Troubleshooting

Common issues and starting points for debugging storage, device, revocation, and encryption problems.

Storage setup issues

Verify bucket names, regions, endpoints, access keys, role ARNs, trust relationships, and optional external IDs when self managed storage configuration fails.

BYOK and KMS issues

Confirm the KMS key ARN, role ARN, allowed actions, and whether access to the wrapping key has been revoked.

Device connectivity issues

Review the stored credential type, SSH connectivity, destination paths, and whether the device status is reporting Unable to connect or Modified.

Revocation troubleshooting

Check that CRL and OCSP metadata is present in issued certificates and that your clients can reach the referenced endpoints.

Two-factor authentication issues

Authenticator code is rejected

  • Confirm you are entering the current six-digit code from the authenticator application.
  • Confirm the date and time on the device running the authenticator application are correct.
  • Wait for the next authenticator code and try again if the current code is near the end of its validity period.

Setup QR code expired

Two-factor authentication setup uses a temporary enrollment secret. If the setup session expires, SecuriTLS generates a new QR code. Scan the new QR code before entering another authenticator code.

Authenticator device is unavailable

Use one of the recovery codes generated when two-factor authentication was enabled. Each recovery code can only be used once.

Store recovery codes separately from your authenticator device

Recovery codes provide access when the configured authenticator is unavailable. Keep them in a secure location and treat them as authentication credentials.

Two-factor login session expired

The temporary login session used between password authentication and the two-factor challenge expires after a short period. Return to the login page, authenticate with your password again, and complete the two-factor challenge.