Troubleshooting
Common issues and starting points for debugging storage, device, revocation, and encryption problems.
Storage setup issues
Verify bucket names, regions, endpoints, access keys, role ARNs, trust relationships, and optional external IDs when self managed storage configuration fails.
BYOK and KMS issues
Confirm the KMS key ARN, role ARN, allowed actions, and whether access to the wrapping key has been revoked.
Device connectivity issues
Review the stored credential type, SSH connectivity, destination paths, and whether the device status is reporting Unable to connect or Modified.
Revocation troubleshooting
Check that CRL and OCSP metadata is present in issued certificates and that your clients can reach the referenced endpoints.
Two-factor authentication issues
Authenticator code is rejected
- Confirm you are entering the current six-digit code from the authenticator application.
- Confirm the date and time on the device running the authenticator application are correct.
- Wait for the next authenticator code and try again if the current code is near the end of its validity period.
Setup QR code expired
Two-factor authentication setup uses a temporary enrollment secret. If the setup session expires, SecuriTLS generates a new QR code. Scan the new QR code before entering another authenticator code.
Authenticator device is unavailable
Use one of the recovery codes generated when two-factor authentication was enabled. Each recovery code can only be used once.
Recovery codes provide access when the configured authenticator is unavailable. Keep them in a secure location and treat them as authentication credentials.
Two-factor login session expired
The temporary login session used between password authentication and the two-factor challenge expires after a short period. Return to the login page, authenticate with your password again, and complete the two-factor challenge.