The audit messages in this section are from the Cryptographic Security Platform Vault Management Appliance, the Cryptographic Security Platform Vault for Cloud Keys, the Cryptographic Security Platform Vault for Databases, and the Cryptographic Security Platform Vault for VM Encryption.

There are many audit messages produced by Cryptographic Security Platform Vault. Many of these are informative and require no action. In the table below, we list many of the audit messages and show:

  • Whether an Alert is also generated.
  • The severity (L=Low, M=Medium, H=High).
  • What the resolution is if any action should be taken.
  • In the Message column,

    • a %s represents a string value. For example, in the following message:

      Added user %s to group %s

      The actual message will be displayed with the name of the user and group, for example:

      Added user fred to group IT
    • a value in braces, such as {user_name}, represents a placeholder that is replaced with an actual value. For example, in the following message:

      '{user_name}' created the policy '{policy_name}'

      The actual message will be displayed with the name of the user and policy, for example:

      'Fred' created the policy 'Default_Policy'

Msg ID

Message

Severity

Alert?

Description

Resolution

Category

Tags

1

System License installed.

L

false

A new license has been uploaded and installed.


Security

Licensing

2

Begin System Initialization

L

false



Security


3

Created group %s

M

false

The specified admin group has just been created.


Security

Account

4

Created Domain %s

L

false

This message appears during initialization of the first KeyControl node.


Security

Cluster

5

Added user %s to group %s

M

false

The user shown has been added to the specified admin group.


Security

Account

6

Expired password for user %s

H

false

A password has expired for the specified user.

The specified user needs to log in to the WebGUI and change his/her password.

Security

Account

7

User %s logged out from ipaddr %s

L

false

The specified user has just logged out from the IP address shown.


Security

Account

8

Changed following attributes for user Security Administrator :- Password, Password Expiration Date, Password History List

M

false

One or more of the listed attributes has been changed for the user.


Security

Account

9

Changed SMTP Auth Settings

M

false

Email settings have been modified.


Security

Configuration

10

EKS has been removed, not destroying old admin keypair

M

false

Permission to use External Key Store has been removed. The old Admin Key was NOT removed on the EKS to allow restoration of older backups.

Informational only. Restore or add new access if so desired.

Security

EKS, KMIP

11

Regenerated Admin Key. The generation count of this key is %s. Reason: %s

H

true



Security


12

Created Cloud Virtual Machine Set %s

L

false



Security


13

Could not create Cloud Virtual Machine Set %s, HTCC server connection not configured

M

false



Security

HTCC, Boundary Control

14

Masterkey Recovered on node %s

H

true



Security


15

User %s logged in from ipaddr %s

L

false

The specified user has just logged in from the IP address shown.


Security

Account

16

Repeated log in failures for %s from ipaddr %s

H

true

There have been a succession of log in failures for the specified user.

A security admin should check whether the correct user has been trying to log in or not.

Security

Account

17

Account disabled for %s due to repeated log in failures

H

true

The number of failed log in attempts has reached the maximum allowed value.

A security admin needs to reset the account to enable access.

Security

Account

18

Server registration failed -- No license Installed

H

true



Security

Licensing

19

Attempt to register a new %s server "%s" failed -- licensed limit reached.

H

true

The number of KeyControl servers is already at the limit imposed by the license. An attempt is being made to another node.

A new license will be required before the number of nodes in the cluster can be extended. Please contact hytrust.support@entrust.com

Security

Licensing

20

Storage Pool %s Filestore %s on server %s is low on space.

H

true



Clusters


21

Changed following Settings :- %s

M

false



Security


22

Changed following attributes for group %s :- %s

M

false

One or more of the listed attributes has been changed for the group shown.


Security

Account

23

Virtual Machine %s authenticated

L

false

A virtual machine has registered or re-authenticated.

This message is in response to direct admin actions. No action is required.

Security

Reauth

24

Virtual Machine %s created in group %s

L

false



Security


25

Removed Server %s from Cloud %s

L

false



Security


26

Created Cluster Info %s

L

false



Security


27

Removed Cluster Info %s

L

false



Security


28

Activated account for user %s

M

false

A user's account has been activated.


Security

Account

29

Disabled account for user %s

H

false

A user's account has been disabled.

A security admin should check to see if the account should be enabled again.

Security

Account

30

Created user %s

M

false

The specified user has been created.


Security

Account

31

Deleted user %s

M

false

The specified user has been deleted.


Security

Account

32

Renamed user %s to %s

L

false

A username has been modified.


Security

Account

33

Deleted group %s

L

false

The specified group has been deleted.


Security

Account

34

Renamed group %s to %s

L

false

An admin group has been renamed.


Security

Account

35

Removed user %s from group %s

M

false

The specified user has been removed from the group shown.


Security

Account

36

Using EKS for MasterKey protection

M

false

An External Key Store has been configured to protect the Admin Key.


Security

EKS, KMIP

37

Admin Key regeneration failed. Failed to use external KMIP Server for MasterKey protection

M

true

An External Key Store has been configured to protect the Admin Key but access was not allowed for keypair creation.

EKS denied access to create/retrieve an RSA keypair. Please check KMIP settings and configuration.

Security

EKS, KMIP

38

Could not register to HTCC, htcc server, password and log in must be specified

H

false



Security

Boundary Control

39

Could not register to HTCC %s: HTCC log in failed

H

false



Security

Boundary Control

40

Could not register to HTCC %s. Please check user privileges and Boundary Control License on HTCC

H

false



Security

Boundary Control

41

Successfully registered with HTCC Server %s

M

false



Security

Boundary Control

42

Keyid %s has %s

H

true

Keyid has expired and/or rotated. Keys only expire if a Cloud Admin has explicitly set them to expire.


Security

KeyID

43

The Key for disk %s Virtual Machine %s has %s

H

true

A key for the specified virtual machine has either expired or been rotated. Keys only expire or rotate if a Cloud Admin has explicitly set them to expire or rotate.


Security

KeyID

44

Key in VMSet %s on VMV %s has %s

M

true



Security

KeyID

45

Changed following KeyControl cluster settings :- %s

M

false

The name of the cluster has been modified.


Clusters

Domain

46

Deleted Domain %s

M

true



Security

Domain

47

Changed following KPS Settings :- %s

M

false



Security

Configuration

48

Changed following VS Appliance Settings :- %s

M

false



Security


49

Unknown pool %s appeared on VMV, destroying...

M

true



Security


50

Changed following Storage Pool Settings :- %s

M

false



Security


51

Changed following attributes of filestore %s :- %s

M

false



Security


52

Changed following settings for Cluster Info %s :- %s

M

false



Security


53

Coretrace Server %s, changed following attributes :- %s

M

false



Security

CoreTrace

54

Changed following settings for Cloud VM Set %s :- %s

M

false



Security


55

Cloud VM Set %s changed group ownership from %s to %s.

H

false



Security


56

Deleted Cloud VM Set %s

M

false



Security


57

Cloud VM Set %s: added keyid %s using %s cipher

H

false

A virtual machine user has explicitly requested creation of a KeyID using the specified cipher.


Security

KeyID

58

Cloud VM Set %s: Virtual Machine %s removed keyid %s

M

false

A virtual machine user has explicitly requested deletion of the specified KeyID. It has been removed from the specified Cloud VM.


Security

KeyID

59

Cloud VM Set %s: updated keyid %s

L

false

The KeyID description was changed.


Security

KeyID

60

Cloud VM Set %s: Virtual Machine %s attempted to fetch inactive keyid %s

M

false

The KeyID shown has been revoked but an attempt was made to fetch it.

The cloud admin who owns the key should determine whether access should be reinstated or not.

Security

KeyID

61

Cloud VM Set %s: Virtual Machine %s attempted to fetch expired keyid %s

M

false

An attempt has been made to fetch an expired KeyID.

The cloud admin who owns the key should determine whether access should be reinstated or not. This is only possible if the KeyID was set to 'No use?' on expiration.

Security

KeyID

62

Cloud VM Set %s: Virtual Machine %s fetched keyid %s

M

false

A request has been made to access the specified KeyID.


Security

KeyID

63

Revoked permission for keyid %s

M

true

KeyID is currently revoked. It must be activated before use.

The cloud admin who owns the key should determine whether access should be reinstated or not.

Security

KeyID

64

Granted permission for keyid %s

H

true

KeyID has been activated after having been previously revoked.


Security

KeyID

65

Cloud VM Set %s keyid %s updated - description %s

L

false

The description field for the specified KeyID has been updated.


Security

KeyID

66

Cloud VM Set %s keyid %s updated - key expires on %s, onexpiry %s

M

false

The expiration date and effect on expiration for the specified KeyID have been updated.


Security

KeyID

67

Cloud VM Set %s Keyid %s has expired

M

true

The specified KeyID has reached its expiration date.

The owning cloud admin should verify that the KeyID should be no longer used.

Security

KeyID

68

Keyid %s has expired

M

true

A request to access an expired KeyID has been made.

The owning cloud administrator should verify that the KeyID should no longer be used.

Security

KeyID

69

The Key for keyid %s in Cloud VM Set %s expires in %d day(s). Please extend the key life.

M

true

A KeyID is about to expire.

The owning cloud administrator should verify whether the KeyID should expire and, if not, update the expiration date.

Security

KeyID

70

Unable to check keyid %s

M

false

An error occurred while attempting to check properties of KeyID.

An internal error occurred while checking expiration/rotation properties for specific keyid. Informational only, keyid will be checked again.

Security

KeyID

71

Cloud VM Set %s: added fsid %s using %s cipher

M

false



Security


72

Cloud VM Set %s: Virtual Machine %s removed fsid %s

M

false



Security


73

Cloud VM Set %s: Virtual Machine %s updated fsid %s

M

false



Security


74

Revoked permission for fsid %s

M

true



Security


75

Granted permission for fsid %s

M

true



Security


76

Cloud VM Set %s fsid %s updated - key expires on %s, onexpiry %s

M

false



Security


77

Cloud VM Set %s Fsid %s has expired

M

true



Security


78

Properties changed for VMSet %s on server %s (%s)

M

false



Security


79

Virtual Machine %s, changed following attributes: %s

M

false



Security


80

Deleted Virtual Machine %s

L

true



Security


81

Deleted Certificate %s

L

false

An unused certificate was deleted


Security


82

The Virtual Machine %s, could not be checked for geo-location boundary. HTCC log in failed

H

true



Security

Boundary Control

83

The Virtual Machine %s, is not in the geo-location boundary. Key access is denied

H

true



Security

Boundary Control

84

The Virtual Machine %s, is in the geo-location boundary. Key access is granted

M

true



Security

Boundary Control

85

Added Virtual Machine %s, authentication complete

L

true

A virtual machine has completed registration.

This message is in response to direct admin actions. No action is required.

Security

Reauth

86

Added Virtual Machine %s, authentication pending

M

true

A virtual machine has a registration request pending.

The cloud admin needs to complete authentication in the KeyControl WebGUI.

Security

Reauth

87

Removed Server %s from Cloud %s

L

false



Security


88

Renamed Server %s to %s

L

false



Security


89

Virtual Machine %s re-connected, authentication pending

H

true

A virtual machine has a re-authorization request pending.

The cloud admin needs to complete re-authorization in the KeyControl WebGUI.

Security

Reauth

90

Revoked permissions for Virtual Machine %s

M

false



Security


91

Re-authenticated Virtual Machine %s from KPS

M

false

A virtual machine has been re-authorized.

This message is in response to direct admin actions. No action is required.

Security

Reauth

92

Virtual Machine %s added disk %s

L

false

A new disk has been added to the specified virtual machine.


Security

Key

93

Virtual Machine %s removed disk %s

L

true

A disk has been removed from the specified virtual machine.


Security

Key

94

Virtual Machine %s : disk %s renamed to %s

L

false



Security

Key

95

Virtual Machine %s attempted to fetch key for inactive disk %s. %s

L

false

If a disk is not active, no keys will be delivered.


Security

Key

96

Virtual Machine %s attempted to fetch expired key for disk %s. %s

H

false

If a key has expired an attempt by a virtual machine to fetch the key will fail.

The cloud admin should determine whether the expiration date should be extended. This does not apply to shredded keys.

Security

Key

97

Virtual Machine %s fetched key for disk %s. %s

L

false

A key for the specified disk has been requested by the virtual machine shown.


Security

Key

98

Virtual Machine %s created key for disk %s using %s cipher

L

false

A disk has been encrypted. The type of cipher is shown.


