External key restore fails with error "Cipher engine is not initialized"
Applies to
- ONTAP 9
- External KMIP
- GKLM
Issue
- External key restore fails with error "Cipher engine is not initialized"
Cluster::*> security key-manager external restore -vserver svm1 -key-id 00000000000000000200000000000500096e2dad923fffb93bed463axxxxxxxxxxx0000000000000
Warning: Unable to list entries on node nodeA. KMIP "Get" command
failed on external key server "10.xxx.xxx.xxx:5696". Cryptsoft error:
"Response status: OPERATION_FAILED. Reason: GENERAL_FAILURE. Message:
CYYYYXXXXE Failed to decrypt data using the master key. Rerun the
master key management or master key for device group management
operation. Failure Reason : Cipher engine is not initialized.".
- Same error message seen in kmip2_clinet.log
Cluster::*> systemshell local sudo tail -f /mroot/etc/mlog/kmip2_client.log
(system node systemshell)
00000024.0001b5d2 00019ed8 Thu Dec 12 2024 17:57:11 +00:00 [kern_kmip2_client:info:12845] [Dec 12 17:57:11]: 0x80a208f00: 0: ERR: kmip2::tables::kmip_keytable_v2: [populateFields]:2011: Get command failed. Exception: KmipGetException: Response status: OPERATION_FAILED. Reason: GENERAL_FAILURE. Message: CYYYYXXXXE Failed to decrypt data using the master key. Rerun the master key management or master key for device group management operation. Failure Reason : Cipher engine is not initialized.
00000024.0001b5d5 00019ed9 Thu Dec 12 2024 17:57:12 +00:00 [kern_kmip2_client:info:12845] [Dec 12 17:57:12]: 0x80a206500: 0: WARNING: kmip2::kmipCmds::KmipConnection: [cryptsoftErrorCb]:99: Warning: src/kmipObjects/KmipSymmetricKey.cc: 212: error: 11: msg: KMIP_DATA_LIST_get_data KEY_MATERIAL