In helping a customer who was having an issue with getting TOTP working, I came upon an interesting situation with their ID Vault. When issuing ‘show idvault’, the following error was displayed.
Invalid or nonexistent document: Vault replica list inconsistency for vault /ID_Vault
The really strange thing about this situation was the replica of the ID Vault was on both the primary and secondary server, however only the primary server was listed as a Vault Server in the ID Vault itself. Additionally, the Public Encryption Key for the RecoveryKeys document only had the primary server listed, the secondary server was missing.