Security

Key

99

Virtual Machine %s revoked permission for disk %s

M

true



Security

Key

100

Virtual Machine %s granted permission for disk %s

M

true



Security

Key

101

Virtual Machine %s added mount point %s

L

false

An encrypted folder has been mounted.


Security

Key

102

Virtual Machine %s removed fs %s

L

true

An encrypted folder has been removed.


Security

Key

103

Virtual Machine %s attempted to fetch key for inactive fsid %s

M

false

A virtual machine attempted to access an inactive FSID.

The cloud admin should determine whether the FSID should be made accessible.

Security

Key

104

Virtual Machine %s attempted to fetch expired key for fsid %s

H

false

The FSID has expired and therefore the filesystem cannot be mounted.

The cloud admin should determine whether the FSID should be made accessible. This is only possible if the FSID has not been shredded.

Security

Key

105

Virtual Machine %s fetched key for fsid %s

L

false

A filesystem was mounted using the specified FSID.


Security

Key

106

The Key for disk %s Virtual Machine %s has expired

H

true

An attempt is being made to change properties for an already expired key.

The cloud admin should determine whether the key of the disk should be made accessible. This is only possible if the disk's key has not been shredded.

Security

Key

107

Virtual Machine %s set key expiry to %s, onexpiry to %s for disk %s

H

false

An expiration date has been set on a key for the specified disk. The effect taken on expiration is shown.

The cloud admin should determine whether the expiration date should be extended.

Security

Key

108

The Certificate for Virtual Machine %s expire%s %d days%s. Please renew the certificate.

M

true



Security


109

The Key for disk %s Virtual Machine %s has expired

H

true

The key shown for the specified virtual machine has expired.

The cloud admin should determine whether the expiration date should be extended.

Security

Key

110

The Key for disk %s Virtual Machine %s expires in %d day(s). Please extend the key life.

H

true

The encryption key shown is about to expire.

The cloud admin should determine whether the expiration date should be extended.

Security

Key

111

Unable to check key for disk %s Virtual Machine %s

M

false

An error occurred while attempting to check properties of key for the given disk and virtual machine.

An internal error occurred while checking expiration/rotation properties for specified key. Informational only, key will be checked again.

Security

Key

112

Virtual Machine %s rebooted, reauthentication required

H

true

A virtual machine has rebooted and the reboot setting requires that the virtual machine is re-authenticated.

The cloud admin needs to complete re-authorization in the KeyControl WebGUI.

Security

Reauth

113

Virtual Machine %s has new alerts, please check

M

true



Security


114

Added Coretrace policy "%s" to Virtual Machine %s

L

true



Security

CoreTrace

115

Activated Coretrace policy "%s" for Virtual Machine %s

M

false



Security

CoreTrace

116

De-activated Coretrace policy "%s" for Virtual Machine %s

M

false



Security

CoreTrace

117

Modified Coretrace policy "%s" for Virtual Machine %s

M

false



Security

CoreTrace

118

Removed Coretrace policy "%s" for Virtual Machine %s

M

false



Security

CoreTrace

119

Deleted CAStore %s

M

false



Security


120

Removed Server %s from Domain %s

L

false



Clusters

Domain

121

Storage pool %s created on server %s (%s)

L

false



Security


122

Storage pool %s extended on server %s (%s)

L

false



Security


123

Log added to Storage pool %s on server %s (%s)

L

false



Security


124

Log removed from Storage pool %s on server %s (%s)

L

false



Security


125

Storage pool %s deleted from server %s (%s)

L

false



Security


126

Disk added to hot spare list on server %s (%s)

L

false



Security


127

Disk removed from hot spare list on server %s (%s)

L

false



Security


128

Filestore %s created on server %s (%s)

L

false



Security


129

Filestore %s deleted from server %s (%s)

L

false



Security


130

Removed server %s (%s) from domain %s

L

true



Clusters


131

KMIP Server restarted on %s

M

false

The KMIP server has been restarted on the specified host.


Security

KMIPServer

132

KMIP Server started on %s

L

true

The KMIP server has been started on the specified host.


Security

KMIPServer

133

KMIP Server halted on %s

H

true

The KMIP server has been halted on the specified host.


Security

KMIPServer

134

KMIP Server: All client certificates removed

H

true

All client certificates have been removed from the KMIP server.


Security

KMIPServer

135

KMIP Server: Client certificate %s removed

H

true

The specified client certificate has been removed from the KMIP server.


Security

KMIPServer

136

KMIP Server: Client certificate %s updated

M

false

The specified client certificate has been updated on the KMIP server.


Security

KMIPServer

137

KMIP Server: Client certificate %s created

M

true

The specified client certificate has been created on the KMIP server.


Security

KMIPServer

138

Could not store oskey on %s/%s. Needs recovery

H

true

Could not store object store key on joining KeyControl node

KeyControl join did not succeed, node should be removed from cluster. If problem persists contact support.

Clusters

HCAuth

139

Reconnect not allowed for %s/%s. Please follow reauthentication steps

H

true

KC has attempted to reauthenticate with cluster that does not recognize it

KeyControl node likely was in the cluster and removed. Should be re-joined

Clusters

HCAuth

140

Cluster join failed for %s/%s.

H

true

KC has failed to join cluster

KeyControl node join can be attempted again. If problem persists contact support

Clusters

HCAuth

141

Reconnect info does NOT match. Follow reauthentication steps for node %s/%s

H

true

KC has attempted to reauthenticate with cluster but its info has changed

KeyControl node likely needs MasterKey recovery or kicked out of cluster and re-joined

Clusters

HCAuth

142

Could not store connection info for %s/%s

H

true

KC cannot store info to reconnect to cluster on restart

Condition could be transitory, node could be restarted. Also could indicate that KCKeyControl disk is full

Clusters

HCAuth

143

Problem with auth/secd communication

H

true

Communication stack on KC is not working


Clusters

HCAuth

144

System utilities NOT functioning. Authentication will not happen

H

true

Auth daemon unable to query system information


Clusters

HCAuth

145

Attempt to add node %s/%s which has valid data but no clusterid. Please reauthenticate if this is a valid action.

M

true

KC was formerly in a cluster that has no identifying cluster ID

If action is a valid one, proceed with join. Note that the KCKeyControl data on joining node will be destroyed

Clusters

HCAuth

146

Attempt to add node %s/%s which has a different clusterid. Please reauthenticate if this is a valid action.

M

true

KC was formerly in a different cluster than the one it is attempting to join

If action is a valid one, proceed with join. Note that the KeyControl data on joining node will be destroyed

Clusters

HCAuth

147

Could not restore cluster to normal operating mode after adding new node, error $rc

M

true

KC cluster state could not be restored to normal operating state

Can indicate cluster join issues

Clusters

HCAuth

148

CSP Vault Management Server system hostname ($myip) $act.

L

false



Clusters


149

Restricted support log in enabled on hostname

M

true

Restricted support log in was enabled on KC


Security


150

%s support log in enabled on hostname

M

true

Full or Restricted support log in was enabled on KC


Security


151

%s support log in disabled on hostname

M

true

Full or Restricted support log in were disabled on KC


Security


152

KeyControl node {$myip[0]}/{$myhost[0]} has failed upgrade to version {$curver}

H

true

KC upgrade to new version has failed

KeyControl will revert to prior install. Upgrade can be attempted again if valid or contact support

Clusters

Upgrade

153

KeyControl node {$myip[0]}/{$myhost[0]} reverted from {$str[1]} to {$str[2]}

M

true

User initiated revert to previous version has succeeded.


Clusters

Upgrade

154

KeyControl node {$myip[0]}/{$myhost[0]} has successfully upgraded to version {$curver}

M

true

KC upgrade to new version has succeeded.


Clusters

Upgrade

155

KeyControl node {$myip[0]}/{$myhost[0]} has failed upgrade finalization to version {$curver}

H

true

KC upgrade to new version has failed

KeyControl will revert to prior install. Upgrade can be attempted again if valid or contact support

Clusters

Upgrade

156

Hostname %s, Management IP %s, Current Version %s, New Version %s. Upgrade from version {$oldver} (b{$oldrevision}) to version {$curver} (b{$newrevision}) not allowed. Consult product documentation for upgrade procedure

H

true

KC upgrade to this version is not supported from current version

Upgrade to a supported version and/or contact support

Clusters

Upgrade

157

Upgrade from version {$oldver} to version {$curver} not officially supported but allowed for development

L

true

KC upgrade to this version is not officially supported but allowed for development build


Clusters

Upgrade

158

Internal error $ret checking upgrade from {$oldver} to {$curver}

H

true

An error has occurred attempting to valid upgrade

Contact support

Clusters

Upgrade

159

Multiple KeyControl nodes still in cluster. All excess KeyControl nodes must be removed before upgrade.

H

true

Upgrade should be attempted on only a single node cluster

Remove all nodes from cluster except the node to be upgraded

Clusters

Upgrade

160

Insufficient free space to perform upgrade. Consult product documentation for procedure to add another disk

H

true

Disk does not have enough space for upgrade

Consult support for freeing disk space or create/join a node with more space and upgrade that

Clusters

Upgrade

161

System has reverted to prior installation.

L

true

System has successfully reverted to prior version


Clusters

Upgrade

162

Failed revert to prior installation.

H

true

System failed to revert to prior version

Contact support. Current version is still in place

Clusters

Upgrade

163

System utilities NOT functioning.

H

true

Unable to query system info


Clusters


164

Error resizing partition

H

true

An error occurred while resizing the KeyControl storage. Please contact support.


Clusters


165

Error resizing storage pool

H

true

An error occurred while resizing the KeyControl storage. Please contact support.


Clusters


166

Successfully resized KeyControl storage pool

M

false

The storage pool on the KeyControl node was successfully resized.


Clusters


167

KMIP Server operation failed - internal error

M

true

KMIP server operation failed with an internal error.

Consult support or retry operation

Security

KMIPServer

168

%s operation %s for %s on %s, TaskId: %s.

L

false

A task has changed state


Security


169

Virtual Machine %s : disk %s resized to %s

L

false

Virtual Machine disk is resized


Security


170

Virtual Machine %s : KC mapping %s attached

L

false

A KC Mapping is attached to a virtual machine


Security


172

Passwd changed for htadmin

M

true

An admin reset console/htadmin passwd


Security


173

User %s failed to change %s passwd

M

true

An administrator attempted to reset the console/htadmin password, but the operation failed.


Security


174

A support event has occurred on CSP Vault Management node %s. Please create a Support Bundle and include core files as described in the online help, then contact support.

H

true

A support event has occurred. Generate a support bundle and contact Entrust Support for assistance.


Security


175

New certificate created with guid %s in group %s

L

false

A new certificate has been created for use with policy agent or KMIP server


Security


176

Backup created successfully for %s (%s)

L

false

A new backup image has been created on the KeyControl appliance


Clusters


177

Failed to create backup for %s (%s)

M

false

Creation of the backup image failed.

Backup will be retried automatically or can be triggered manually via the WebGUI

Clusters


178

KeyControl Cluster is in normal mode

L

false

The KeyControl cluster state has returned to normal operating mode


Clusters


179

KeyControl Cluster is in degraded mode

H

false

The KeyControl cluster has gone into degraded mode. This occurs when the KeyControl nodes in the cluster are not able to communicate successfully

Check the availability and connectivity of the KeyControl nodes in the cluster

Clusters


180

KeyControl Cluster is in standby mode

L

false

The KeyControl cluster is in a standby state. This is a temporary state which occurs when a node is joining the cluster


Clusters


181

Freespace available on %s has fallen below 2G. Consider increasing the storage capacity of this system.

H

true

The amount of free disk space available to the KeyControl appliance has dropped below our recommended threshold. Please increase the size of the disk or contact support for more assistance

Increase the size of the disk and reboot the KeyControl appliance to resize

Security


182

Login failure for %s from %s

L

false

User unsuccessfully attempted to log in to the KeyControl instance


Security


183

Reboot of %s initiated by %s

M

true

Domain administrator initiated reboot of KeyControl node


Clusters


184

KeyControl node reboot initiated from console

M

true

The KeyControl node was rebooted from the console


Security


185

KeyControl node shutdown initiated from console

M

true

The KeyControl node was shut down from the console.


