Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-71-1626541.1
Update Date:2016-08-22
Keywords:

Solution Type  Technical Instruction Sure

Solution  1626541.1 :   Oracle Key Manager (OKM): SCA6000 Card Shows Error in OKM Console GUI  


Related Items
  • Sun StorageTek Crypto Key Management System
  •  
Related Categories
  • PLA-Support>Sun Systems>TAPE>Backup Software-Filesystems>SN-TP: Encryption
  •  


Customer says his KMA shows an error under HSM status in his OKM gui.

In this Document
Goal
Solution
References


Created from <SR 3-8579088401>

Applies to:

Sun StorageTek Crypto Key Management System - Version All Versions and later
Information in this document applies to any platform.

Goal

 How to troubleshoot the SCA6000 card in a KMA.

Solution

1. Determine which KMA in the cluster has the status.

2. Verify the KMA has an installed SCA6000 card. (Look at the system dump for the sca6000info.txt file)

    It should show you something like this...
    Getting SCA device version information, command line is: /usr/sbin/scadiag -v mca0 Device mca0 version      numbers: Hardware : 1.6.6 Bootrom : 1.0.10 Firmware : 1.1.8
    .....
    Trying to log into the SCA key slot...
    PKCS11 Error: [00000005] (General error)
    PKCS11 Error: [00000190] (Cryptoki is not initialized)
    PKCS11 Error: [00000190] (Cryptoki is not initialized)
    PKCS11 Error: [00000190] (Cryptoki is not initialized)
    **means the card is not working correctly**

3. A reboot from the ELOM/ILOM redirection console is usually a good first step.
    Log onto the KMA as security officer and select the reboot option from the menu.

4. After the reboot, log into the KMA in question and look at the KMA list, what
is the status now?
     a. Inactive - look to see if the KMA is locked, if it is, unlock the KMA and refresh
         the KMA list. Should now see "Hardware" in the HSM status. (now this is fixed)
     b. Error - means the SCA6000 card has probably failed. Get another system dump and
         verify by looking at the sca6000info.txt file.

6. If the card has failed to initialize, then open a field service task and have the card replaced.


 

References

<NOTE:1447111.2> - Information Center: Oracle Key Manager (KMS/OKM) Overview Advisor

Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback