メインコンテンツまでスキップ

エラー:コマンドが失敗しました:「 x.x.x.x 」のキーサーバには、現在使用中では使用できないボリューム暗号化キーが格納されています

Views:
1
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core<a>2008739541</a>
Last Updated:

環境

  • ONTAP 9
  • 外部キーマネージャ(EKM)
  • NetApp Volume Encryption(NVE)

問題

  • 外部キー管理サーバを新しいサーバに移行しようとしても、最後のキーサーバは削除できません。
Cluster-01::*> security key-manager external remove-servers -vserver cluster-1 -key-servers 10.28.XX.XX
 
Error: command failed: The key server at "10.28.XX.XX" contains volume encryption keys that are currently in use
and not available from any other configured key server.
  • 新しいKMIPサーバ に証明 書とキー がコピーさ れてい ますが、クラスタは それらのサーバからキーを取得しません。 
  • 次の例では、10.28.XX.XXが古いキーサーバの最後です。新しいキーサーバは使用可能と表示されますが、キークエリには表示されません。
Cluster-01::> security key-manager key query
Node: Cluster-01-01
Vserver: Cluster-01
Key Manager: 10.28.XX.XX:5696
Key Manager Type: KMIP
 
Key Tag Key Type Restored
------------------------------------ -------- --------
2170bf6c-998b-11eb-b2a8-d039ea061535 VEK true
Key ID: 00000000000000000200000000000500d3a552b209a7265eb531e4cf5adb21c50000000000000000
38bc9422-998b-11eb-b2a8-d039ea061535 VEK true
Key ID: 00000000000000000200000000000500e32ca6a0c308f850c51120b47334869f0000000000000000
27696c31-998b-11eb-b2a8-d039ea061535 VEK true
Key ID: 00000000000000000200000000000500fefbd8470e63a8877d53509b9cd708e40000000000000000
 
Node: Cluster-01-02
Vserver: Cluster-01
Key Manager: 10.28.XX.XX:5696
Key Manager Type: KMIP
 
Key Tag Key Type Restored
------------------------------------ -------- --------
2170bf6c-998b-11eb-b2a8-d039ea061535 VEK true
Key ID: 00000000000000000200000000000500d3a552b209a7265eb531e4cf5adb21c50000000000000000
38bc9422-998b-11eb-b2a8-d039ea061535 VEK true
Key ID: 00000000000000000200000000000500e32ca6a0c308f850c51120b47334869f0000000000000000
27696c31-998b-11eb-b2a8-d039ea061535 VEK true
Key ID: 00000000000000000200000000000500fefbd8470e63a8877d53509b9cd708e40000000000000000
6 entries were displayed.
  • 使用可能なキーサーバ:
Cluster-01::*> key-manager show -status
security key-manager show)
 
Node Port Registered Key Manager Status
---------------------- ------ --------------------------- ---------------
Cluster-01-01 5696 10.28.XX.XX available           
Cluster-01-01 5696 10.36.XX.XX available
Cluster-01-02 5696 10.28.XX.XX available
Cluster-01-02 5696 10.36.XX.XX available

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.