Security


186

Azure agent: illegal attempt to install plugin

M

true

Azure "extensions" (a.k.a. "plugins") to a KeyControl virtual machine are not allowed


Security


187

Azure agent: illegal attempt to disable or uninstall a plugin

M

true

Azure "extensions" (a.k.a. "plugins") to a KeyControl virtual machine are not allowed


Security


188

%d inactive tasks found on Cloud VM Set %s. %s task for %s on %s not updated since %s, TaskId: %s.

L

true

List of tasks that have not been updated for a long time


Security


189

Updated LDAP configuration: %s

M

false

The values for the given LDAP fields have been updated


Security


190

Virtual Machine %s synchronized devices. Following devices were not found - %s

M

false

The Policy Agent synchronized the registered device list; some devices not found


Security


191

Virtual Machine %s synchronized devices. Reason for sync: %s

M

true

The Policy Agent synchronized the registered device list


Security


192

Virtual Machine %s state for disk %s changed to %s. %s

L

false

Disk state on policy agent changed


Security


193

HyTrust bootloader ssh key updated for %s

L

false

Private key required for ssh log in to Hytrust bootloader updated on KC


Security


194

Two-factor authentication enabled for %s

L

false

Two factor authentication has been enabled for the user


Security


195

Two-factor authentication disabled for %s

M

true

Two factor authentication has been disabled for the user


Security


196

KeyControl Cluster is in degraded mode during node-join

L

false

The KeyControl cluster has gone into degraded mode while a new node is joining the cluster. This occurs as KeyControl restarts communication protocols after a new node has joined the cluster.


Clusters


197

KeyControl Cluster is in degraded mode during node-join

L

false

The KeyControl cluster has gone into normal mode while a new node is joining the cluster. This occurs as KeyControl restarts communication protocols after a new node has joined the cluster.


Clusters


198

New AppLink created to %s

M

true

A new Application Link has been created. This link will allow secure communication between the Entrust products.


Clusters


199

Application link removed for Product (%s) Version (%s) IP List (%s)

L

false

Application link has been removed for the external product.


Clusters


200

admin user logged in successfully

M

false

htadmin account log in successful in one of the KeyControl nodes


Security

Support

201

%s account logged in from

M

false

Full support account log in successful in one of the KeyControl nodes


Security

Support

203

%s account log in failure from -

M

false

Failed attempt to log in to full support account


Security

Support

204

Full support account logged in from and executed

M

false

Full support account log in successful and executed a command


Security

Support

205

%s account log in failure from attempting

M

false

Failed attempt to log in to full support account and execute command


Security

Support

206

Created new log bundle - %s with options - %s

L

false

New log bundle creation has been initiated by some user


Security


207

Downloaded log bundle - %s

L

false

Latest log bundle has been downloaded by some user


Security


208

Exported Cloud VM Set %s

M

false

A Cloud VM Set has been exported


Security


209

Imported Cloud VM Set %s

M

false

A Cloud VM Set has been imported


Security


210

Following guests have unsupported policy agent installed in Cloud VM Set %s: %s(%s)

M

true

A Cloud VM Set has guests with unsupported agent version

Upgrade policy agent on reported guests

Security


211

Unsupported Policy Agent (version %s ) detected on guest %s.

M

false

A guest has an unsupported agent version installed

Upgrade policy agent on reported guest

Security


212

Download of admin key generation %s initiated by %s

M

false

Download of admin key initiated via admin_key GET call


Security


213

Reset of KMIP server initiated

M

false

Reset of KMIP server initiated


Security


214

KMIP Response/Request:

M

false

Create, destroy or revoke of KMIP object initiated


Security


215

KMIP Response/Request:

M

false

Operation on some KMIP object initiated


Security


216

The Certificate for Virtual Machine %s will auto-renew in %d days%s.

L

true



Security


217

The Certificate for Virtual Machine %s failed to auto-renew. Certificate expire%s %d days%s. Please renew the certificate.

H

true



Security


218

Set Key Encryption Key expiry to %s onexpiry to %s, for Cloud VM Set %s. %s Cloud VMs affected.

H

false

An expiration date has been set for Key Encryption Key for the specified Cloud VM Set. The effect taken on expiration is shown.

The cloud admin should determine whether the expiration date should be extended.

Security

Key Encryption Key

219

The Key Encryption Key for Cloud VM Set %s expire%s in %d days%s.

H

true


The cloud admin should determine whether the expiration date should be extended.

Security

Key Encryption Key

220

The Key Encryption Key for Cloud VM Set %s has expired. %s Cloud VMs affected.

H

true

The Key Encryption Key for specified Cloud VM Set has expired.

The cloud admin should determine whether the expiration date should be extended.

Security

Key Encryption Key

221

Access to Key Encryption Key of Cloud VM Set %s has been revoked. %s Cloud VMs affected.

H

true

Access to specified Cloud VM Set has been revoked.


Security

Key Encryption Key

222

Access to Key Encryption Key of Cloud VM Set %s has been granted. %s Cloud VMs affected.

H

true

Access to specified Cloud VM Set has been granted.


Security

Key Encryption Key

223

The Key Encryption Key for Cloud VM Set %s has expired. %s Cloud VMs deleted. Deleted CVM Set %s.

H

true

The Key Encryption Key for specified Cloud VM Set has expired.


Security

Key Encryption Key

224

The Certificate for Virtual Machine %s failed to auto-renew as the Virtual Machine is unreachable.

H

true

The Certificate Auto Renewal of a virtual machine fails if the virtual machine is in auto renewal period and is unreachable.


Security


225

Authentication of Server %s (%s) failed due to incorrect passphrase

H

false

Authentication of KeyControl node failed due to incorrect passphrase.


Security


226

Cloud VM Set creation failed. Error: Failed to store key in HSM. %s

H

true

Cloud VM Set creation failed. Failed to store key in HSM.

A security admin should check whether the HSM connection is configured properly

Security

Key Encryption Key

227

Key Encryption Key import failed. Error: Failed to store key in HSM. %s

H

true

Key Encryption Key import failed. Failed to store key in HSM.

A security admin should check whether the HSM connection is configured properly

Security

Key Encryption Key

228

Failed to fetch Key Encryption Key from HSM. Error: %s

H

true

Failed to fetch Key Encryption Key from HSM.

A security admin should check whether the HSM connection is configured properly

Security

Key Encryption Key

229

Successfully imported Key Encryption Key for Cloud VM Set %s.

M

false

Successfully imported Key Encryption Key


Security

Key Encryption Key

230

Removed Domain %s from group %s

L

false

Removed Domain from group


Security


231

Authenticated Server %s (%s)

L

false

New KeyControl node has been successfully authenticated and added to the cluster


Clusters


232

Added Server %s (%s) to Domain %s

L

false

Server has been successfully added to a domain


Clusters


233

Invalid Key Encryption Key size specified for Cloud VM Set %s.

H

true

Invalid Key Encryption Key size

Verify that the Key Encryption Key size is 128 bits or 256 bits

Security

Key Encryption Key

234

Retention period has expired for Cloud VM Set %s. %s Cloud VMs deleted. Deleted Cloud VM Set %s.

L

true

Retention period has expired for Cloud VM Set


Security

Key Encryption Key

235

Retention period for Cloud VM Set %s will expire in %d days.

H

true

Retention period expiration for Cloud VM Set

The cloud admin should determine whether the retention date should be extended.

Security

Key Encryption Key

236

Set Retention Date to %s for Cloud VM Set %s.

L

false

Changed Retention period for Cloud VM Set


Security

Key Encryption Key

237

Failed to delete Key Encryption Key from HSM for Cloud VM Set %s. Error: %s.

M

true

Failed to delete Key Encryption Key from HSM


Security

Key Encryption Key

238

New CA Certificate added to Certificate Store for verifying %s

L

false

New CA certificate has been added to verify some subsystem


Clusters


239

CA Certificate for %s removed from Certificate Store

H

false

CA Certificate for some subsystem has been removed from Certificate Store


Clusters


240

Authentication for LDAP user %s failed. Reason :- %s

H

false

Reason for LDAP log in failures


Security


241

Cannot register Cloud VM until Key Encryption Key for Cloud VM Set %s is imported

L

true

Cannot register Cloud VM


Security

Key Encryption Key

242

Virtual Machine %s HTcrypt driver update -- %s

L

false

HTcrypt driver state on policy agent changed


Security


243

New self-signed certificates generated for %s

L

false

New self-signed certificates generated for server


Clusters

Certificate

244

New SSL certificate installed for %s

L

false

New SSL certificate installed for server


Clusters

Certificate

245

CSR generated with common name - %s

L

false

New CSR generated


Clusters

Certificate

246

Web server for %s restarted

L

false

Webserver/Apache restarted for server


Clusters

Certificate

247

Certificate installation task got timed out. There are VMs that did not receive the new CA certificate. Please contact Cloud Administrators to log in to the Virtual Machine and execute hcl heartbeat before restarting the webserver

H

true

One (or more) policy agents did not receive the new CA certificate uploaded. Cloud administrator has to log in to the policy agent and execute hcl heartbeat


Clusters

Certificate

248

Cannot update CA as part of SSL certificate installation for %s. Please log in to the Virtual Machine and execute hcl heartbeat

H

true

Domain Administrator has attempted to install a new SSL certificate for the webserver. Unfortunately one of the policy agents did not receive a copy of the new CA certificate that can verify the SSL certificate of the webserver. Cloud administrator has to log in to the policy agent and execute hcl heartbeat


Clusters

Certificate

249

External web server certificate of %s has expired. A new certificate must be installed before the associated VMs can communicate with %s. After the new certificate has been installed, the certificate information on the associated VMs must be manually updated if the new certificate is from a different Certificate Authority. For more information, search for certificates in the WebGUI online help.

H

true

Certificate used by the external webserver of one of the nodes has expired. Domain administrator has to install a new certificate. If the newly installed certificate is generated by a new CA, cloud administrators will have to log in to policy agent and update the CA certificate file. The latest CA certificate file can be found in the cloud tab in WebGUI


Clusters

Certificate

250

External web server certificate of %s will expire in %s days, %s hours and %s minutes. If another certificate is not installed before the current one expires, the VMs will not be able to communicate with %s after %s and all VMs may need to be manually updated after the new certificate is installed. For more information, search for certificates in the WebGUI online help.

H

true

Certificate used by the external webserver of one of the nodes is about to expire. Domain administrator has to install a new certificate before it gets expired. Otherwise policy agents will not be able to communicate with the KC after expiry


Clusters

Certificate

251

CA certificate used for verifying %s:%s on %s has already expired. Please upload a new CA certificate to verify the %s server certificate. Otherwise %s users will not be able to log in to the WebGUI.

H

true

CA certificate used by the LDAP server has already expired. Security Administrator has to install a new certificate to verify the LDAP server certificate. Otherwise LDAP users will not be able to log in to the WebGUI.


Clusters

Certificate

252

CA certificate used for verifying %s:%s on %s will expire in %s days, %s hours and %s minute. If another CA certificate is not installed before the current one expires, %s users will not be able to log in to the WebGUI after %s.

M

true

CA certificate used for evaluating LDAP server certificate is about to expire. Security Administrator has to install a new certificate before the current one expires. Otherwise LDAP users will not be able to log in to the WebGUI after the CA certificate expiry date.


Clusters

Certificate

253

Certificate for %s:%s has already expired. Please re-configure %s after updating the certificate in %s.

H

true

Certificate for APPLINK has already expired. APPLINK should be reconfigured after uploading a new certificate.


Clusters

Certificate

254

Certificate for %s:%s will expire in %s days, %s hours and %s minutes. Once the certificate of %s is updated, please re-configure the %s:%s

M

true

Certificate for APPLINK is about to expire. Security Administrator has to install a new certificate and re-configure the APPLINK before the current one expires.


Clusters

Certificate

255

KeyControl Cluster is in maintenance mode

L

false

The KeyControl cluster is in maintenance state. This is a temporary state which occurs during upgrade process


Clusters


256

Virtual Machine with IP %s is a possible clone of %s (%s) and hardware signature verification is turned off.

H

true

A possible clone of a virtual machine that is already registered has been detected. Verify that the virtual machine is valid and register it as a new virtual machine using 'hcl register -c' command.


Security


257

CSP Vault node %s has been successfully upgraded from version %s to version KC %s

M

true

CSP Vault node upgrade to new version has succeeded.


Clusters

Upgrade

258

CSP Vault node %s has been successfully reverted from version %s to version KC %s

M

true

CSP Vault node revert to old version has succeeded


Clusters

Upgrade

259

Access Control Policy: %s, at version: %s applied to disk: %s on Virtual Machine: %s

H

true

Access Controls Policy version update to disk.


