When updating the passive-attack-protection-only-key keyring via Management Center (MC) script or local CLI, the operation fails with: % Unable to read or create file
Appliance Event Logs:
CFSSL: can't open file to read /legacy/.../config/v10/pki/passive-attack-protection-only-key
Unexpected error extracting certificate for keyring 'passive-attack-protection-only-key'Note: Converting the private key format (PKCS#8 to PKCS#1)
File system/directory layout corruption on the virtual disk. The underlying PKI directory path may have become unreadable or unwritable by the OS. Standard SGOS software upgrades cannot repair a corrupted disk layout, preventing the appliance from committing new keyring objects.
A clean redeployment of the affected Virtual Machine is required.
Backup: In Management Center, trigger Back Up Device Configuration Now for the affected SWG.
Decommission: Gracefully power down and shut down the corrupted VM instance.
Deploy New VM: Provision a fresh Edge SWG VM instance directly using the needed SGOS image.
Initial Setup: Complete the initial CLI wizard to configure management networking (IP, Subnet, Gateway).
Restore: Add the new VM to Management Center and execute Restore Device Backups to push your production configuration.
Verify: Upon initial boot, the fresh filesystem automatically generates a healthy, default passive-attack-protection-only keyring. No manual certificate updates are required.