How does ONTAP behave when the external key manager is not accessible?
Applies to
- ONTAP 9
- NetApp Volume Encryption (NVE)
- NetApp Aggregate Encryption (NAE)
Answer
- When ONTAP is booting:
- NVE system: encrypted volumes remain offline
- NSE system: ONTAP will refuse to boot, see the ONTAP Documentation for Encryption
- When creating a key:
- The key is not created
- When running the following commands:
security key-manager query
command: key IDs are shown if cache is filled
security key-manager restore
command: command will fail
security key-manager show -status
command: command will show unavailable
Additional Information
FAQ: NetApp Volume Encryption and NetApp Aggregate Encryption