<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Unable to insert secret into keystore&amp;quot; error when enabl in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006988#M586796</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Ref :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/16_xe/smg/xe-16-10/b-sem-16-10-1/b-sem-16-10-1_chapter_0100.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/16_xe/smg/xe-16-10/b-sem-16-10-1/b-sem-16-10-1_chapter_0100.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;gt;...&lt;/P&gt;
&lt;TABLE id="r-sem-16-10-1-ISDN-to-KEYSTORE__sec-KEYSTORE-tab13" class="table frame-topbot" border="1" width="100%"&gt;
&lt;THEAD class="thead"&gt;
&lt;TR class="row"&gt;
&lt;TH id="r-sem-16-10-1-ISDN-to-KEYSTORE__sec-KEYSTORE-tab13__entry__1" class="entry colsep-0 rowsep-0" colspan="2"&gt;%KEYSTORE-3-NO_KEYSTORE : CTS hardware keystore is not responsive and software emulation is not enabled.&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row"&gt;
&lt;TD class="entry colsep-0 rowsep-0"&gt;&lt;STRONG class="ph b"&gt;Explanation&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD class="entry colsep-0 rowsep-0"&gt;&lt;EM&gt;The CTS hardware keystore on the switch has failed and needs to be inspected. Since CTS credentials are stored in the keystore, this means that CTS authentication and authorization operations will fail. The following action is recommended: If the defect is shown on the Active Supervisor, try to switchover to Standby Supervisor. If the defect is shown on Standby Supervisor, try to reset the Standby. If the defect persists, there may be damage to the hardware keystore chip, please take appropriate action. In the meantime, you can configure the switch to use software keystore emulation. After you have enabled software keystore emulation, please re-configure CTS credentials to populate the software keystore.&lt;/EM&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Sat, 27 Jan 2024 11:45:11 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2024-01-27T11:45:11Z</dc:date>
    <item>
      <title>"Unable to insert secret into keystore" error when enabling TrustSec</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006944#M586794</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have several Catalyst &lt;STRONG&gt;9200L&lt;/STRONG&gt; switches (version &lt;STRONG&gt;17.09.04a&lt;/STRONG&gt;) and want to implement Cisco TrustSec on them, followed by integrating them with Cisco ISE.&lt;/SPAN&gt; &lt;SPAN&gt;At the initial step, upon executing the '&lt;STRONG&gt;cts credentials id&lt;/STRONG&gt;' command, the following log messages are displayed:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Unable to insert secret into keystore.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;%KEYSTORE-3-NO_KEYSTORE: CTS hardware keystore is not responsive and software emulation is not enabled.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1706344573076.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208884iA2B50BBB40BDBE10/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1706344573076.png" alt="rezaalikhani_0-1706344573076.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I searched Google, but unfortunately, I did not find useful information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My questions are:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Does the message pertain to any malfunctioning hardware on the device?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;How can I enable software emulation for the same purpose of hardware keystore?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Does this problem relate to the current license of the device?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 08:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006944#M586794</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-27T08:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006988#M586796</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Ref :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/16_xe/smg/xe-16-10/b-sem-16-10-1/b-sem-16-10-1_chapter_0100.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/16_xe/smg/xe-16-10/b-sem-16-10-1/b-sem-16-10-1_chapter_0100.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;gt;...&lt;/P&gt;
&lt;TABLE id="r-sem-16-10-1-ISDN-to-KEYSTORE__sec-KEYSTORE-tab13" class="table frame-topbot" border="1" width="100%"&gt;
&lt;THEAD class="thead"&gt;
&lt;TR class="row"&gt;
&lt;TH id="r-sem-16-10-1-ISDN-to-KEYSTORE__sec-KEYSTORE-tab13__entry__1" class="entry colsep-0 rowsep-0" colspan="2"&gt;%KEYSTORE-3-NO_KEYSTORE : CTS hardware keystore is not responsive and software emulation is not enabled.&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR class="row"&gt;
&lt;TD class="entry colsep-0 rowsep-0"&gt;&lt;STRONG class="ph b"&gt;Explanation&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD class="entry colsep-0 rowsep-0"&gt;&lt;EM&gt;The CTS hardware keystore on the switch has failed and needs to be inspected. Since CTS credentials are stored in the keystore, this means that CTS authentication and authorization operations will fail. The following action is recommended: If the defect is shown on the Active Supervisor, try to switchover to Standby Supervisor. If the defect is shown on Standby Supervisor, try to reset the Standby. If the defect persists, there may be damage to the hardware keystore chip, please take appropriate action. In the meantime, you can configure the switch to use software keystore emulation. After you have enabled software keystore emulation, please re-configure CTS credentials to populate the software keystore.