byok-server.service) fails to start and remains in a crash loop./opt/vmware/byok/logs/byok-error.logtime="####-##-###########" level=error msg="cloud director endpoint https://<VCD-FQDN>:443/oauth/provider/token failed: {\"error\":\"invalid_grant\",\"error_description\":\"Invalid refresh token\",\"error_uri\":null,\"minorErrorCode\":\"invalid_grant\",\"message\":\"Invalid refresh token\",\"stackTrace\":null}"This issue can occur when the refresh token stored in the Encryption Management appliance's local configuration (/opt/vmware/byok/etc/config.yaml) no longer matches the token expected by VMware Cloud Director.
To resolve this issue in Encryption Management 1.2.1, A clean removal and reinstallation of the add-on configuration should be performed.
This process will force a new OAuth Device Authorization flow and synchronize a fresh token.
Note: Proceeding with a full removal and reinstallation of the add-on will temporarily prevent existing end-tenants from performing encryption-related tasks (such as managing keys or creating encrypted VMs). This reconnection does not happen automatically. Once the provider completes the resolution steps below, tenant administrators must manually log into their VCD Tenant Portal to re-authenticate their sessions (detailed in Step 10).
encryption-management-system-user service account should be 'Active'.root user./mnt/cdrom/vcdemctl addon remove/mnt/cdrom/vcdemctl addon installbyok-server service.