Security

Access Control

260

Access Control Policy removed from disk: %s on Virtual Machine: %s

H

true

Access Controls Policy removed.


Security

Access Control

261

New Access Control Policy: %s created.

L

false

New Access Control Policy Created.


Security

Access Control

262

Access Control Policy: %s updated. Policy now available as: %s.

H

false

Access Control Policy Updated.


Security

Access Control

263

Access Control Policy: %s deleted.

L

false

Access Control Policy Deleted.


Security

Access Control

264

Access Control Rule: %s added to Policy: %s.

H

false

New Access Control Rule added to Policy.


Security

Access Control

265

Access Control Rule: %s updated for Policy: %s.

H

false

Access Control Rule updated for Policy.


Security

Access Control

266

Access Control Rule: %s deleted from Policy: %s.

H

false

Access Control Rule deleted from Policy.


Security

Access Control

267

hytrust_accesscontrols rpm state changed to: %s on Virtual Machine: %s

M

false

HyTrust Access Controls rpm state changed


Security

Access Control

268

Initiated application of Access Control Policy: %s to disk: %s on Virtual Machine: %s.

H

false

Access Control Policy application initiated by Admin.


Security

Access Control

269

Initiated removal of Access Control Policy: %s from disk: %s on Virtual Machine: %s.

H

false

Access Control Policy removal initiated by Admin.


Security

Access Control

270

Created Cloud VM Set %s with Single Encryption Key

L

true

CVMSet created with Single Encryption Key for dedup


Security


271

Failed to upgrade KeyControl nodes: %s. Reverting upgraded nodes: %s.

L

true

Failed to upgrade KeyControl nodes.


Clusters

Upgrade

272

Failed to revert KeyControl nodes: %s. Remove nodes from KeyControl after reboot.

L

true

Failed to revert KeyControl nodes.


Clusters

Upgrade

273

Upgrade Cancelled. Error: %s

L

true

Failed to finalize upgrade.


Clusters

Upgrade

274

%s got reverted during upgrade. Reverting other nodes in the cluster to revision %s

L

false

Failed to upgrade KeyControl node.


Clusters

Upgrade

275

Successfully cancelled KeyControl Upgrade.

M

false

Cancelled KeyControl Upgrade.


Clusters

Upgrade

276

IP conflict detected for %ipaddr with MAC %this_mac on %this_month %this_day %this_time

H

true

Another virtual machine is/was using this KeyControl IP address.


Security


277

Access Controls removed successfully on Virtual Machine %s

H

true

Successful Access Controls removal on virtual machine


Security

Access Control

278

Applying Policy %s, version %s failed on Virtual Machine %s. %s

H

true

Policy application failure on virtual machine with reason.


Security

Access Control

279

Applying Policy %s, version %s failed on disk %s of Virtual Machine %s

H

true

Failure in Policy application on a specific disk of a virtual machine.


Security

Access Control

280

Error removing Access Control Policy on disk %s of Virtual Machine %s

H

true

Error removing Access Control Policy on a disk.


Security

Access Control

281

%s doesn't allow local user creation. Cannot support Access Controls

H

true

Virtual machine doesn't support Access Controls due to inability to create local users


Security

Access Control

282

%s doesn't allow ssh for localhost. Cannot support Access Controls

H

true

Cannot setup Access Controls on virtual machine since it doesn't allow ssh for localhost


Security

Access Control

283

%s doesn't allow password-based ssh log in. Cannot support Access Controls

H

true

Cannot setup Access Controls on virtual machine since it doesn't allow password-based ssh log in.


Security

Access Control

284

Access Control setup failed on Virtual Machine %s. Please check /var/log/htac.log on Virtual Machine for more details

H

true

Failure in initial Access Controls setup


Security

Access Control

285

Insufficient free space on %s to perform upgrade. Consult product documentation for procedure to add another disk

H

true

Disk does not have enough space for upgrade

Consult support for freeing disk space or create/join a node with more space and upgrade that

Clusters

Upgrade

286

Access Control tampering detected on Virtual Machine %s

H

true

Access Control Tampering


Security

Access Control

287

Error enforcing policy %s, version %s on Virtual Machine %s. %s

H

true

Access Control Policy application failure due to htadmin error


Security

Access Control

288

New AD Server: %s created.

L

false

Create AD Server


Security

Active Directory

289

Updated AD Server config: %s.

L

false

Updated AD Server config


Security

Active Directory

290

Deleted AD Server: %s.

L

false

Deleted AD server


Security

Active Directory

291

User account htadmin already exists on Virtual Machine %s. Please delete htadmin, before enforcing Access Control Policy

L

true

Local user account htadmin detected before Access Control pre-setup tests


Security

Access Control

292

Virtual Machine - %s cannot verify communications from KeyControl because the KeyControl SSL certificate has changed but the CA certificate on the Virtual Machine was not updated when the new SSL certificate was installed for KeyControl. To update the CA certificate on the Virtual Machine and restore connectivity, log into the WebGUI, download the latest CA certificate from Cloud tab > Actions > Download CA Certificate, copy the CA certificate to the Virtual Machine, and execute "hcl update_ca -f </path/to/cert>"

H

true

SSL certificate of KeyControl has changed and webserver has been restarted. One of the VMs did not receive the latest copy of the CA certificate to verify KeyControl. To restore communication, download the latest CA certificate from WebGUI cloud tab, copy it to the virtual machine and execute hcl update_ca command


Security

Certificate

295

Virtual Machine %s is using an older Hardware Signature format. Please run "hcl auth" cmd on the Virtual Machine for a more secure signature.

H

true

Virtual machine is using an older Hardware Signature format. Please run "hcl auth" cmd on the virtual machine for a more secure signature.


Security

Client

296

Alert email sent to Security Admins on upgrade.

L

true

Alert email sent to Security Admins on upgrade.


Security


297

Abandoning %d inactive tasks on %s. Abandoning %s task %s on %s not updated since %s, TaskId: %s

L

true

List of tasks that have been abandoned due to inactivity


Security


298

Error!!! Could not enable support log in. Please make sure there is enough space in the filesystem

H

true

Cannot enable support log in. Please make sure there is enough space in the file-system

Increase the size of the disk and reboot the KeyControl appliance to resize

Security

Support

299

Error!!! Could not disable support log in. Please make sure there is enough space in the filesystem

H

true

Cannot disable support log in. Please make sure there is enough space in the file-system

Increase the size of the disk and reboot the KeyControl appliance to resize

Security

Support

300

%s attempting %s account log in when object store is not readable

M

false

Attempt to log in to support log in in one of the KeyControl nodes when object store is down


Security

Support

301

Decryption is not allowed for device %s on Virtual Machine %s. To decrypt: Access Control Policy : %s Version: %d must be removed from device. Auto Encryption Policy should be changed so as to exclude the device.

L

true

Device decryption refused due to applied policies.

Change policies as suggested in error message.

Security


302

Space on HyTrust Bootloader partition %s is running low (%lld bytes free). Often times USN journal is the culprit. You can check USN journal size using the command: "fsutil usn queryjournal %s". To delete USN journal, use the command: "fsutil usn deletejournal /N %s "

H

true

Device decryption refused due to applied policies.

Change policies as suggested in error message.

Security


303

Login failure for %s from %s because %s is in lock out period.

M

false

Attempt to log in to secroot in the lock out period after repeated unsuccessful log in attempts


Security

Account

304

Changed AD group members for group %s. %s

L

false

List of AD Group members has been changed for a KeyControl Group


Security

Group

305

The current number of KeyControl nodes (%d) exceeds the maximum number of nodes allowed by your license (%d). You cannot add any more KeyControl nodes to this cluster until you upgrade your license.

M

true

KeyControl nodes in use exceeds license limit of installed license


Security

Licensing

306

The current number of VMs registered with this KeyControl cluster (%d) exceeds the maximum number of VMs allowed by your license (%d). You cannot register any additional VMs until you upgrade your license.

M

true

Registered virtual machine count exceeds license limit of installed license


Security

Licensing

307

Service %s is up

L

false

KeyControl system service is up


Security

SystemService

308

Service %s is down

H

true

KeyControl system service is down


Security

SystemService

309

Using AD group membership for %s - %s

M

false

AD group membership of the AD user that was returned by the LDAP server during first time log in. The AD group membership will be used to determine the KeyControl Group membership of the AD user.


Security

Licensing

310

Updating AD group membership for %s - %s

M

false

AD group membership of the AD user that was returned by the LDAP server. The new AD group membership will be used to determine the KeyControl Group membership of the AD user who has already logged into KeyControl previously.


Security

Licensing

311

Added KMIP client configuration. Server: %s

L

false

Added KMIP client configuration


Security

KMIP Client

312

Updated KMIP client configuration. Server: %s

L

false

Updated KMIP client configuration


Security

KMIP Client

313

Deleted KMIP client configuration. Server: %s

H

true

Deleted KMIP client configuration


Security

KMIP Client

314

Deleted all KMIP client configurations.

H

true

Deleted KMIP client configuration


Security

KMIP Client

315

Failed to delete key:%s on external KMIP server

M

false

Failed to delete key on KMIP server


Security

KMIP Client

316

Added AD Domain: %s

L

false

Added a new AD Domain


Security

LDAP

317

Updated AD Domain %s. Changed Attributes - %s

L

false

Updated the AD Domain


Security

LDAP

318

Removed AD Domain %s

L

false

Removed AD Domain from KeyControl


Security

LDAP

319

Added new Domain Controller %s for AD Domain %s

L

false

Added a new AD Domain Controller


Security

LDAP

320

Updated Domain Controller %s for AD Domain %s. Changed Attributes - %s

L

false

Updated Domain Controller


Security

LDAP

321

Removed Domain Controller %s for AD Domain %s

L

false

Removed Domain Controller from KeyControl


Security

LDAP

322

encrypt failed for device %s on Virtual Machine %s, error %d

M

true

Encrypt operation failed on virtual machine


Security

Client

323

decrypt failed for device %s on Virtual Machine %s, error %d

M

true

Decrypt operation failed on virtual machine


Security

Client

324

rekey failed for device %s on Virtual Machine %s, error %d

M

true

Rekey operation failed on virtual machine


Security

Client

325

Successfully deleted admin key on EKS: %s

M

false

Successfully deleted admin key on KMIP server


Security

KMIP Client

326

Successfully generated admin key on EKS: %s

M

false

Successfully generated admin key on KMIP server


Security

KMIP Client

327

Failed to generate admin key on EKS: %s

H

true

Failed to generate admin key on KMIP server


Security

KMIP Client

328

Failed to store admin key on EKS: %s

H

true

Failed to store admin key on KMIP server


Security

KMIP Client

329

Successfully stored admin key on EKS: %s

M

false

Successfully stored admin key on KMIP server


Security

KMIP Client

330

Failed to fetch admin key from EKS: %s

M

true

Failed to fetch admin key from KMIP server


Security

KMIP Client

331

KeyControl Upgrade failed. Please contact Support

H

true

Post upgrade failed


Clusters

Rolling Upgrade

332

Domain Controllers re-ordered for %s

L

false

Order of Domain Controllers has been changed for an AD domain configured


Security

LDAP

333

Failed to set backup hosts to %s on %s

H

true

Failed to update backup hosts


Security


334

Virtual Machine %s is in BoundaryControl grace period

M

true

Virtual machine in Boundary Control grace period


Security

Boundary Control

335

Virtual Machine %s, BoundaryControl grace period expired

M

true

Virtual machine Boundary Control grace period expired


Security

Boundary Control

336

Application Link created from Product (%s) Version (%s) IP List (%s)

L

false

A new Application Link has been created from an external product. This link will allow the external product to make API calls to KeyControl.


Clusters

AppLink

337

Application Link renewed for Product (%s) Version (%s) IP List (%s)

L

false

An Application Link has been renewed for the external product.


Clusters

AppLink

338

Failed to upgrade LDAP Settings. Please reconfigure LDAP settings manually

H

true

Failed to upgrade LDAP Settings.


