful (applied to only a subset of the crypto units in the instance), retry the command only against the crypto units that returned a failure. Each of these commands can be configured to target specific crypto units. To determine how to target specific crypto units, append-hto anycrypto-unitcommand to view the help text, or see the CLI reference. -
Run the
kp crypto-unitscommand in the CLI reference to confirm that all crypto units are in the same state.- If crypto unit states are mismatched, see Crypto unit states.
- If any crypto unit is in
maintenancestate, retry thekp crypto-unitcommands at a later time.