PageSourceSearch

https://ratify.dev/assets/js/8586594d.fbc3d357.js

js ratify.dev collected 2026-09-24 19:27:33 UTC 6,675 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[1581],{28453(e,r,n){n.d(r,{R:()=>o,x:()=>s});var t=n(96540);const i={},a=t.createContext(i);function o(e){const r=t.useContext(a);return t.useMemo(function(){return"function"==typeof e?e(r):{...r,...e}},[r,e])}function s(e){let r;return r=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:o(e.components),t.createElement(a.Provider,{value:r},e.children)}},56679(e,r,n){n.r(r),n.d(r,{assets:()=>c,contentTitle:()=>s,default:()=>u,frontMatter:()=>o,metadata:()=>t,toc:()=>l});const t=JSON.parse('{"id":"troubleshoot/key-management-provider/kmp-tsg","title":"Troubleshoot Key Management Provider Errors","description":"Please use `kubectl get` or `kubectl describe` command to retrieve the error.","source":"@site/versioned_docs/version-1.3/troubleshoot/key-management-provider/kmp-tsg.md","sourceDirName":"troubleshoot/key-management-provider","slug":"/troubleshoot/key-management-provider/kmp-tsg","permalink":"/docs/1.3/troubleshoot/key-management-provider/kmp-tsg","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.3/troubleshoot/key-management-provider/kmp-tsg.md","tags":[],"version":"1.3","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"Key Management Provider","permalink":"/docs/1.3/category/key-management-provider"},"next":{"title":"Verifier","permalink":"/docs/1.3/category/verifier"}}');var i=n(74848),a=n(28453);const o={},s="Troubleshoot Key Management Provider Errors",c={},l=[{value:"CERT_INVALID",id:"cert_invalid",level:3},{value:"Scenario 1",id:"scenario-1",level:4},{value:"Cause and Solution",id:"cause-and-solution",level:5},{value:"Access Denied",id:"access-denied",level:3},{value:"Scenario 1",id:"scenario-1-1",level:4},{value:"Cause and Solution",id:"cause-and-solution-1",level:5}];function d(e){const r={br:"br",code:"code",h1:"h1",h3:"h3",h4:"h4",h5:"h5",header:"header",p:"p",pre:"pre",strong:"strong",...(0,a.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(r.header,{children:(0,i.jsx)(r.h1,{id:"troubleshoot-key-management-provider-errors",children:"Troubleshoot Key Management Provider Errors"})}),"\n",(0,i.jsxs)(r.p,{children:["Please use ",(0,i.jsx)(r.code,{children:"kubectl get"})," or ",(0,i.jsx)(r.code,{children:"kubectl describe"})," command to retrieve the error."]}),"\n",(0,i.jsx)(r.pre,{children:(0,i.jsx)(r.code,{className:"language-bash",children:"kubectl get keymanagementproviders.config.ratify.deislabs.io -o yaml\nkubectl describe keymanagementproviders.config.ratify.deislabs.io\n"})}),"\n",(0,i.jsx)(r.p,{children:"or"}),"\n",(0,i.jsx)(r.pre,{children:(0,i.jsx)(r.code,{className:"language-bash",children:"kubectl get namespacedkeymanagementproviders.config.ratify.deislabs.io -n <namespace> -o yaml\nkubectl describe namespacedkeymanagementproviders.config.ratify.deislabs.io -n <namespace>\n"})}),"\n",(0,i.jsx)(r.h3,{id:"cert_invalid",children:"CERT_INVALID"}),"\n",(0,i.jsx)(r.p,{children:"This error is returned when Ratify fails to parse certificate fetched from Key Management Provider."}),"\n",(0,i.jsx)(r.h4,{id:"scenario-1",children:"Scenario 1"}),"\n",(0,i.jsxs)(r.p,{children:["Brieferror:       failed to get certificates fro...