Security

LDAP

339

Failed to store admin key on HSM

H

true

Failed to store admin key on HSM


Security

HSM

340

Removed Server(s) %s from Domain %s

L

true



Clusters


341

Grace period will expire on %s for Virtual Machine %s, please check connectivity

H

true



Security


342

Grace period expired for Virtual Machine %s, please authenticate again

H

true



Security


343

Virtual Machine %s, failed to update following attributes: %s

H

false

Failed to update virtual machine settings


Security


344

Finished propagating changed attributes: %s to all Virtual Machines in Cloud VMSet: %s

H

false

Propagation of changed attributes completed for CVMSet


Security


345

Invalid software was discovered on KeyControl system %s. This is a possible trojan horse attack. Contact Support for assistance

H

true

Whitelisting violation detected on production build


Security

Whitelisting

346

Entrust Whitelist validation on KeyControl system %s has discovered modified files. These changes are allowed for development systems, but please review Whitelist logs for correctness.

L

true

Whitelisting violation detected on development build


Security

Whitelisting

347

Could not set password for %s: %s

H

true

Failed to set password


Security


348

Password changed for %s

H

true

Password changed


Security


349

Enabled %s user

H

true

Enabled user


Security


350

Failed to enable %s user

H

true

Failure in enabling user


Security


351

Disabled %s account

H

true

Disable account


Security


352

%s user logged out successfully

L

false

User logout


Security


353

Could not download the certificate: %s

M

true

Download certificate failure


Security


354

Downloaded a new CA certificate

M

true

Downloaded CA certificate


Security


355

ssh %sd for %s

M

false

SSH enabled/disabled for user


Security


356

Failed to %s ssh for %s

M

false

Failure in enabling/disabling SSH for user


Security


357

KeyControl restored from version %s backup file

M

false

KeyControl restored from backup successfully


Security


358

License auto-update: %s

M

true

License change during auto-update


Security


359

Failed to %s syslog on %s

H

true

Failed to enable/disable syslog on KeyControl node(s)


Security

syslog

360

Generated Syslog Certificate Signing Request with common name %s

L

false

Generated Syslog Certificate Signing Request with common name


Security

syslog

361

Changed following Syslog settings attributes: %s

L

false

Changed some Syslog settings attributes.


Security

syslog

362

Exporting audit log succeeded for %s (%s). Audit log is available to download.

M

true

Finish exporting audit log


Security


363

Exporting audit log failed for %s (%s).

M

true

Exporting audit log failed


Security


364

CVM Certificate %s, associated with CVM %s, CVMSet %s, revoked successfully

H

true



Security

Certificate

365

Cloud VM Set creation failed. Error: Failed to create root key in HSM. %s.

H

true

Root key creation failure on HSM during Cloud VM Set creation.

Security Admin should determine whether HSM is properly configured.

Security

Key Encryption Key

366

Cloud VM Set creation failed. Error: Failed to generate wrapped Key Encryption Key in HSM. %s.

H

true

Wrapped Key Encryption Key generation failed on HSM during Cloud VM Set creation

Security Admin should determine whether HSM is properly configured.

Security

Key Encryption Key

367

Virtual Machine %s moved from Cloud VM Set - %s (in KeyControl Group - %s) to Cloud VM Set - %s in (KeyControl Group - %s)

M

true

The virtual machine has been moved from one Cloud VM Set to another (which may belong to a different KeyControl Group).


Security


368

Successfully enabled passphrase based startup authentication

M

false

Set startup authentication type


Clusters

Startup Authentication

369

Successfully changed passphrase for startup authentication

M

false

Changed passphrase for startup authentication


Clusters

Startup Authentication

370

Recovered access to KeyControl node %s using passphrase

M

true

Recovered Masterkey using passphrase


Clusters

Startup Authentication

371

Successfully disabled passphrase based startup authentication

M

false

Set startup authentication type


Clusters

Startup Authentication

372

Successfully reset nShield HSM configuration

M

false

nShield HSM configuration reset


Security

HSM

373

Cloud VM Set %s: Asymmetric KeyID %s created.

M

false

Asymmetric KeyID created


Security

Asymmetric KeyID

374

Cloud VM Set %s: Asymmetric KeyID %s revoked/unrevoked.

M

false

Asymmetric KeyID revoked/unrevoked


Security

Asymmetric KeyID

375

Cloud VM Set %s: Asymmetric KeyID %s updated - expires %s, onexpiry %s.

M

false

Asymmetric KeyID expiration attributes updated


Security

Asymmetric KeyID

376

Cloud VM Set %s: Asymmetric KeyID %s description updated.

M

false

Asymmetric KeyID description updated


Security

Asymmetric KeyID

377

Cloud VM Set %s: Asymmetric KeyID %s deleted.

M

false

Asymmetric KeyID deleted


Security

Asymmetric KeyID

378

Successfully encrypted plaintext using KeyID: %s

M

false

Encrypted plaintext using keyid key


Security

KeyID

379

Successfully decrypted ciphertext using KeyID: %s

M

false

Decrypted ciphertext using keyid key


Security

KeyID

380

Cloud VM Set %s: Asymmetric KeyID %s has expired

M

true

Asymmetric KeyID expired


Security

Asymmetric KeyID

381

Fatal error on KeyControl nodes: %s. Please contact Support

H

true

KeyControl Upgrade Failure

Reinstall specified nodes to secure KeyControl Cluster

Security

Rolling Upgrade

382

CRL regenerated and applied successfully on %s

M

false

CRL regeneration


Security

Certificate

383

Attempt to register a new KeyControl node (%s) with revision %s failed. Error: %s

M

true

Attempt to register a new KeyControl node failed


Clusters

Cluster Node Join

384

Successfully reset %s

M

true

The KeyControl node has been reset.


Clusters

Cluster Node Join

385

%s. Please contact Entrust to purchase or renew the license. If you do not plan to use this feature, you should delete your existing vault(s) to stop this message. For more information, see the Administration Guide.

M

true

Vault license not enabled or expired


Security

Licensing

386

Created Secrets Vault %s

M

false

The specified vault has just been created.


Security

Secrets Vault

387

Successfully removed pre-upgrade snapshots.

M

true

KC pre-upgrade snapshots were removed.


Clusters

Upgrade

388

KeyControl node {$myip[0]}/{$myhost[0]} removed pre-upgrade snapshots.

M

true

KC pre-upgrade snapshots were removed from a node.


Clusters

Upgrade

389

KeyControl configuration has been successfully updated. New node %s needs to be added to nShield HSM server configuration

M

true

Update nShield HSM server configuration


Security

HSM

390

Failed to configure newly joined node %s for nShield HSM server

H

true

Failed to configure node for nShield HSM


Security

HSM

391

Successfully completed decryption of KMIP objects

H

true

Decrypt operation completed for KMIP objects


Security

KMIP

392

Successfully completed rekey of KMIP objects

H

true

Rekey operation completed for KMIP objects


Security

KMIP

393

Successfully enabled encryption of KMIP objects

H

true

Enabled encryption of KMIP objects


Security

KMIP

394

Successfully disabled encryption of KMIP objects

H

true

Disabled encryption of KMIP objects


Security

KMIP

395

Failed to generate Key Encryption Key on HSM. Error: %s

H

true

Failed to generate Key Encryption Key on HSM


Security

KMIP

396

Successfully generated Key Encryption Key on HSM

M

false

Generated Key Encryption Key on HSM


Security

KMIP

397

Successfully cancelled node-join

M

false

Cancelled KeyControl Node-Join


Clusters

Cluster Node Join

398

Failed to join %s to KeyControl Cluster. Error: %s

M

true

Failed to join KeyControl node


Clusters

Cluster Node Join

399

Successfully joined %s to KeyControl Cluster

M

false

Added new node to KeyControl Cluster


Clusters

Cluster Node Join

400

CSR generated with common-name %s for node-join

M

false

Certificate Signing Request generated for node-join


Clusters

Cluster Node Join

401

Certificate bundle generated for node-join

M

false

Certificate bundle generated for node-join


Clusters

Cluster Node Join

402

Returning keys to Virtual Machine %s running on ESXi Host %s. Virtual Machine UUID is %s.

M

false

Returning keys to virtual machine on successful authorization with HTCC with additional virtual machine info


Security

GET-KEY Container

403

Returning keys to Virtual Machine %s

M

false

Returning keys to virtual machine on successful authorization with HTCC


Security

GET-KEY Container

404

NTP servers not found on KeyControl %s

H

true

NTP servers not found on KeyControl

Configure NTP servers using KeyControl TUI

Clusters

NTP

405

NTP synchronization failed on KeyControl %s

M

true

NTP synchronization failed on KeyControl

Check if NTP servers are reachable from KeyControl

Clusters

NTP

406

Freespace available on %s has fallen below %s%% for the /boot volume. Please contact support.

H

false

The amount of free disk space on the KeyControl appliance /boot filesystem has dropped below our recommended threshold. Please contact support for assistance.

Contact support.

Clusters


407

Set Key Encryption Key expiry to %s, onexpiry to %s for Cloud VMSet %s. Initiated rekey process to encrypt all Data Encryption Keys.

M

false

Added Key Encryption Key to Cloud VMSet


Security

Key Encryption Key

408

Successfully encrypted Data Encryption Keys of all CVMs in CVMSet: %s with a Key Encryption Key: %s. %s VMs, %s KeyIDs %s Asymmetric KeyIDs affected

