# Chef vault issue

**URL:** <https://discourse.chef.io/t/chef-vault-issue/11993>\
**Category:** Chef Infra (archive)\
**Created:** [November 20, 2017, 3:24pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993 "2017-11-20T15:24:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![priyanshu](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@priyanshu](https://discourse.chef.io/u/priyanshu)\
**Post date:** [November 20, 2017, 3:24pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993/1 "2017-11-20T15:24:30Z")

</div>

while creating a chef vault, if we use -C option and many values then it is unable to recognize the private key of the node,  
whereas when using -S option then also it gives the same error.

but when using these options with a single value of client then it gives no error?

---

<div class="post-metadata">

**Author:** ![thommay](https://avatars.discourse-cdn.com/v4/letter/t/f08c70/32.png) [@thommay](https://discourse.chef.io/u/thommay)\
**Post date:** [November 20, 2017, 3:36pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993/2 "2017-11-20T15:36:26Z")

</div>

Please share _exactly_ the command line you’re using to specify many nodes with the `-C` option.

---

<div class="post-metadata">

**Author:** ![priyanshu](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@priyanshu](https://discourse.chef.io/u/priyanshu)\
**Post date:** [November 21, 2017, 6:34am UTC](https://discourse.chef.io/t/chef-vault-issue/11993/3 "2017-11-21T06:34:06Z")

</div>

knife vault create \<vault\_name\> -A ‘user1,user2’ -M client -C ‘name:node1name,node2name’ -J /path/xyz.json file

This does not recognizes the private key on node1 .  
When used only one name in -C option then recognizes the key and in vault which was created, the client is having the name of node.

---

<div class="post-metadata">

**Author:** ![thommay](https://avatars.discourse-cdn.com/v4/letter/t/f08c70/32.png) [@thommay](https://discourse.chef.io/u/thommay)\
**Post date:** [November 21, 2017, 9:35am UTC](https://discourse.chef.io/t/chef-vault-issue/11993/4 "2017-11-21T09:35:11Z")

</div>

Like I said, that syntax is not right.  
`knife vault create <vault_name> -A ‘user1,user2’ -M client -C ‘name:node1name,node2name’ -J /path/xyz.json file`

should be  
`knife vault create <vault_name> -A ‘user1,user2’ -M client -C ‘node1name,node2name’ -J /path/xyz.json file`  
ie, remove the `name:` at the start of the -C section when you’re specifying the list of nodes. It’s not a search.

---

<div class="post-metadata">

**Author:** ![priyanshu](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@priyanshu](https://discourse.chef.io/u/priyanshu)\
**Post date:** [November 21, 2017, 12:14pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993/5 "2017-11-21T12:14:15Z")

</div>

@thommay what’s the exact difference between -C and -S option?

---

<div class="post-metadata">

**Author:** ![thommay](https://avatars.discourse-cdn.com/v4/letter/t/f08c70/32.png) [@thommay](https://discourse.chef.io/u/thommay)\
**Post date:** [November 21, 2017, 3:12pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993/6 "2017-11-21T15:12:35Z")

</div>

-C takes a comma separated list of nodes, -S takes a search.  
ie: `-C nodea,nodeb,nodec` or `-S name:node*` .

---

<div class="post-metadata">

**Author:** ![priyanshu](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@priyanshu](https://discourse.chef.io/u/priyanshu)\
**Post date:** [November 27, 2017, 3:14pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993/7 "2017-11-27T15:14:07Z")

</div>

@thommay though the private key is existing on node but when using  
knife vault create \<vault\_name\> -A ‘user1,user2’ -M client -C ‘node1name,node2name’ -J /path/xyz.json file

This does not recognizes the private key on node1 ?? why is this happening

---

<div class="post-metadata">

**Author:** ![priyanshu](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@priyanshu](https://discourse.chef.io/u/priyanshu)\
**Post date:** [November 27, 2017, 3:32pm UTC](https://discourse.chef.io/t/chef-vault-issue/11993/8 "2017-11-27T15:32:36Z")

</div>

@thommay i am creating vault through root user but on node running the recipe as oracle user so does this make it for the cookbook to be not recognizable and it says that

vault/vault item is not encrypted with your public key. Contact an administrator of the vault item to encrypt for you!

Or is there any problem in the creation of vault
