One or more nodes have onboard key management VEK keys that need to be restored
Applies to
- ONTAP 9 (Upgrades)
- Onboard Key Manager (OKM)
- NetApp Volume Encryption (NVE)
- NetApp Aggregate Encryption (NAE)
- Volume Encryption Key (VEK)
Issue
- Command
security key-manager key query
shows that some of the VEK keys are not restored:
Key Tag Key Type Restored
------------- --------- --------
Key ID: <key> VEK false
- Command
security key-manager key show
(deprecated in ONTAP 9.6) shows the following error:
Error: One or more nodes have onboard key management keys that need to be restored. Run the "security key-manager onboard sync" command to restore the onboard key hierarchy on those nodes.
- The error is reported despite trying to restore the key using
security key-manager onboard sync
.