ISG Proxy Fails to Update Keyring with Error "% Unable to read or create file"
search cancel

ISG Proxy Fails to Update Keyring with Error "% Unable to read or create file"

book

Article ID: 445525

calendar_today

Updated On:

Products

ISG Proxy

Issue/Introduction

When updating the passive-attack-protection-only-key keyring via Management Center (MC) script or local CLI, the operation fails with: % Unable to read or create file

Appliance Event Logs:

CFSSL: can't open file to read /legacy/.../config/v10/pki/passive-attack-protection-only-key
Unexpected error extracting certificate for keyring 'passive-attack-protection-only-key'

Note: Converting the private key format (PKCS#8 to PKCS#1)

Cause

File system/directory layout corruption on the virtual disk. The underlying PKI directory path may have become unreadable or unwritable by the OS. Standard SGOS software upgrades cannot repair a corrupted disk layout, preventing the appliance from committing new keyring objects.

Resolution

A clean redeployment of the affected Virtual Machine is required.

  1. Backup: In Management Center, trigger Back Up Device Configuration Now for the affected SWG.

  2. Decommission: Gracefully power down and shut down the corrupted VM instance.

  3. Deploy New VM: Provision a fresh Edge SWG VM instance directly using the needed SGOS image.

  4. Initial Setup: Complete the initial CLI wizard to configure management networking (IP, Subnet, Gateway).

  5. Restore: Add the new VM to Management Center and execute Restore Device Backups to push your production configuration.

  6. Verify: Upon initial boot, the fresh filesystem automatically generates a healthy, default passive-attack-protection-only keyring. No manual certificate updates are required.