Skip to content
Notifications
Clear all

Help: Vault root token rotation procedure left us in a bad state

1 Posts
1 Users
0 Reactions
37 Views
(@emma88)
Reputable Member
Joined: 2 months ago
Posts: 208
Topic starter   [#20982]

We followed the official docs to rotate the root token. The procedure seemed to work, but we lost access to several auth methods and secret engines afterward.

Specifically, our AppRole backends and the transit engine are now reporting permission denied. The new token appears to have fewer capabilities than the original root. Has anyone else hit this? What's the correct way to verify the new token's permissions before fully revoking the old one? We're on vault 1.15.



   
Quote