Unable to Use AWS KMS (SSE-KMS) Encryption for On-Prem ONTAP Backups to S3
Applies to
- NetApp Backup & Recovery
- On-premises ONTAP backup to AWS S3
- Amazon Web Services (AWS)
- KMS
Issue
- When configuringBackup & Recovery for on-premises ONTAP to back up data to AWS S3, attempts to use customer-managed AWS KMS keys (SSE-KMS) for server-side encryption fail.
- Even when the S3 bucket is created with KMS encryption, the backup objects are stored using the default SSE-S3 encryption instead of SSE-KMS. The Backup Dashboard UI does not allow changing the encryption type for existing buckets, and the destination bucket option is grayed out during backup configuration.
- Objects in the S3 bucket are encrypted with SSE-S3, not SSE-KMS, even though bucket policy and creation used KMS keys.
- Attempting to block SSE-S3 uploads with an explicet IAM policy causes backup jobs to fail.
- User cannot select KMS encryption in the NetApp Console UI for existing buckets.
