Cannot unlock FIPS drives due to communication issues with the key manager
Applies to
- ONTAP 9.1P20
- Gemalto SafeNet KeySecure
Issue
Cannot unlock NSE drives, the following is observed in EMS messages:
Thu Jul 21 08:17:23 EDT [cluster-01: scsi_cmdblk_strthr_admin: disk.encryptCmdFailed:error]: Encrypting disk 0a.10.6 failed disk encrypt modify command with error status Could not authenticate with disk. (0xe).
We also see that the key servers are not responding:
::> key-manager show -status
(security key-manager show)
Node Registered Key Manager Status
---------------------- --------------------------- ---------------
cluster-01 x.x.x.x not-responding