Forums MyID knowledge base MY0386 Persisted key could not be found after updating keys stored on an nCipher HSM in a multi-server environment

Tagged: , ,

  • This topic is empty.
Viewing 1 post (of 1 total)
  • Author
    Posts
  • #3384
    MyID Support
    Keymaster

    Issue:

    After configuring customer keys (GP or 9B) that are nCipher HSM protected, there are intermittent errors about GP and/or 9B keys being missing or incorrect during Collect Card (error 85122) .  An error message similar to “Info: Persisted key could not be found” is being recorded in the System Events report.

    Resolution:

    When keys are generated or imported, files are created in the nCipher kmdata\local folder on the application server that triggered the generation/import of the key.  These files need to be shared to the other application servers in a multi-server environment.

    When the nCipher “Remote File System” feature is configured, these files are shared automatically across servers in the same “security world”. More information can be found in your nCipher documentation.

    If this is not configured, the files need to be copied manually to the other MyID application servers. Otherwise sessions that get routed through the MyID application servers without the updated files will not be able to make use of the keys.

Viewing 1 post (of 1 total)
  • The forum ‘MyID knowledge base’ is closed to new topics and replies.