Try To Import Key On OKM And It Not Working
(Doc ID 2694397.1)
Last updated on JULY 30, 2020
Applies to:Oracle Key Manager - Version 2.5.1 to 3.3 [Release 2.0 to 3.0]
Information in this document applies to any platform.
A two KMA cluster running OKM 2.5.1 had to be upgraded because of a new SL4000 library that was added to the environment.
( Certain tape drives from the SL3000 were moved to the SL4000. )
Only one KMA was upgraded to OKM 3.3.2 and during the upgrade the encryption keys of the existing drive agents were successfully converted ( and migrated ) to the OKM 3.3.2 database.
The customer was advised to run an additional step of importing the keys by means of the transfer partner process just to make sure all keys are migrated to the OKM 3.3.2 environment.
However, the transfer partner process resulted to duplicate key errors:
The OLD-SITE KMA has the same data units as the NEW-SITE KMA.
The Audit event log has messages like these, implying that that the data units have been imported to the NEW-SITE-KMA:
353324E5E8F66F040000000000033186 353324E5E8F66F04 NEWKMA01 Data Unit Management Operations Medium Term Retention Key Sharing Worker Thread Import Keys Key already exists Warning 000259000249
2020-07-08 18:46:44.27066+00 su x.x.x.210 Data Unit ID = 9D4A1907AD5221131C268DCC53379F58, External Unique ID = (null), External Tag = XXX034, Key ID = 9D4A1907AD5221130614B90A9B5979FF365CC3576943AF9B46752FFCD85C,
Transfer Partner ID = OLDKMA01 A key in the Key Transfer file already appears in the local Cluster. Check to see which Data Units reside in both Clusters and export from the remote Cluster Data Units that do not already appear in the local Cluster.
353324E5E8F66F040000000000033185 353324E5E8F66F04 NEWKMA01 Data Unit Management Operations Medium Term Retention Key Sharing Worker Thread Import Keys Data Unit already exists Warning 000259000163
2020-07-08 18:46:44.27066+00 su x.x.x.x.210 Data Unit ID = 9D4A1907AD5221131C268DCC53379F58, External Unique ID = (null), External Tag = XXX034, Transfer Partner ID = OLDKMA01 No recommended action
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document