M

false

Successfully encrypted Data Encryption Keys with Key Encryption Key


Security

Key Encryption Key

409

Successfully reset Luna HSM configuration

M

false

Luna HSM configuration reset


Security

HSM

410

Successfully tested nShield HSM configuration

M

false

nShield HSM configuration was successfully tested


Security

HSM

411

Luna HSM configuration changed:-

M

false

Luna HSM configuration changed


Security

HSM

412

Successfully tested Luna HSM configuration

M

false

Luna HSM configuration was successfully tested


Security

HSM

413

Luna Cloud HSM configuration changed:-

M

false

Luna Cloud HSM configuration changed


Security

HSM

414

Successfully reset Luna Cloud HSM configuration

M

false

Luna Cloud HSM configuration was reset


Security

HSM

415

Successfully tested Luna Cloud HSM configuration

M

false

Luna Cloud HSM configuration was successfully tested


Security

HSM

416

Failed to create /bootext filesystem. Please contact support for more assistance

H

true

Failed to create /bootext filesystem. Please contact support for more assistance


Security


417

Failed to join %s/%s to KeyControl Cluster. Please contact Support

H

true

Failed to join KeyControl node to cluster


Clusters

Cluster Node Join

418

CloudKey: {} in KeySet {} modified

M

true

CloudKey: {} in KeySet {} modified


Security

BYOK

419

CloudKey: {} in KeySet {} migrated to HSM

M

false

CloudKey: {} in KeySet {} migrated to HSM


Security

BYOK

420

Cloud Key {} deleted from KMS

H

true

Cloud Key {} deleted from KMS


Security

BYOK

421

Cloud Key {} restored to KMS

M

true

Cloud Key {} restored to KMS


Security

BYOK

422

Cloud Key {} state changed to {} on KMS

H

true

Cloud Key {} state changed to {} on KMS


Security

BYOK

423

Tag {} (value {}) set on Cloud Key {}

M

false

Tag {} (value {}) set on Cloud Key {}


Security

BYOK

424

Removed Tag {} on Cloud Key {}

M

false

Removed Tag {} on Cloud Key {}


Security

BYOK

425

Set users ({}) and administrators ({}) to Cloud Key {}

M

true

Set users ({}) and administrators ({}) to Cloud Key {}


Security

BYOK

426

Removed {} ({}) from Cloud Key {}

M

true

Removed {} ({}) from Cloud Key {}


Security

BYOK

427

New Cloud Key {} created in KeySet {}

M

true

New Cloud Key {} created in KeySet {}


Security

BYOK

428

New Cloud Key {} created in KeySet {} {} {}

M

true

New Cloud Key {} created in KeySet {} Region/Vault {}


Security

BYOK

429

Cloud Key {} in KeySet {} uploaded to {} {}

M

true

Cloud Key {} in KeySet {} uploaded to {} {}


Security

BYOK

430

Cloud Key {} in KeySet {} rotated

M

true

Cloud Key {} in KeySet {} rotated


Security

BYOK

431

Cloud Key {} in KeySet {} scheduled for deletion in {} days

H

true

Cloud Key {} in KeySet {} scheduled for deletion in {} days


Security

BYOK

432

Deletion schedule canceled on Cloud Key {} in KeySet {}

M

true

Deletion schedule canceled on Cloud Key {} in KeySet {}


Security

BYOK

433

Cloud Key {} in KeySet {} deletion complete

M

false

Cloud Key {} in KeySet {} deletion complete


Security

BYOK

434

Processed Expiry Action {} on Cloud Key {} in KeySet {}

H

true

Processed Expiry Action {} on Cloud Key {} in KeySet {}


Security

BYOK

435

Cloud Key {} region {} imported in KeySet {}

M

false

Cloud Key {} region {} imported in KeySet {}


Security

BYOK

436

Started Key Import from {} {} from KMS to KeySet {}

M

true

Started Key Import from region/keyvault/keyring {} from KMS to KeySet {}


Security

BYOK

437

Keys imported from {} {} from KMS to KeySet {}

M

true

Keys imported from region/keyvault/keyring {} from KMS to KeySet {}


Security

BYOK

438

Keys imported from AWS KMS to KeySet {}

M

true

Keys imported from AWS KMS to KeySet {}


Security

BYOK

439

Keys migrated to HSM from KEYCONTROL for KeySet {}

H

true

Keys migrated to HSM from KEYCONTROL for KeySet {}


Security

BYOK

440

KeySet: {} modified

M

true

KeySet: {} modified


Security

BYOK

441

Started key migration, from {} to {}, for KeySet {}

H

true

Started key migration for KeySet


Security

BYOK

442

New KeySet: {} created

M

true

New KeySet: {} created


Security

BYOK

443

Key Set {} deleted

H

true

Key Set {} deleted


Security

BYOK

444

CSP Account: {} modified

M

true

CSP Account: {} modified


Security

BYOK

445

CSP Account {} access keys rotated

H

true

CSP Account {} access keys rotated


Security

BYOK

446

New CSP Account: {} created

M

true

New CSP Account: {} created


Security

BYOK

447

CSP Account {} deleted

H

true

CSP Account {} deleted


Security

BYOK

448

Access key rotation failed

H

true

Access key rotation failed


Security

BYOK

449

CloudKey rotation failed

M

true

CloudKey rotation failed


Security

BYOK

450

CloudKey expiry processing failed

M

true

CloudKey expiry processing failed


Security

BYOK

451

CloudKey import failed

M

true

CloudKey import failed


Security

BYOK

452

CloudKey auto import failed

M

true

CloudKey auto import failed


Security

BYOK

453

Set Key Policy for Cloud Key {}

M

true

Set Key Policy for Cloud Key


Security

BYOK

455

Encryption finished on system volumes of KeyControl {}

M

false

Encryption finished on system volumes of KeyControl


Clusters

BYOK

456

Successfully installed managed Secret Vault Plugin: {} (version {})

M

false

Managed Secret Vault Plugin install success


Security

Secrets Vault

457

Cloud Key {} in KeySet {} deleted as upload failed

L

false

Cloud Key object deleted as upload failed


Security

BYOK

458

Enabled Root-of-Trust in password mode

M

false

Enabled Root-of-Trust in password mode


Security

HSMROT

459

Failed to enable Root-of-Trust

M

false

Failed to enable Root-of-Trust


Security

HSMROT

460

Enabled Root-of-Trust in hwsig mode

M

false

Enabled Root-of-Trust in hwsig mode


Security

HSMROT

461

Failed to enable Root-of-Trust

M

false

Failed to enable Root-of-Trust


Security

HSMROT

462

Disabled Root-of-Trust

M

false

Disabled Root-of-Trust


Security

HSMROT

463

Failed to disable Root-of-Trust: %s

M

false

Failed to disable Root-of-Trust: %s


Security

HSMROT

464

A different Cloud Key with name {} for KeyVault {} is already present in KeySet {}.If you want to overwrite the key in KeyControl node, delete the existing key from KeyControl node and import again

M

true

Could not import cloudkey as a different key with the same keyname already present in KeyControl node


Security

BYOK

465

Created new KMIP tenant {} with Active Directory domain {} and Active Directory user/group {} as initial KMIP administrator

M

true

Created new KMIP tenant with its own Active Directory config and an Active Directory user/group for initial access


Security

KMIP

466

Deleted KMIP tenant {}

M

true

Deleted KMIP tenant


Security

KMIP

467

Internal web server certificate of %s has expired. A new certificate must be installed for KeyControl Cluster to be healthy

H

true

Certificate used by the internal web server of one of the nodes has expired. Domain administrator has to install a new certificate for the KeyControl cluster to be healthy.


Clusters

Certificate

468

Internal web server certificate of %s will expire in %s days, %s hours and %s minutes. A new certificate must be installed before the current one expires for the KeyControl Cluster to be healthy.

H

true

Certificate used by the internal web server of one of the nodes is about to get expired. Domain administrator has to install a new certificate before it gets expired. Otherwise cluster will be degraded


Clusters

Certificate

469

Cloud Key {} KeyVault {} in KeySet {} synced from KMS

M

false

Cloud Key {} KeyVault {} in KeySet {} synced from KMS


Security

BYOK

470

Cloud Key {} operations changed to {} on Azure KMS

M

true

Cloud Key {} operations changed to {} on Azure KMS


Security

BYOK

471

Cloud Key {} KeyVault {} imported in KeySet {}

M

false

Cloud Key {} KeyVault {} imported in KeySet {}


Security

BYOK

472

CloudKey import failed in KeyVault {} KeySet {} Error {}

M

false

CloudKey import failed in KeyVault {} KeySet {} Error {}


Security

BYOK

473

Client Secret for Service application {} (CSP {}) will expire on {}. Please update it now to avoid BYOK management service disruption

H

true



Security


474

Client Secret for Service application {} (CSP {}) has expired on {}. Please update it now to resume BYOK management service

H

true



Security


475

Successfully started migration of KMIP objects to multi-tenant KMIP server

M

false

Started migration of KMIP objects to multi-tenant KMIP server


Security

KMIP

476

Successfully completed migration of KMIP objects to multi-tenant KMIP server

M

false

Completed migration of KMIP objects to multi-tenant KMIP server


Security

KMIP

477

Successfully cancelled migration of KMIP objects to multi-tenant KMIP server

M

false

Cancelled migration of KMIP objects to multi-tenant KMIP server


Security

KMIP

478

Successfully sent KMIP tenant account verification email to %s

M

false

Sent KMIP tenant account verification email


Security

KMIP

479

Successfully reset administrator account password of KMIP vault %s

M

false

Reset KMIP vault administrator account password


Security

KMIP

480

Successfully reset administrator account password of Secrets vault %s

M

false

Reset Secrets vault administrator account password


Security

Secrets Vault

481

Failed to initialize Authentication database

M

true



Security

oidc

482

Cloud Key {} KeyRing {} imported in KeySet {}

M

false

Cloud Key {} KeyRing {} imported in KeySet {}


Security

BYOK

483

Cloud Key {} KeyRing {} in KeySet {} synced from KMS

M

false

Cloud Key {} KeyRing {} in KeySet {} synced from KMS


Security

BYOK

484

CloudKey import failed in KeyRing {} KeySet {} Error {}

M

false

CloudKey import failed in KeyRing {} KeySet {} Error {}


Security

BYOK

485

Label {} (value {}) set on Cloud Key {}

M

false

Label {} (value {}) set on Cloud Key {}


Security

BYOK

486

Removed Label {} on Cloud Key {}

M

false

Removed Label {} on Cloud Key {}


Security

BYOK

487

Failed to delete old access keys for CSP Account '{}'. Error - '{}'

M

false

Failed to delete old access keys for CSP Account '{}'. Error - '{}'


Security

BYOK

488

EKM Key Access Justification policy violation while accessing Cloud Key {} in KeySet {} : error {}

M

false

EKM Key Access Justification policy violation


Security

BYOK

489

TDE Connector {} state changed to {} on Keyset {}

M

true

TDE Connector state changed


Security

BYOK

490

TDE Connector {} expiry date changed to {} on Keyset {}

M

true

TDE Connector expiry date changed


Security

BYOK

491

Added TDE Connector {} for CVM {} in KeySet {}

M

true

Add TDE connector


Security

BYOK

492

Removed TDE Connector {} from CVM {} in KeySet {}

M

true

Remove TDE connector


Security

BYOK

493

Successfully registered with CSP Compliance Manager (id: {}) from {}

M

true

CSP Compliance Manager register


Security

KCM

494

Successfully unregistered with CSP Compliance Manager (id: {}) from {}

M

true

CSP Compliance Manager unregister


Security

KCM

495

Successfully reset CSP Compliance Manager registration configuration from {}

M

true

CSP Compliance Manager configuration reset


Security

KCM

496

User %s reset syslog settings

M

false

Reset Syslog settings


Security

syslog

497

Attempt to register a new node, named server "%s" failed -- maximum node limit reached.

M

true

Maximum allowed cluster node count reached


Security

Licensing

498

Backup failed due to insufficient space on root device. Please contact support.

H

true

Backup failed due to insufficient space on the root device.


Security

Backup

499

Backup was not started due to heavy load on %s

M

true

Backup was not started due to heavy load on KeyControl


Security

Backup

500

Admin Key generation %s can be downloaded from the Settings page (https://%s/appliance/#!/account). Reason for regeneration: %s

H

true

Regenerated Admin Key


Security

Appliance

501

Rescued %s vault: %s

L

true

Rescued Vault


Security

Account

502

%s logged in from ipaddr %s using Personal Access Token %s

L

false

The specified user has just logged in from the IP address shown with Personal Access Token.


Security

Personal Access Token

503

AD authorization (Personal Access Token log in) for user %s failed. Reason :- %s

H

false

Reason for AD/LDAP log in failure for Personal Access Token log in


Security

Personal Access Token

504

%s %s Personal Access Token %s from ipaddr %s

M

false

Create/Update/Delete Actions on Personal Access Token


Security

Personal Access Token

505

Keys migrated from HSM to KEYCONTROL for KeySet {}

H

true

Keys migrated from HSM to KEYCONTROL for KeySet {}


Security

BYOK

506

CloudKey: {} in KeySet {} migrated to KEYCONTROL

M

false

CloudKey: {} in KeySet {} migrated to KEYCONTROL


Security

BYOK

507

Keys migrated from KEYCONTROL to HSM for KeySet {}

H

true

Keys migrated from KEYCONTROL to HSM for KeySet {}


Security

BYOK

508

Updated %s Vault %s with CSP Compliance Manager %s

M

false

The specified vault has just been updated with CSP Compliance Manager.


Security

KCM

509

Configured OIDC without AD with client id %s

M

false

Configured OIDC without AD


Security

AUTHENTICATION

510

OIDC without AD configuration removed

M

false

OIDC without AD configuration removed


Security

AUTHENTICATION

511

Changed Password Settings :- %s from %s to %s

M

false

One or more of the listed password settings has been changed.


Security

Configuration

512

Keys cached from HSM to KEYCONTROL for KeySet {}

H

true

Keys cached from HSM to KEYCONTROL for KeySet {}


Security

BYOK

513

Keys uncached from KEYCONTROL for KeySet {}

H

true

Keys uncached from KEYCONTROL for KeySet {}


Security

BYOK

514

CloudKey: {} in KeySet {} cached to KeyControl

M

false

CloudKey: {} in KeySet {} cached to KeyControl


Security

BYOK

515

CloudKey: {} in KeySet {} uncached from KeyControl

M

false

CloudKey: {} in KeySet {} uncached from KeyControl


Security

BYOK

516

OIDC authorization failed. Reason :- %s

M

false

Reason for OIDC log in failure


Security

AUTHENTICATION

517

Connection from node %s to HSM %s has failed

H

true

The node is unable to communicate with the HSM

Security Admin should check the HSM configuration.

Security

HSM

518

Connection from node %s to HSM %s is restored

L

true

The node is able to communicate with the HSM again


Security

HSM

519

Connection from node %s to HSM %s still failed after HSMROT timeout, locking down

H

true

The node is shutting down because it has lost contact with the HSM

Fix the issue preventing the node from contacting the HSM and restart the node.

Security

HSM

520

HSM issue on node %s: %s

M

true

Some HSM issues have been detected on the node that do not prevent communication with the HSM

Security Admin should check the HSM configuration.

Security

HSM

521

HSM issues resolved on node %s

L

true

The HSM issues previously reported on the node have been resolved


Security

HSM

522

Failed to install self-signed certificate cluster-wide

M

true

Install self signed certificate cluster-wide


Clusters


523

Failed to clean cacert list.

M

false

Clean cacert list guid from system setting


Clusters


524

Successfully moved the cluster to self-signed certificate.

M

false

Install self signed certificate cluster-wide


Clusters


525

Successfully changed the EMS Enforcement crypto policy.