&lt;/EM&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 11:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006988#M586796</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-01-27T11:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006999#M586797</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have reviewed this resource, and as you can see, there are many unanswered questions regarding this problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 12:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5006999#M586797</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-27T12:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007009#M586798</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check the output of :&amp;nbsp; #&amp;nbsp;&amp;nbsp;&lt;EM class="Green"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;STRONG class="cBold"&gt;show cts keystore&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 12:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007009#M586798</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-01-27T12:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007032#M586799</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1706361247219.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208895i66E563DF4D01AB56/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1706361247219.png" alt="rezaalikhani_0-1706361247219.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 13:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007032#M586799</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-27T13:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007064#M586800</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt; &amp;nbsp;- Check if you can execute this procedure on your platform too :&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/ident-conn_config.html#77849" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/ident-conn_config.html#77849&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 14:22:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007064#M586800</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-01-27T14:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007298#M586806</link>
      <description>&lt;P&gt;As you can see below, the device does not have the ability to use emulated keystore:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1706431527215.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208927i46DCAF78133B1F65/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1706431527215.png" alt="rezaalikhani_0-1706431527215.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I think the problem is related to my device license. As you can see below, the device does not have&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;Network Advantage&lt;/STRONG&gt; license which is required to support SGT, based on the following Cisco's document:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/m/en_us/products/software/dna-subscription-switching/en-sw-sub-matrix-switching.html" target="_blank"&gt;https://www.cisco.com/c/m/en_us/products/software/dna-subscription-switching/en-sw-sub-matrix-switching.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_1-1706433760425.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208929i5A67DE2FB5944807/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_1-1706433760425.png" alt="rezaalikhani_1-1706433760425.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1706433688352.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208928i1C23DD109B8526CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1706433688352.png" alt="rezaalikhani_0-1706433688352.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 09:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5007298#M586806</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-28T09:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5023835#M587645</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;Your solution also clearly stated below for Catalyst 9200 switches:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-12/configuration_guide/cts/b_1612_cts_9200_cg/configuring_sgt_mapping.html#reference_y5s_cn1_cjb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-12/configuration_guide/cts/b_1612_cts_9200_cg/configuring_sgt_mapping.html#reference_y5s_cn1_cjb&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2024 14:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5023835#M587645</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-02-24T14:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5037527#M588006</link>
      <description>&lt;P&gt;Rez,&lt;/P&gt;&lt;P&gt;Did you obtain the Network Advantage License? did it resolve your problem?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 13:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5037527#M588006</guid>
      <dc:creator>DamianRCL</dc:creator>
      <dc:date>2024-03-11T13:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5037932#M588021</link>
      <description>&lt;P&gt;Unfortunately not for now but will be soon. If so i will update this post.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 07:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5037932#M588021</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-03-12T07:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: "Unable to insert secret into keystore" error when enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5253966#M594601</link>
      <description>&lt;P&gt;I had this exact same issue, with all the same results people posted above. I wanted to confirm/let others know that my C9200 switch was also using a DNA Essentials license. I upgraded the device's license to Advantage from within Catalyst Center and once the device restarted the command(s) worked as they should.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 22:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-unable-to-insert-secret-into-keystore-quot-error-when/m-p/5253966#M594601</guid>
      <dc:creator>MikeMoss</dc:creator>
      <dc:date>2025-01-28T22:32:18Z</dc:date>
    </item>
  </channel>
</rss>

