---
name: openshift-ts-cluster-vpn
title: Why does the cluster master return a VPN server error?
description: '[Virtual Private Cloud] [Classic infrastructure]'
last-updated: 2026-02-18
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/openshift?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Why does the cluster master return a VPN server error?
{: #rhoks_ts_openvpn_login}
{: support}

[Virtual Private Cloud]{: tag-vpc} [Classic infrastructure]{: tag-classic-inf} 


After you create or update a cluster, the master status returns a VPN server configuration error message similar to the following example.
{: tsSymptoms}

```sh
VPN server configuration update failed. IBM Cloud support has been notified and is working to resolve this issue.
```
{: screen}


The infrastructure credentials that are associated with the resource group that the cluster is created in are missing (such as the API key owner is no longer part of the account) or missing required permissions.
{: tsCauses}


[Complete the troubleshooting guide](https://cloud.ibm.com/docs/openshift?topic=openshift-cluster_infra_errors&format=markdown) to check and update the infrastructure credentials that are used for the resource group.
{: tsResolve}