キーがリストアされたときにKeymanagerが原因でギブバックが拒否された
環境
- タレス外部キー管理機能
- NetApp Volume Encryption(NVE)
- ONTAP 9
問題
- ONTAPアップグレードのためにANDUが開始されました
- キー管理ツールが原因でデータアグリゲートのギブバックが拒否された
Cluster::*> sto fa show-giveback
(storage failover show-giveback)
Partner
Node Aggregate Giveback Status
-------------- -------------------- --------------------------------------------
Node1 CFO Aggregates Done
aggr_data
Failed: Operation was vetoed by keymanager.
Check the event log Node2
No aggregates to give back
3 entries were displayed.
Cluster::*> event log show -severity AlERT
Time Node Severity Event
------------------- ---------------- ------------- ---------------------------
6/17/2023 21:37:04 Node1 ALERT sfo.giveback.failed: Giveback of aggregate aggr_data failed due to Giveback was vetoed..
6/17/2023 21:37:04 Node1 ALERT sfo.sendhome.subsystemAbort: The giveback operation of 'aggr_data' was aborted by 'keymanager'.
- ボリューム暗号化キーがONTAPキーキャッシュにリストアされました
Cluster::*> security key-manager external show-status -key-server-status !available
There are no entries matching your query.
Cluster::*> security key-manager key query -node * -restored false
There are no entries matching your query.