External Key Manager in unknown state with SSL peer validation errors
Applies to
- ONTAP 9
- External Key Management (EKM)
- Key Management Interoperability Protocol (KMIP)
Issue
- External key managers report "Unknown" status with the SSL_PEER_VALIDATION errors:
::*> security key-manager external show-status
Node Vserver Key Server
Status
---- ------- ------------------------------------------- ---------------
cluster-1a
SVM1
x.x.x.x:5696 unknown
Status Details: SSL_PEER_VALIDATION
- Volume creations will fail with the following error:
cluster1::> volume create -vserver svm1 -size 1G -volume vol1 -state online -aggregate aggr1_cluster1b
Error: command failed: One or more key servers are unavailable for Vserver "cluster1". Use the "security key-manager external show-status -vserver cluster1" command to check the status of the key servers. Verify that the network configuration is correct.