[SOLVED] CEPH Key Migration now "Not a proper rbd authentication file error"

# pveversion -v
proxmox-ve: 9.2.0 (running kernel: 7.0.14-19-pve)
pve-manager: 9.2.20 (running version: 9.2.20/49318c671b82f31e)
proxmox-kernel-helper: 9.2.0
pve-kernel-6.2: 8.0.5
proxmox-kernel-7.0.14-19-pve-signed: 7.0.14-19
proxmox-kernel-7.0: 7.0.14-19
proxmox-kernel-7.0.14-17-pve-signed: 7.0.14-17
proxmox-kernel-6.17: 6.17.13-21
proxmox-kernel-6.17.13-21-pve-signed: 6.17.13-21
proxmox-kernel-6.2.16-20-pve: 6.2.16-20
proxmox-kernel-6.2: 6.2.16-20
pve-kernel-6.2.16-3-pve: 6.2.16-3
ceph: 19.2.6-pve4
ceph-fuse: 19.2.6-pve4
corosync: 3.1.10-pve3
criu: 4.1.1-1
frr-pythontools: 10.6.1-1+pve3
ifupdown2: 3.3.0-1+pmx12
intel-microcode: 3.20251111.1~deb13u1
ksm-control-daemon: 1.5-1
libjs-extjs: 7.0.0-7
libproxmox-acme-perl: 1.7.2
libproxmox-backup-qemu0: 2.0.3
libproxmox-rs-perl: 0.4.1
libpve-access-control: 9.1.2
libpve-apiclient-perl: 3.4.3
libpve-cluster-api-perl: 9.1.6
libpve-cluster-perl: 9.1.6
libpve-common-perl: 9.2.2
libpve-guest-common-perl: 6.0.5
libpve-http-server-perl: 6.0.5
libpve-network-perl: 1.6.7
libpve-notify-perl: 9.1.6
libpve-rs-perl: 0.15.3
libpve-storage-perl: 9.1.2
libspice-server1: 0.15.2-1+b1
lvm2: 2.03.31-2+pmx1
lxc-pve: 7.0.0-2
lxcfs: 7.0.0-pve1
novnc-pve: 1.7.0-2
proxmox-backup-client: 4.2.6-1
proxmox-backup-file-restore: 4.2.6-1
proxmox-backup-restore-image: 1.0.0
proxmox-enterprise-support-keyring: 1.1
proxmox-firewall: 1.2.3
proxmox-kernel-helper: 9.2.0
proxmox-mail-forward: 1.0.3
proxmox-mini-journalreader: 1.7
proxmox-widget-toolkit: 5.2.10
pve-cluster: 9.1.6
pve-container: 6.1.14
pve-docs: 9.2.12
pve-edk2-firmware: 4.2026.08-1
pve-esxi-import-tools: 1.0.1
pve-firewall: 6.0.6
pve-firmware: 3.18-6
pve-ha-manager: 5.2.5
pve-i18n: 3.10.0
pve-qemu-kvm: 11.0.3-3
pve-xtermjs: 6.0.0-2
qemu-server: 9.1.16
smartmontools: 7.5-pve2
spiceterm: 3.4.2
swtpm: 0.8.0+pve3
vncterm: 1.9.2
zfsutils-linux: 2.3.4-pve1
 
# apt update
Hit:1 http://ftp.us.debian.org/debian trixie InRelease
Get:2 http://ftp.us.debian.org/debian trixie-updates InRelease [47.3 kB]
Get:3 http://security.debian.org trixie-security InRelease [43.4 kB]
Get:4 http://security.debian.org trixie-security/main amd64 Packages [264 kB]
Get:5 http://security.debian.org trixie-security/main Translation-en [161 kB]
Get:6 http://download.proxmox.com/debian/pve trixie InRelease [4,357 B]
Hit:7 http://download.proxmox.com/debian/ceph-squid trixie InRelease
Get:8 http://download.proxmox.com/debian/pve trixie/pve-no-subscription amd64 Packages [392 kB]
Fetched 912 kB in 1s (925 kB/s)
18 packages can be upgraded. Run 'apt list --upgradable' to see them.

# apt full-upgrade
The following package was automatically installed and is no longer required:
libzpool6linux
Use 'apt autoremove' to remove it.

Upgrading:
libheif-plugin-aomenc libheif-plugin-x265 libpcre2-8-0 linux-libc-dev qemu-server zfs-zed
libheif-plugin-dav1d libheif1 libpcre2-posix3 pve-docs rsync zfsutils-linux
libheif-plugin-libde265 libpcre2-16-0 libpve-storage-perl pve-manager zfs-initramfs

Installing dependencies:
libzfs7linux libzpool7linux

REMOVING:
libzfs6linux

Summary:
Upgrading: 17, Installing: 2, Removing: 1, Not Upgrading: 0
Download size: 25.9 MB
Space needed: 5,908 kB / 70.8 GB available
 
Last edited:
so you haven't installed upgrades - please do so (if you haven't in the meantime), then those errors will disappear..

edit: did you maybe install updates using "upgrade" instead of "full-upgrade"? because of the ZFS library transition, that might have held off some of the packages.. there's a version constraint from pve-storage to ZFS that matches your old package version, for example..
 
Last edited:
I'm curious what packages you noticed in my "pveversion -v" list which were old, and I'm curious what package update should have resolved the "regressive upstream parser bug." In any case, thanks for your help!
 
Gemini saved my butt.

"This persistent failure confirms you are experiencing a known regressive upstream parser bug introduced in the September 2026 Proxmox VE (9.2.x) updates.

Fix 1: The Triple Equals (===) Pad Trick (Quickest Bypass)

Because the pve-storage parsing code uses a strict regular expression to validate the key length, adding a trailing = sign padding forces the regex validation to pass while the underlying librbd and kernel client ignore the extra whitespace character..."

Bottom line:

1 add one '=' to the end of the key in both /etc/pve/priv/ceph/cfs.secret (for my cephfs filesystem) and /etc/pve/priv/ceph/cbd.keyring (for my rbd pool)
2 systemctl restart pvestatd

Are you kidding me? Two equal signs!


Thanks for sharing this! That padding trick just saved my setup too.

I was hitting the exact same Not a proper rbd authentication file error after recent updates on PVE 9.2. Adding the trailing = to the key in /etc/pve/priv/ceph/ and restarting pvestatd cleared the error right away.

Can't believe a base64/regex length parser issue caused this much headache, but glad to have it sorted out. Cheers!
 
Thanks for sharing this! That padding trick just saved my setup too.

I was hitting the exact same Not a proper rbd authentication file error after recent updates on PVE 9.2. Adding the trailing = to the key in /etc/pve/priv/ceph/ and restarting pvestatd cleared the error right away.

Can't believe a base64/regex length parser issue caused this much headache, but glad to have it sorted out. Cheers!
I cannot believe how often I have to post this in this thread - if you run into this issue, your system is misconfigured and not getting proper upgrades. that issue has been fixed in parallel to the ceph updates, if you run into it you only upgraded the ceph packages and not the relevant parts of PVE itself, and are missing other fixes including security fixes. please fix your repository setup and/or upgrade procedures!