We use a Secure Store Service Application for several external connections. All else appears normal, however, we frequently find that the master encryption key requires a manual refresh. In the meantime, the secure store service application is non-functional, and of course so is everything beyond it, for users.
The issue has been occurring since we set SSSA up months ago. It's been difficult to pinpoint exactly the types of actions that produce this state. It appears common that a reboot of the SharePoint server (all-inclusive, one server in farm, SQL services elsewhere on different server) triggers the need for a key refresh. We have reproduced the issue each of the past two nights, with scheduled reboots.
When in Central Administration, the Secure Store Service Application page shows "Unable to obtain master key".
If we try to access a data connection beyond the SSSA, Windows logs receive a few events:
Windows Application log shows Event ID 7522 from Secure Store, saying "[...] encountered a failure while restoring the encryption key. The error returned was: 'Exception of type 'Microsoft.Office.SecureStoreService.Server.KeyManagement.InvalidMasterKeyException' was thrown.'."
Another event, ID 7535 is also thrown: "[...] failed to retrieve the master secret key. The error returned was: 'Unable to obtain master key.'"
Any help or insight is greatly appreciated!