M

false

Change EMS Enforced Configuration


Clusters


526

The license for this system expired %s days ago. Please renew or upgrade the license. Start that process from the licensing page in the WebGUI at https://%s/appliance/#!/license

H

true

License expired


Security

Licensing

527

The license for this system expires in %s days. Please renew or upgrade the license. Start that process from the licensing page in the WebGUI at https://%s/appliance/#!/license

H

true

License will expire after some days.


Security

Licensing

528

The license for this system expires today. Please renew or upgrade the license. Start that process from the licensing page in the WebGUI at https://%s/appliance/#!/license

H

true

License is expiring today.


Security

Licensing

529

This system has exceeded the licensed limit of %s Virtual Machines. Further Virtual Machine creation is disabled. Please renew or upgrade the license. Start that process from the licensing page in the WebGUI at https://%s/appliance/#!/license

H

true

This system has exceeded the licensed limit of virtual machines count. Further virtual machine creation is disabled.


Security

Licensing

530

This system has exceeded the licensed limit of %s Virtual Machines. Please renew or upgrade the license. Start that process from the licensing page in the WebGUI at https://%s/appliance/#!/license

H

true

This system has exceeded the licensed limit of virtual machines count.


Security

Licensing

531

System Initialization Complete

L

false

System Initialization Complete


Security


532

System Autoconfiguration Complete

L

false

System Autoconfiguration Complete


Security


533

Cloud Key {} in KeySet {} replicated to {}

M

true

Cloud Key {} in KeySet {} replicated to {}


Security

BYOK

534

The Cloud Key {} from KeySet {} will be rotated on {}.

H

true

Send notification before cloudkey rotation.


Security

BYOK

535

The Cloud Key {} from KeySet {} is expiring on {} with the Action {}.

H

true

Send notification before cloudkey expiration.


Security

BYOK

536

System has completed automatic renewal of self-signed certificates.

L

false

Automatic renewal of self-signed certificates.


Clusters


537

System has completed automatic renewal of CA certificates.

L

false

Automatic renewal of CA certificates.


Clusters


538

Probable LOW DISK SPACE: refreshing KMIP database is failing. Most probably the disk is low on space. Please consider increasing disk space.

H

true



Security


539

Generated Access Token for TDE Connector {} in KeySet {}

M

true

Add TDE connector


Security

BYOK

540

Internal CA signed certificate with common name and SANs - '%s', '%s' is generated and installed for %s.

L

false

New internal CA signed certificate generated and installed.


Clusters

Certificate

541

KeyControl upgrade failed. Failed to revert nodes. Please contact Support

H

true

Post upgrade failed


Clusters

Rolling Upgrade

542

Failure to change the EMS Enforcement crypto policy. Reverting to %s

M

false

Change EMS Enforced Configuration


Clusters


543

NTP synchronization succeeded on KeyControl %s

M

true

NTP synchronization succeeded on KeyControl

Check if NTP servers are reachable from KeyControl

Clusters

NTP

544

Backup of Cloud Key {} failed: {}

M

true

Backup of Cloud Key {} failed: {}


Security

BYOK

545

Cloud Key {} backup {} is not available in remote storage

M

true

Cloud Key {} backup {} is not available in remote storage


Security

BYOK

546

Unsupported ciphers found in KMIP server configuration: %s

L

true

Unsupported ciphers found in KMIP server configuration


Security


547

Updated default cipher list to %s in KMIP server configuration

L

true

Updated default cipher list to %s in KMIP server configuration


Security


548

Cloud Key {} with key id {} is the active key version and cannot be deleted. The scheduled deletion has been cancelled

M

true

Cloud Key {} with key id {} is the active key version and cannot be deleted. The scheduled deletion has been cancelled


Security

BYOK

549

Cloud Key {} with key id {} is the active key version and cannot be deleted. The scheduled expiry has been cancelled

M

true

Cloud Key {} with key id {} is the active key version and cannot be deleted. The scheduled expiry has been cancelled


Security

BYOK

550

CSP Account: {} access credentials are due for rotation. Please rotate through the Salesforce UI.

M

true

CSP Account: {} access credentials are due for rotation.


Security

BYOK

551

Started HSM key caching for KeySet {}

M

true

Started HSM key caching for KeySet {}


Security

TDE

552

Keys cached to HSM for KeySet {}

M

true

Keys cached to HSM for KeySet {}


Security

TDE

553

CSP Account {} failed to access AWS global infra API with the default region. The key management capabilty is unaffected, but some region's full names may not be displayed.

L

true

Unable to access AWS global infra API


Security

BYOK

554

Certificate based authentication enabled on CSP Account {}

M

true

Certificate based authentication enabled on CSP Account {}


Security

BYOK

555

Certificate based authentication disabled on CSP Account {}

M

true

Certificate based authentication disabled on CSP Account {}


Security

BYOK

556

Failed to create new client secret for CSP Account {}. Error {}

M

true

Failed to create new client secret for CSP Account {}. Error {}


Security

BYOK

557

CloudKey {} status changed from {} to {} on synchronization with Cloud

M

true

CloudKey {} status changed from {} to {} on synchronization with Cloud

Check the cloud status of the cloudkey is expected

Security

BYOK

558

Cache only key replay attack detected on on csp {}

H

true

Cache only key replay attack detected


Security

BYOK

559

To comply with certificate validity of CSP Vault's CA signed server certificate, the certificate will be automatically renewed on %s for %s. If you have a VM Encryption-vault, please ensure the authentication of all VMs after that renewal. Or if you have a Database-vault, please ensure the database clients reconnect after that renewal.

H

true

To comply with certificate validity of CSP Vault's CA signed server certificate, we will auto renew it on %s for %s. If you use a VME vault, please ensure the re-authentication of all VMs after that renewal.


Clusters

Certificate

560

CloudKey {} KeySet {} cannot be migrated to FIPS level 3 HSM because it uses cipher {}.

M

false

CloudKey {} KeySet {} cannot be migrated to FIPS level 3 HSM because it uses cipher {}.


Security

BYOK

561

Unknown error in check_ncipher_data - %s

H

true

Unknown error in HSM files


Security

HSM

562

Failed to clear error in check_ncipher_data - %s

H

true

Failed to clear error in HSM files


Security

HSM

563

CSP Vault has renewed the CA certificate that is being used by CSP Vault's external web server.

M

false

CSP Vault has renewed the CA certificate that is being used by CSP Vault's external web server.


Security

Certificate

564

CSP Vault has renewed the CA certificate that is being used by CSP Vault's internal web server.

M

false

CSP Vault has renewed the CA certificate that is being used by CSP Vault's internal web server.


Security

Certificate

565

CSP Vault's internal CA certificate, used for external communication (external webserver) will expire on %s. CSP Vault will renew the CA certificate on %s before the expiry. The system will reboot at the time of renewal and will be in read only mode. We recommend to re-authenticate all Virtual Machines connected to the VME vault using the commands 'hcl updatecert -a' and 'hcl auth -a' after the renewal. If your vault uses client certificate, then please generate new client certificate and use it at client application after the renewal.

M

true

CSP Vault's internal CA certificate, used for external communication (external webserver) will expire on %s. CSP Vault will renew the CA certificate on %s before the expiry. The system will reboot at the time of renewal and will be in read only mode. We recommend to re-authenticate all virtual machines connected to VME vault using the commands 'hcl updatecert -a' and 'hcl auth -a' after the renewal. If your vault uses client certificate, then please generate new client certificate and use it at client application after the renewal.


Security

Certificate

566

CSP Vault's internal CA certificate, used for internal communication (internal webserver) will expire on %s. CSP Vault will renew the CA certificate on %s before the expiry. The system will reboot at the time of renewal and will be in read only mode. If your cluster is in a degraded state following the renewal, reboot each node individually, making sure to reboot the master node last.

M

true

CSP Vault's internal CA certificate, used for internal communication (internal webserver) will expire on %s. CSP Vault will renew the CA certificate on %s before the expiry. The system will reboot at the time of renewal and will be in read only mode. If your cluster is in a degraded state following the renewal, reboot each node individually, making sure to reboot the master node last.


Security

Certificate

567

OIDC CA Certificate Uploaded Successfully

M

false

OIDC CA Certificate Uploaded Successfully


Security

OIDC

568

{} purged KeyVault {}.

M

true

{} purged KeyVault {}.


Security

BYOK

569

KC self-signed certificate for {server.hostname} (use for external webserver) is renewed.

L

false

KC self-signed certificate for {server.hostname} (use for external webserver) is renewed.


Security

Certificate

570

KC self-signed certificate for {server.hostname} (use for internal webserver) is renewed.

L

false

KC self-signed certificate for {server.hostname} (use for internal webserver) is renewed.


Security

Certificate

571

Failed to migrate Azure Keyvaults to target keyset {}. Error: {}.

M

true

Failed to migrate Azure Keyvaults to target keyset {}. Error: {}.


Security

BYOK

572

{} started migration of Azure keyvaults from source KeySets {} to target KeySet {}

M

true

Azure Keyvault migration between KeySets started


Security

BYOK

573

Migration of Azure Keyvaults to {} did not complete successfully. Expected {} cloud keys and {} key versions but found {} cloud keys and {} key versions.

M

true

Azure Keyvault migration between KeySets partially completed


Security

BYOK

574

Migration of Azure Keyvaults to {} completed successfully

M

true

Azure Keyvault migration between KeySets completed


Security

BYOK

575

Warning: CSP Account {} manages keys in overlapping subscriptions with existing Azure CSP accounts: {}. Subscription IDs: {}

M

true

Azure CSP created with overlapping subscriptions with existing Azure CSP accounts


Security

BYOK

576

Could not process {} on AWS Cloud Key {}. {}. The key has been disabled instead.

M

true

AWS Cloudkey expiry action failed.


Security

BYOK

577

Changed AD group members for group Appliance. %s

L

false

List of AD Group members has been changed for a CSP Vault Appliance


Security

Group

578

CSR generated for CSP Account {}

M

true

CSR generated for CSP Account


Security

BYOK

579

Azure keyvault {} containing replica keys has purge protection enabled. Rotation operations will fail.

M

true

A vault containing replica keys has purge protection enabled.


Security

BYOK

580

Replication of the key rotation for key {} to vault {} failed. The key must be manually restored to {} and synced in KeyControl to restore redundancy. Review other replica vaults in case replication has not occurred in them either.

H

true

Replication of a key rotation in Azure failed.


Security

BYOK

581

Trial period for vault {} has expired. This vault is now operating in restricted mode. Please connect to CSP Compliance Manager to retrieve a valid license.

H

true

Vault trial period has expired.


Licensing


582

{} {} has not been able to connect to CSP Compliance Manager for {} days. This is required for licensing checks. This vault is now operating in restricted mode. Please check the network connectivity and CSP Compliance Manager status.

H

true

Vault grace period has expired.


Licensing


583

{} {} is unlicensed. No license information is available for {}. This vault is now operating in restricted mode. Check that the vault type is covered by your license.

H

true

No license available for vault.


Licensing


584

The number of {} {} has exceeded the licensed limit of {}. Current usage: {}. This {} is now operating in restricted mode. Please purchase additional licenses.

H

true

License limit exceeded.


Licensing


585

The license for {} expired on {}. This vault is now operating in restricted mode. Please renew your license.

H

true

License Expired.


Licensing


586

Trial period for {} {} is nearing expiration. To avoid loss of service, please connect to CSP Compliance Manager to retrieve a valid license.

M

true

Vault trial period is nearing expiration.


Licensing


587

The license for {} will expire on {}. Please renew your license to avoid loss of service.

M

true

License Nearing Expiry.


Licensing


588

{} {} is in the grace period after upgrade to {} or later and will become unlicensed when this grace period ends.

M

true

Upgrade Grace Period Nearing Expiry.


Licensing


589

The number of {} {} is over 90% of the licensed limit of {}. Current usage: {}. To avoid loss of service, please purchase additional licenses if needed.

M

true

Usage is nearing license limit.


Licensing


590

Attempt to register a new node, named server "%s" failed -- license check failed. Reason: %s.

L

false

Appliance license check failed.


Licensing


591

Attempt to register a new node, named "%s" failed -- cluster not connected to KeyControl Compliance Manager.

L

false

Appliance is not connected to CSP Compliance Manager.


Licensing


592

Enabled Authentication Inheritance

M

true

Enabled Authentication Inheritance


Security

AUTHENTICATION

593

Disabled Authentication Inheritance

M

true

Disabled Authentication Inheritance


Security

AUTHENTICATION

594

Successfully fetched Key Encryption Key from HSM. %s

H

false

Successfully fetched Key Encryption Key from HSM.

