Troubleshoot pkcs11_kms Issues
Use these procedures to troubleshoot error conditions that may be encountered when using OKM with pkcs11_kms.
Cannot Retrieve the Master Key When Using pkcs11_kms
Use these steps to correct when the Oracle Database reports the master key cannot be retrieved (error ORA-28362 & ORA-06512).
Loss of the pkcs11_kms Configuration Directory
Use this procedure to recover a lost or corrupted pkcs11_kms token profile.
No Slots Available Error When Using pkcs11_kms
Use this procedure when the client gets "No Slots Available" errors when issuing any PKCS#11 operation.
- Ensure that the kmscfg utility has run successfully.
- Ensure that the pkcs11_kms provider has been properly installed and configured.
CKA_GENERAL_ERROR Error When Using pkcs11_kms
Use this procedure when the client gets the CKA_GENERAL_ERROR error when trying to retrieve keys.
- Verify that the agent has a default key group in the OKM cluster.
- Review the $KMSTOKEN_DIR/KMSAgentLog.log file for more information.
Could Not Open PKCS#12 File Error
Use this procedure when the "Could not open PKCS#12 file" error appears in the $KMSTOKEN_DIR/KMSAgentLog.log file.
- Select audit events in the OKM cluster to determine whether the agent passphrase has recently changed.
- Remove the <profile-name> directory under $KMSTOKEN_DIR.