Troubleshooting Guide
"No license is installed" when creating a user
The appliance refuses new user creation until a .lic is
uploaded. Go to Manage License and install one. If your
license is uploaded but the message persists, check the page header
— the license may be EXPIRED or REVOKED.
Browser warns about an untrusted certificate
The installer generates a self-signed cert (CN=sos-vault.local).
Replace it from Certificate Manager: upload your real
fullchain.pem and privkey.pem. If your environment
uses an internal CA, also upload the corporate root under "Corporate Root
CA" so other hosts on the network trust the new cert without a per-machine
override.
Vault storage is nearly full
The vault is a plain directory (default /vault; see
Disk Manager for the configured path). Free space the usual
way: grow the underlying volume or filesystem, prune retired cases, or move
/vault onto larger storage or a network share (NFS/CIFS) mounted by
the OS and point Disk Manager at the new path.
Cannot install a license — "machine token mismatch"
The license binds to the host fingerprint captured at install (machine-id +
DMI identifiers). If the hardware changed, the stored tokens no longer match the
issued .lic. Re-run the installer to re-capture the host
fingerprint, then generate a fresh license request key from
Manage License, re-verify it at sos-vault.com, and order a
replacement .lic from the Customer Portal.
Locked out of an admin account (2FA)
Admins must use TOTP 2FA. If an admin loses their authenticator device —
or the appliance clock drifts on a host without NTP so the codes are rejected
— reset 2FA for that account from a shell on the host, then have them sign
in and re-enrol at Settings → Security:
docker compose exec -T <app-container> \
sudo -u www-data php artisan 2fa:disable <email|username|id>
If the clock is the culprit, fix time sync (enable NTP/chrony) so future codes
validate. To make 2FA optional for admins entirely, turn off the
auth.two_factor_required_for_admins setting.
sos-vault.service will not start
Diagnostics in order:
sudo systemctl status sos-vault.service
sudo journalctl -u sos-vault.service -n 200 --no-pager
sudo docker compose -f /opt/sos-vault/docker-compose.yml ps
sudo docker compose -f /opt/sos-vault/docker-compose.yml logs --tail=200
Most failures are /etc/default/sos-vault pointing at the wrong
install root, or the host running out of disk under /var/lib/docker.
nginx container reload after a cert upload silently fails
Check the sudoers fragment /etc/sudoers.d/sos-vault-cert was
installed (mode 0440, owned root:root) and that
SOS_VAULT_NGINX_CONTAINER matches your live compose service
name. The fragment scopes www-data NOPASSWD on
docker exec sos-vault-nginx nginx -s reload and nothing else.