Successfully fetched Key Encryption Key from HSM

Security

Key Encryption Key

595

OIDC authentication settings updated for Appliance and inheriting vaults

M

true

OIDC authentication settings updated for Appliance and inheriting vaults


Security

AUTHENTICATION

596

OIDC authentication settings for inheriting vault updated by System Admin

M

true

OIDC authentication settings for inheriting vault updated by System Admin


Security

AUTHENTICATION

597

XKS store for {} ({}) in region {} is unreachable

H

true

XKS service unreachable


Security

BYOK

598

XKS store {} ({}) in region {} is {}.

H

true

XKS store not connected


Security

BYOK

599

XKS store {} ({}) in region {} is now CONNECTED.

M

true

XKS store connected


Security

BYOK

600

%s for Virtual Machine %s. %s. Reauthentication required.

H

true



Security


601

Could not authenticate user. Unknown username {}.

H

false

Could not authenticate user. Unknown username


Security


602

Failed to promote %s as KeyControl Cluster Master Node. Error: %s

H

true

Failed to change the KeyControl master node


Clusters

Cluster Node Switchover

603

Successfully promoted the node %s as KeyControl Cluster Master

M

false

Changed the master node


Clusters

Cluster Node Switchover

604

Could not pass CSP vault's appliance info to CSP CM {}

L

false

Failed to send CSP vault's appliance info to CSP CM


Security


605

Import of cloudkey {} in {} {} skipped beacause it is managed by KeySet: {} (GUID: {}) already.

L

false

Cloudkey import skipped beacause it is already managed by another keyset on this system.


Security

BYOK

606

Import of cloudkey {} in {} {} skipped beacause it is managed by a KeySet on another system already. Owning keyset GUID: {}.

L

false

Cloudkey import skipped beacause it is already managed by another keyset on another system.


Security

BYOK

607

Import of SFDC cloudkey {} skipped beacause it is managed by KeySet: {} (GUID: {}) already.

L

false

SFDC Cloudkey import skipped beacause it is already managed by another keyset on this system.


Security

BYOK

608

Import of SFDC cloudkey {} skipped beacause it is managed by a KeySet on another system already. Owning keyset GUID: {}.

L

false

SFDC Cloudkey import skipped beacause it is already managed by another keyset on another system.


Security

BYOK

609

CloudKey {} is managed by multiple keysets. {} and {}

M

true

CloudKey {} is managed by multiple keysets.


Security

BYOK

610

Created distribution list {} for {}.

M

true

Created distribution list.


Security

GROUP

611

Updated distribution list {} in {}. {}

M

true

Updated distribution list.


Security

GROUP

612

Deleted distribution list {} in {}.

M

true

Deleted distribution list.


Security

GROUP

613

Distribution list {} associated with group {}. It will receive all alerts sent to the group.

M

true

Associated distribution list.


Security

GROUP

614

Distribution list {} dissociated from group {}. It will no longer receive alerts sent to the group.

M

true

Dissociated distribution list.


Security

GROUP

615

Two-factor authentication enforced by %s

M

false

Two factor authentication has been enforced for the users


Security


616

Two-factor authentication enforcement removed by %s

M

false

Two factor authentication enforced removed for the users


Security


617

Failed to add owning keyset guid to CloudKey {} during upgrade. Error: {}

M

true

Failed to add owning keyset guid to CloudKey during upgrade.


Security

BYOK

618

Failed to update failover order, triggerred by %s. Error: %s

M

true

Failed to update failover order


Clusters

Cluster

619

Failed to set the new primary to %s, please contact support

M

true

Failed to set new Postgres primary


Clusters

Cluster

621

Import of cloudkey {} in Region {} skipped beacause it uses on demand rotations with AWS generated key material. Such keys cannot be managed by CSP.

L

false

Cloudkey import skipped beacause it cannot be managed by CSP.


Security

BYOK

622

Failed to set keyset ownership tag on key {} in {} {} after import: {}.

L

false

Failed to set keyset ownership tag on key after import.


Security

BYOK

623

Failed to set keyset ownership tag on SFDC key {} after import: {}

L

false

Failed to set keyset ownership tag on key after import.


Security

BYOK

624

Failed to write KeySafeAgent Configuration to Database. Error: %s

H

false

Failed to write KeySafeAgent Configuration to Database.


Clusters

Cluster

625

Whitelisting database verification test

H

false

Whitelisting database verification test


Security

Whitelisting

626

Whitelisting database verification was successfull

H

false

Whitelisting database verification was successfull


Security

Whitelisting

627

Whitelisting database verification failed, entering error mode!

H

false

Whitelisting database verification failed, entering error mode!


Security

Whitelisting

628

FIPS POST tests

H

false

FIPS POST tests


Security

Whitelisting

629

Access credentials for CSP {} are not valid: {}. Please update the credentials to avoid management service disruption.

H

true

Access credentials for CSP account are invalid.


Security

BYOK

630

HYOK Key {} ({}) in keyset {} used to perform {} operation from remote address {}. {}

L

false

HYOK key used to perform crypto operation.


Security

BYOK

631

Failed to sync root CA cert for MHSM {} in KeySet {}: {}.

H

true

Failed to sync root CA cert for EKM enabled MHSM


Security

BYOK

632

Root CA certificate for MHSM {} in KeySet {} is expiring on {}. Please update the root CA certificate to avoid disruption to EKM crypto operations.

H

true

EKM enabled MHSM Root CA certificate is nearing expiry


Security

BYOK

633

Upgrade failed: not enough space in %s on host %s, %ld%% free, need min %ld%%

H

true

Not enough space

Consult support for freeing disk space or create/join a node with more space and upgrade that

Clusters

Upgrade

634

Upgrade failed: not enough space in %s on host %s, need %lldMB more free space

H

true

Not enough space

Consult support for freeing disk space or create/join a node with more space and upgrade that

Clusters

Upgrade

635

Upgrade failed: initiator argument missing from do_chkspace

H

true

Initiator argument missing from do_chkspace


Clusters

Upgrade

636

Upgrade failed: could not find space usage on host %s

H

true

Could not determine space

contact support or replace the node

Clusters

Upgrade

637

Upgrade failed: could not find available space on host %s

H

true

could not determine space

contact support or replace the node

Clusters

Upgrade

638

Upgrade failed: not enough space on host %s

H

true

Not enough space on host

contact support or replace the node

Clusters

Upgrade

639

Cleaning upgrade on %s

H

true

Cleaning upgrade


Clusters

Upgrade

640

Upgrade failed: could not scrub prior upgrade %s

H

true

Could not scrub prior upgrade


Clusters

Upgrade

641

Upgrade failed: could not find existing cipher of the KeyControl nodes

H

true

Could not find existing cipher of the KeyControl nodes


Clusters

Upgrade

642

Upgrade failed: could not find kit staging area usage

H

true

Could not find kit staging area usage


Clusters

Upgrade

643

Upgrade failed: could not find KeyControl nodes

H

true

Could not find KeyControl nodes


Clusters

Upgrade

644

Upgrade failed: could not find encryption status of volumes of the KeyControl node

H

true

Could not find encryption status of volumes of the KeyControl node


Clusters

Upgrade

645

Upgrade failed: rekey in progress on KeyControl nodes

H

true

Rekey in progress on KeyControl nodes


Clusters

Upgrade

646

CloudKey {} in KeySet {} key material exported.

M

true

CloudKey key material exported.


Security

BYOK

647

Upgrade bundle upload rejected: %s

H

true

Upgrade precondition check failed

Resolve the reported precondition and retry the upgrade

Clusters

Upgrade

648

Started key caching {} operation for KeySet {}

H

true

Started key caching operation for KeySet


Security

BYOK

649

Failed to refresh key cache for KeySet {}. Error: {}.

H

true

Failed to refresh key cache for KeySet


Security

BYOK

650

Multi-tenant KMIP migration in progress. Retry after migration is complete

H

true

KMIP migration in progress blocks upgrade

Wait for KMIP migration to complete before attempting upgrade

Clusters

Upgrade

651

No upgrade image found in the upload request

H

true

No upgrade image found in the upload request

Ensure the upgrade bundle file is included in the upload request

Clusters

Upgrade

652

Failed to save upgrade bundle: %s

H

true

Failed to save the uploaded upgrade bundle to disk

Check available disk space and file permissions, then retry

Clusters

Upgrade

653

Issue with bundle version. Bundle not valid for upgrade

H

true

Upgrade bundle has invalid version information

Obtain a valid upgrade bundle and retry

Clusters

Upgrade

654

Failed to properly fetch and decode upgrade bundle

H

true

Failed to mount or decode the upgrade bundle

Verify the upgrade bundle is not corrupted and retry

Clusters

Upgrade

655

Support license expired. Upgrade not allowed

H

true

Support license has expired preventing upgrade

Renew the support license before attempting upgrade

Clusters

Upgrade

656

The upgrade can not be started: %s

H

true

Pre-upgrade script failed

Check the pre-upgrade script output and resolve the issue

Clusters

Upgrade

657

Upgrade initiation failed: %s

H

true

Upgrade initiation failed

Check if another upgrade is already in progress. Contact support if the issue persists

Clusters

Upgrade

658

Unexpected error upgrading: %s

H

true

An unexpected error occurred during upgrade bundle upload

Contact support

Clusters

Upgrade

659

TLS configuration changed from %s to %s on node %s

H

true

TLS/SSL protocol or cipher configuration changed


Security

Configuration

660

[SCIM] Added user %s to group %s

L

false

SCIM provisioning added a user to a group.


Security

Account, SCIM

661

[SCIM] Created user %s, name %s

L

false

SCIM provisioning created a user.


Security

Account, SCIM

662

[SCIM] Removed user %s from group %s

L

false

SCIM provisioning removed a user from a group.


Security

Account, SCIM

663

[SCIM] Deleted user %s

L

false

SCIM provisioning deleted a user.


Security

Account, SCIM

664

[SCIM] Updated user %s name from %s to %s

L

false

SCIM provisioning updated a user's name.


Security

Account, SCIM

665

KeyControl Upgrade not allowed on a multinode cluster in passphrase based startup authentication mode

H

true

Passphrase based auth mode blocks multinode upgrade

Disable Passphrase based startup authentication or reduce to single node for upgrade

Clusters

Upgrade

666

Cluster must be in normal mode for upgrade

H

true

Cluster not in normal mode for upgrade

Wait for cluster to return to normal mode before attempting upgrade

Clusters

Upgrade

667

Failed to update trusted client root certificates on cluster {}.

M

true

Failed to update trusted client root certificates on cluster.


Security

BYOK

668

KMIP server custom certificate has expired. KMIP clients will not be able to connect to the KMIP server. Please install a new certificate.

H

true

KMIP server custom certificate has expired. KMIP clients will not be able to connect to the KMIP server.

Install a new custom certificate for the KMIP server.

Security

KMIP

669

KMIP server custom certificate will expire in %s days, %s hours and %s minutes. If a new certificate is not installed before the current one expires, KMIP clients will not be able to connect to the KMIP server.

M

true

KMIP server custom certificate will expire soon. Upon expiry, KMIP clients will not be able to connect to the KMIP server.

Install a new custom certificate for the KMIP server before it expires.

Security

KMIP

670

Imported Key name {} version {} to KeySet {}

M

false

Cloud Key imported in KeySet


Security

TDE

671

Failed to import key {} version {} into KeySet {}

M

false

Failed to import Cloud Key to KeySet


Security

TDE

672

Upgrade failed: Unable to delete boot backup for extra space in /boot on {}.

L

true

Could not free extra disk space


Clusters

Upgrade

673

An updated Policy Agent version %s is available for guest %s (current version: %s). Please upgrade to ensure optimal security and features.

M

true

A newer version of the Policy Agent is available for installation

Upgrade the Policy Agent on the affected guest to the latest version

Cloud

Cloud, Policy Agent, Update

674

SNMP has been disabled during upgrade because the configured trap version is no longer supported. Only SNMPv3 is allowed.Please reconfigure SNMP after upgrade.

H

false



Security


675

SNMP has been disabled during upgrade because all configured agent users were non-v3 and have been removed. Please reconfigure SNMP after upgrade.

H

false



Security


676

{} non-v3 SNMP agent user(s) were removed during upgrade because only SNMPv3 is supported.

H

false



Security