![]() | Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition | ||
|
|
![]() |
||||||||||||||||
Solution Type Technical Instruction Sure Solution 1626541.1 : Oracle Key Manager (OKM): SCA6000 Card Shows Error in OKM Console GUI
Customer says his KMA shows an error under HSM status in his OKM gui. In this Document
Created from <SR 3-8579088401> Applies to:Sun StorageTek Crypto Key Management System - Version All Versions and laterInformation in this document applies to any platform. GoalHow to troubleshoot the SCA6000 card in a KMA. Solution1. Determine which KMA in the cluster has the status.
2. Verify the KMA has an installed SCA6000 card. (Look at the system dump for the sca6000info.txt file) It should show you something like this... Getting SCA device version information, command line is: /usr/sbin/scadiag -v mca0 Device mca0 version numbers: Hardware : 1.6.6 Bootrom : 1.0.10 Firmware : 1.1.8 ..... Trying to log into the SCA key slot... PKCS11 Error: [00000005] (General error) PKCS11 Error: [00000190] (Cryptoki is not initialized) PKCS11 Error: [00000190] (Cryptoki is not initialized) PKCS11 Error: [00000190] (Cryptoki is not initialized) **means the card is not working correctly** 3. A reboot from the ELOM/ILOM redirection console is usually a good first step. Log onto the KMA as security officer and select the reboot option from the menu. 4. After the reboot, log into the KMA in question and look at the KMA list, what is the status now? a. Inactive - look to see if the KMA is locked, if it is, unlock the KMA and refresh the KMA list. Should now see "Hardware" in the HSM status. (now this is fixed) b. Error - means the SCA6000 card has probably failed. Get another system dump and verify by looking at the sca6000info.txt file. 6. If the card has failed to initialize, then open a field service task and have the card replaced.
References<NOTE:1447111.2> - Information Center: Oracle Key Manager (KMS/OKM) Overview AdvisorAttachments This solution has no attachment |
||||||||||||||||
|