Docker-based Secure Access Resource Connectors on Ubuntu were launching successfully but failing to register to Cisco Secure Service Edge (SSE), resulting in error 106 due to instance ID length validation and no connector visibility in the dashboard.
The Resource Connector launch appeared successful with the message "Resource Connector launched successfully", but the connector failed to appear in the SSE dashboard and diagnostic checks revealed registration failures.
The diagnostic output showed multiple network connectivity issues including DNS resolution failures for SSE services and the specific daemon error:
daemon init state
106
The diagnostic health check indicated:
error: 106 fail to register, the provision key could be expired
Despite regenerating the provisioning key multiple times and verifying firewall rules, the registration continued to fail with no connector appearing in the dashboard.
Cisco Secure Access - Resource Connector
Docker-based deployment on Ubuntu
The issue was resolved by addressing the instance ID length validation error that was causing the registration failure. The actual root cause was not an expired provisioning key or network connectivity issues, but rather the Resource Connector hostname being too long, which resulted in a generated instance ID exceeding the 50-character limit.
Review the Resource Connector logs to identify the actual registration error by running 'sudo /opt/connector/data/bin/techsupport':
2026-05-28T17:08:51Z INF requesting registration func=makeACARegistrationRequest parameters={"environment":"container","hostname":"(NAME)","instanceId":"(NAME)-d5d28cd78f24759","originIpAddress":"10.162.129.140","sha1":"9a1146f75071717837eff564e7f950a6e8ff2303","version":"v2.0.99"}
2026-05-28T17:08:51Z ERR registration request failed error="RegisterConnector::failed registration request with code 400 - Validation Error - {InstanceId:Attribute value length should be between 1 to 50 Version: Hostname: Sha1: OriginIpAddress: Environment:}" func=registerAndInitACA
Ensure the Resource Connector hostname is short enough so that the generated instance ID remains between 10 and 50 characters. The instance ID is generated by combining the hostname with a hash suffix.
Launch the Resource Connector with a shorter hostname:
sudo /opt/connector/install/connector.sh launch --name [shorter-name] --key [provisioning-key]
Ensure IP forwarding is enabled on the host system:
echo "net.ipv4.ip_forward=1" | sudo tee /etc/sysctl.d/99-docker-forwarding.conf
Restart the container or virtual machine to apply the IP forwarding configuration and ensure the Resource Connector starts with the new hostname.
Run the diagnostic command to verify successful registration:
/opt/connector/data/bin/diagnostic
Check that the daemon init state no lonsger shows error 106 and that the Resource Connector appears in the SSE dashboard.
The Resource Connector registration failure was caused by an instance ID length validation error. When the Resource Connector hostname is too long, the generated instance ID (which combines the hostname with a hash suffix) exceeds the maximum allowed length of 50 characters. The SSE API validates the instance ID length and rejects registration requests with instance IDs that fall outside the 1-50 character range, resulting in a 400 validation error and preventing the connector from appearing in the dashboard.
The error 106 "fail to register, the provision key could be expired" message was misleading, as the actual issue was not related to the provisioning key expiration but rather to the instance ID validation failure.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
06-Oct-2026
|
Initial Release |