question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

"Error validating token: IDX10223" Whilst getting a KeyVault secret

See original GitHub issue
  • Package Name: azure-keyvault-secrets
  • Package Version: 4.1.0
  • Operating System: Ubuntu 20.04
  • Python Version: 3.8

Describe the bug After some period of time, running the following will return an error

credential = DefaultAzureCredential()
self._secret_client = SecretClient(vault_url=keyvault_url, credential=credential)
# ... after a undetermined amount of time
self._secret_client.get_secret(secret_name)

Stacktrace

HttpResponseError: (Unauthorized) Error validating token: IDX10223
  File "a/server.py", line 48, in readyz
    cache.get_secret('a-readyz')
  File "a/cache.py", line 21, in get_secret
    secret = self.storage.get_secret(normalised_secret_name, secret_name)
  File "a/storage.py", line 50, in get_secret
    secret_value_obj = self._secret_client.get_secret(secret_name)
  File "/usr/local/lib/python3.8/site-packages/azure/core/tracing/decorator.py", line 83, in wrapper_use_tracer
    return func(*args, **kwargs)
  File "/usr/local/lib/python3.8/site-packages/azure/keyvault/secrets/_client.py", line 66, in get_secret
    bundle = self._client.get_secret(
  File "/usr/local/lib/python3.8/site-packages/azure/keyvault/secrets/_shared/_generated/v7_0/operations/_key_vault_client_operations.py", line 1625, in get_secret
    map_error(status_code=response.status_code, response=response, error_map=error_map)
  File "/usr/local/lib/python3.8/site-packages/azure/core/exceptions.py", line 102, in map_error
    raise error

To Reproduce

Unknown, it happens after a few hours/days, I’ve had this happen in 3 different environments now,

Expected behavior I expected it to return a secret

Additional context

This is running in a container, on Kubernetes in Azure using pod-aad-identity to assign a managed identity to the worker the container is running on, and then handles calls to the metadata address.

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:8 (3 by maintainers)

github_iconTop GitHub Comments

1reaction
chlowellcommented, Jul 20, 2020

You could enable debug logging on the client with logging_enable=True:

self._secret_client = SecretClient(vault_url=keyvault_url, credential=credential, logging_enable=True)

That would log all its requests at DEBUG level with nothing redacted. So, security warning there, but it would let you read the token from a failed request’s Authorization header and check its exp claim (the token is a JWT). Alternatively, you could do similar with the credential instead, i.e. DefaultAzureCredential(logging_enable=True). Then you’d see the token request itself:

Request URL: 'http://169.254.169.254/...'
Request method: 'GET'
Request headers:
    'Metadata': 'true'
    'User-Agent': 'azsdk-python-identity/1.3.1 ...'
Request body:
None
Response status: 200
Response headers:
    'Content-Type': 'application/json; charset=utf-8'
    'Date': 'Mon, 20 Jul 2020 16:19:39 GMT'
    'Content-Length': '1643'
Response content:
{"access_token":"...","expires_on":"1595347982", ...}

For a monkeypatch approach, SecretClient adds tokens to requests here and the credential deserializes the token here.

0reactions
msftbot[bot]commented, Aug 14, 2020

Hi, we’re sending this friendly reminder because we haven’t heard back from you in a while. We need more information about this issue to help address it. Please be sure to give us your input within the next 7 days. If we don’t hear back from you within 14 days of this comment the issue will be automatically closed. Thank you!

Read more comments on GitHub >

github_iconTop Results From Across the Web

Azure keyvault gives: [TokenExpired] Error validating token
This error may cause if the keyvault unable to authenticate web app. Please check whether you enable system assigned managed identity as ...
Read more >
Azure Key Vault REST API Error Codes - Microsoft Learn
No authentication token attached to the request. Here is an example PUT request, setting the value of a secret: Copy.
Read more >
Solution for Error validating token IDX10223 - Jon Gallant
Got this error today when trying to set a secret with terraform. Error checking for presence of existing Secret keyvault.
Read more >
Using secrets from Azure Key Vault in a pipeline
We will retrieve the password in an Azure pipeline and passed on to subsequent tasks. Before you begin. Refer the Getting Started page...
Read more >
JWT Token Validation in C# - Quinn Gil
The initial problem was that the ValidateToken method requires the signature to successfully validate. I had to get the ... I'm assuming public ......
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found