メインコンテンツまでスキップ

ONTAPクラスタの拡張後にOKMキーがリストアされない

環境

  • ONTAP 9
  • オンボードキーマネージャ(OKM)
  • NetApp Storage Encryption(NSE)
  • NetApp Volume Encryption(NVE)

問題

クラスタに新しいノードを追加すると、次のような状況が発生することがあります。

  • security key-manager key show コマンドで次のエラーが報告されます。
Error: One or more nodes have onboard key management keys that need to be restored. Run the "security key-manager onboard sync" command to restore the onboard key hierarchy on those nodes.
  •  disk encrypt modifyコマンドの失敗とEMSレポート:

[node01: disk_admin: disk.encryptCmdFailed:error]: Encrypting disk <disk> failed disk encrypt modify command with error status Authentication key not found. (0xe).

  • アグリゲートの作成が次のエラーで失敗します。

Failed to create aggregate "aggr_name" on "Node-01". Reason: Cannot generate encryption key. If using an external key manager, use the 'security key-manager external show-status' command to verify that the network configuration is correct and the key servers are reachable. If using the Onboard Key Manager, use the 'security key-manager key query -key-type SVM-KEK' command to verify that the same SVM-KEKs are present on both the local and remote clusters.

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.