When principal has no permission to set or get an entry, FreeIPA fails with an exception like
ACIError: Insufficient access: Insufficient 'add' privilege to add the entry 'cn=keys__secrets__test10,cn=custodia/client1.ipa.example@IPA.EXAMPLE,cn=services,cn=vaults,cn=kra,dc=ipa,dc=example'
custodia.ipa should map the exception to HTTP 404 error.