# XtraBackup fails when using keyring vault for encryption

**URL:** <https://forums.percona.com/t/xtrabackup-fails-when-using-keyring-vault-for-encryption/14204>\
**Category:** Percona XtraBackup\
**Created:** [February 2, 2022, 5:22pm UTC](https://forums.percona.com/t/xtrabackup-fails-when-using-keyring-vault-for-encryption/14204 "2022-02-02T17:22:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![limeaway](https://avatars.discourse-cdn.com/v4/letter/l/e9bcb4/32.png) [@limeaway](https://forums.percona.com/u/limeaway)\
**Post date:** [February 2, 2022, 5:22pm UTC](https://forums.percona.com/t/xtrabackup-fails-when-using-keyring-vault-for-encryption/14204/1 "2022-02-02T17:22:38Z")

</div>

xtrabackup version 2.4.24  
MySQL 5.7.35

Hello - I’m trying to set up a keyring using vault and the server and vault works and I can encrypt tables. But xtrabackup isn’t working with a “keyring\_vault initialization failure”. I’ve tried setting the plugin dir with --xtrabackup-plugin-dir=/usr/lib/xtrabackup/plugin but that gives me the same error. I’ve also made sure the keyring vault config is readable.  
Any ideas on what to look at next?

220202 09:10:17 Added plugin ‘keyring\_vault.so’ to load list.  
Plugin keyring\_vault reported: ‘keyring\_vault initialization failure. Please check that the keyring\_vault\_config\_file points to readable keyring\_vault configuration file. Please also make sure Vault is running and accessible. The keyring\_vault will stay unusable until correct configuration file gets provided.’

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [February 2, 2022, 6:00pm UTC](https://forums.percona.com/t/xtrabackup-fails-when-using-keyring-vault-for-encryption/14204/2 "2022-02-02T18:00:14Z")

</div>

I take it that you’ve gone through the examples on our documentation pages?

> **[Percona Software Documentation](https://docs.percona.com/percona-xtrabackup/2.4/advanced/encrypted_innodb_tablespace_backups.html)**
>
> .container-box-download { justify-content: flex-start; } .container-button-learn-more { margin-bottom: 10px; } .logo-server-home { background: url(/img/product-logos/sprite.png)

---

<div class="post-metadata">

**Author:** ![Marcelo\_Altmann](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/marcelo_altmann/32/11299_2.png) [@Marcelo\_Altmann](https://forums.percona.com/u/Marcelo_Altmann)\
**Post date:** [February 2, 2022, 6:18pm UTC](https://forums.percona.com/t/xtrabackup-fails-when-using-keyring-vault-for-encryption/14204/3 "2022-02-02T18:18:02Z")

</div>

Hi @limeaway .

Please ensure your Percona Server is using vault keyring V1 ( it cannot be configured as auto nor v2).  
Currently vault support for PXB is v1 only.  
We have [[PXB-2608] Upgrade Vault API to V2 - Percona JIRA](https://jira.percona.com/browse/PXB-2608) to upgrade pxb 2.4 support to v2 but it is not released yet.

---

<div class="post-metadata">

**Author:** ![limeaway](https://avatars.discourse-cdn.com/v4/letter/l/e9bcb4/32.png) [@limeaway](https://forums.percona.com/u/limeaway)\
**Post date:** [February 2, 2022, 9:03pm UTC](https://forums.percona.com/t/xtrabackup-fails-when-using-keyring-vault-for-encryption/14204/4 "2022-02-02T21:03:00Z")

</div>

Hi @matthewb - Yes I’ve gone through that documentation. I’m running into the issue just during the backup phase. It seems like the keyring plugin doesn’t get loaded running xtrabackup?

InnoDB: Encryption can’t find master key, please check the keyring plugin is loaded.  
InnoDB: Encryption information in datafile: ./dev/wips.ibd can’t be decrypted, please check if a keyring plugin is loaded and initialized successfully.

HI @Marcelo_Altmann - Yes the server runs fine with the keyring vault and encryption  
I have “secret\_mount\_point\_version = 1” in the keyring vault config
