Ansible beyondtrust.secrets_safe lookup fails with 401 after BeyondTrust Password Safe upgrade to 26.2
Issue
-
After upgrading BeyondTrust Password Safe from 24.2 to 26.2, Ansible playbooks fail to retrieve secrets using the
beyondtrust.secrets_safecollection. -
The lookup plugin fails with the following error:
The lookup plugin 'beyondtrust.secrets_safe.secrets_safe_lookup' failed: Error getting secret by path, message: "Failed to authenticate due to one or more authentication rules.", statuscode: 401 -
On the BeyondTrust Password Safe appliance logs, requests to
/BeyondTrust/api/public/v3/secrets-safe/secretsreturn HTTP 401 Unauthorized:GET /BeyondTrust/api/public/v3/secrets-safe/secrets title=svc_unixad&path=... - 401 0 0 616 393 4
Environment
- Red Hat Enterprise Linux (RHEL)
- 8.x
- 9.x
- Ansible Core
- 2.16 or later
beyondtrust.secrets_safeAnsible collection- 1.0.0
- BeyondTrust Password Safe
- 26.2 (upgraded from 24.2)
NOTE: The
beyondtrust.secrets_safeAnsible collection and BeyondTrust Password Safe are third-party products maintained by BeyondTrust on Ansible Galaxy. Debugging third-party APIs or code-level troubleshooting of third-party Galaxy collections falls outside the scope of Red Hat Production Support. This information is provided as a courtesy to assist in environment diagnosis and configuration.
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.