Error when attempting to create encrypted volume using NetApp Volume Encrpytion (NVE)
Applies to
- ONTAP 9.8
- NetApp Volume Encryption (NVE)
- Thales External Key Manager
- GKLM External key Manager
Issue
- Error when attempting to create an encrypted volume using NetApp Volume Encryption (NVE) and Thales key server:
Reason: Failed to store NVE key with key ID "00000000000000000200000000000500c9b0XXXXXXXXXXXXXXXXXXXXa76008910000000000000000" on external keyserver "10.20.XX.XX:5696". Cryptsoft error: "Response status: OPERATION_FAILED. Reason: GENERAL_FAILURE. Message: DB_GENERAL".
OR
Reason: Failed to store NVE key with key ID "000000000000000002000000000005003ec7XXXXXXXXXXXXXXXXXXXX50705279c0000000000000000" on external key server
"10.20.XX.XX:5696". Cryptsoft error: "Response status: OPERATION_FAILED. Reason: GENERAL_FAILURE. Message:
[NCERRInsufficientPermissions]"
- “crypto_key_stored” and “crypto.key.deleted” events are seen before volume creation failure events:
[Node-1a: svc_queue_thread: crypto_key_stored_1:notice]: params: {'key_id': '00000000000000000200000000000500c9f9aa31c95afc651435d9c7d7cccad40000000000000000', 'key_digest': '3033dd6c85851375878176e127db7169a2885b29f24f166bb760e61c7204a1fa'}
[Node-1a: svc_queue_thread: crypto.key.deleted:notice]: Deleted key with key ID 00000000000000000200000000000500c9f9aa31c95afc651435d9c7d7cccad40000000000000000. Reason src/tables/keymanager_remove_external_key.cc:removeKeyFromCryptomod.
- In the KMIP2_client.log we see:
[kern_kmip2_client:info:7329] [Apr 13 14:16:22]: 0x80940eb00: 0: ERR: kmip2::kmipCmds::KmipCmd: [setStatusReasonAndMessage]:144: Response status: 1(OPERATION_FAILED)
...
[kern_kmip2_client:info:7329] [Apr 13 14:16:22]: 0x80940eb00: 0: ERR: kmip2::tables::kmip_keytable_v2: [create_imp]:717: EXIT: ; Returning Failed to store NVE key with key ID "00000000000000000200000000000500c9b0XXXXXXXXXXXXXXXXXXXXa76008910000000000000000" on external keyserver "10.20.XX.XX:5696". Cryptsoft error: "Response status: OPERATION_FAILED. Reason: GENERAL_FAILURE. Message: DB_GENERAL".