Job log reports the error: Couldn't decrypt Vault contents

Symptoms

Logs report the following during the process:

CONFIG_TEXT: Couldn't connect to Storage Vault: Can't access Storage Vault: Couldn't decrypt Vault contents : exit status 1

Cause

Comet tried to access the Storage Vault, but it contained data encrypted with an unknown key. 

Each Storage Vault in a user's profile is automatically encrypted on first use, with a randomly generated key. If you reuse the data storage location already used by another user's Storage Vault, Comet would not know the Storage Vault's encryption key and would be unable to access it.

Likely causes are:

  • This Storage Vault is using the same data location as another Storage Vault (from the same or a different user account)
  • A Storage Vault was deleted, then a new Storage Vault was created and configured to reuse the same location.
  • The contents of the Storage Vault directory have been corrupted, or potentially affected by ransomware.

Resolution

If you intended to share the same Storage Vault between multiple users, you should log their devices into the same account. Otherwise, you should use a different physical location for each Storage Vault.

New, custom Storage Vaults must point to empty directories/prefixes.

Ensure the data integrity of the Storage Vault. All files (except the top-level config file) are named by their SHA256 hash, so the integrity can be checked without decrypting.

Example SHA256 check commands:

# find . ! -name 'config' -type f -exec sha256sum '{}' \; | awk '{ sub("^.*/", "", $2) ; if ($1 == $2) { print $2,"ok" } else { print "[!!!]",$2,"MISMATCH",$1 } }'

PS Get-ChildItem -Recurse -File | Where-Object { $_.Name -ne "config" } | ForEach-Object {
    $h = (Get-FileHash -Path $_.FullName -Algorithm SHA256)
    if ($_.Name -eq $h.Hash) { echo "$($_.Name) ok"; } else { echo "[!!!] $($_.Name) MISMATCH $($h.Hash)"; }
}

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.