\nError:            failed to get certificates from secret bundle:",(0,i.jsx)(r.br,{}),"\n","Original Error: (",(0,i.jsx)(r.strong,{children:"pkcs12: expected exactly two items in the authenticated safe"}),"),",(0,i.jsx)(r.br,{}),"\n","Error: cert invalid,",(0,i.jsx)(r.br,{}),"\n","Code: ",(0,i.jsx)(r.strong,{children:"CERT_INVALID"}),",",(0,i.jsx)(r.br,{}),"\n","Plugin Name: azurekeyvault, Component Type: certProvider,",(0,i.jsx)(r.br,{}),"\n","Detail: ",(0,i.jsx)(r.strong,{children:"azure keyvault key management provider: failed to convert PKCS12 Value to PEM"}),". Certificate default, version b81be595959f46fbb1c704018d29aca8",(0,i.jsx)(r.br,{}),"\n","Issuccess:        false"]}),"\n",(0,i.jsx)(r.h5,{id:"cause-and-solution",children:"Cause and Solution"}),"\n",(0,i.jsx)(r.p,{children:"PKCS12 format certs in Key Vault with nonexportable private keys causes a parsing failure because Go is hardcoded to expect a private key. We recommend switching to PEM certs."}),"\n",(0,i.jsx)(r.h3,{id:"access-denied",children:"Access Denied"}),"\n",(0,i.jsx)(r.p,{children:"This error occurs when Ratify fails to fetch certificates from akv provider due to permissions issues."}),"\n",(0,i.jsx)(r.h4,{id:"scenario-1-1",children:"Scenario 1"}),"\n",(0,i.jsx)(r.p,{children:"Reconciler error KeyManagementProvider=gatekeeper-system/kmp-akv controller=keymanagementprovider controllerGroup=config.ratify.deislabs.io controllerKind=KeyManagementProvider error=Error fetching certificates in KMProvider kmp-akv with azurekeyvault provider"}),"\n",(0,i.jsxs)(r.p,{children:["error: failed to get secret objectName",":Certname",", objectVersion:, error: keyvault.BaseClient#GetSecret: Failure responding to request: StatusCode=403,\n",(0,i.jsx)(r.code,{children:'Original Error: autorest/azure: Service returned an error. Status=403 Code="Forbidden" Message="The user, group or application \'appid=app;iss=https://sts.windows.net/tenant_id/\' ***does not have secrets get permission*** on key vault \'keyvaultname;location=eastus\'. For help resolving this issue, please see https://go.microsoft.com/fwlink/?linkid=2125287" InnerError={"code":"***AccessDenied***"}'})]}),"\n",(0,i.jsx)(r.h5,{id:"cause-and-solution-1",children:"Cause and Solution"}),"\n",(0,i.jsx)(r.p,{children:"When a certificate is created, an addressable key and secret are also created with the same name. Ratify requires secret permissions to retrieve the public certificates for the entire certificate chain. Please configure keyvault policy for the identity with command below."}),"\n",(0,i.jsx)(r.pre,{children:(0,i.jsx)(r.code,{className:"language-bash",children:"az 
1keyvault set-policy --name ${AKV_NAME} \\\n--secret-permissions get \\\n--object-id ${IDENTITY_OBJECT_ID}\n"})}),"\n",(0,i.jsx)(r.p,{children:"Since the permission change is external to ratify, you MUST manually trigger a fetch operation by deleting and applying the CR again."}),"\n",(0,i.jsx)(r.pre,{children:(0,i.jsx)(r.code,{className:"language-bash",children:"kubectl get keymanagementproviders.config.ratify.deislabs.io/kmp-akv -o yaml > my_kmp_akv.yaml\nkubectl delete keymanagementproviders.config.ratify.deislabs.io/kmp-akv\nkubectl apply -f my_kmp_akv.yaml\n"})})]})}function u(e={}){const{wrapper:r}={...(0,a.R)(),...e.components};return r?(0,i.jsx)(r,{...e,children:(0,i.jsx)(d,{...e})}):d(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.