Cryptsoft error: "I/O Error" when enabling external key manager
Applies to
- ONTAP 9
- External Key Manager (EKM)
- Secure Sockets Layer (SSL)
Issue
- The following error is given when enabling an EKM on the cluster:
Cluster1::> security key-manager external enable -key-servers 192.168.x.x:5696 -client-cert clientcert -server-ca-certs CipherTrustRootCA
Warning: Unable to establish secure connection to KMIP server "192.168.x.x". Cryptsoft error: "I/O Error".
- Using the openssl commands outlined in this KB, ONTAP advised that there was an issue on line 13 of the SSL configuration file:
34370560688:error:0E065068:configuration file routines:STR_COPY:variable has no value:conf_def.c:592:line 13