An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
I think the key is using a PKCS8 PEM and saving that same multiline PEM as a file in Key Vault so ADF can read it.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I am trying to set up key-pair authentication between Data Factory and Snowflake. I want to store the private key inside of a secret in Key Vault. When testing the connection, I receive the following error:
Test connection operation failed. Failed to open the database connection. [Snowflake] Failed to parse PEM block containing the private key
I've seen that it may require inserting newline characters (\n) into the key but that hasn't worked for me. Does anyone have insight as to the correct format for the private key?
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
I think the key is using a PKCS8 PEM and saving that same multiline PEM as a file in Key Vault so ADF can read it.
AI answer
For Azure Data Factory’s Snowflake V2 linked service with key-pair authentication, the private key must be provided in a very specific format, and when using Azure Key Vault the multi-line PEM must be preserved exactly.
Key points for the correct format:
rsa_key.p8.\n) and must remain a valid PEM when retrieved by Data Factory.-----BEGIN ... PRIVATE KEY----- header line-----END ... PRIVATE KEY----- footer lineFailed to parse PEM block containing the private key. cat rsa_key.p8
--file to preserve multi-line format:
az keyvault secret set \
--vault-name <your-keyvault-name> \
--name <your-secret-name> \
--file rsa_key.p8
privateKey property is an Azure Key Vault secret reference (SecretBase) for key-pair auth.privateKey property points to that Key Vault secret (not an inline string), so Data Factory retrieves the exact PEM content.\n in the string literal, as documented:
If the error persists, the most common causes are:
Ensuring a valid PKCS#8 PEM and storing it via CLI/Cloud Shell into Key Vault, then referencing that secret in the privateKey property, aligns with the documented pattern and avoids the Snowflake PEM parse error.
References:
I was able to get it working by using Powershell to save the multiline secret instead of converting it to a single line in bash. Thanks for your help!