Skip to main content
NetApp Knowledge Base

How to protect FIPS or SED drives from authentication lock out while troubleshooting KMIP reachability issues

Views:
119
Visibility:
Public
Votes:
0
Category:
not set
Specialty:
not set
Last Updated:

Applies to

  • ONTAP 9
  • NetApp Storage Encryption (NSE)
  • FIPS Drives
  • SED Drives
  • KMIP Servers
  • External Key Manager

Description

  • All ONTAP versions with fix for Bug 812801 will return to the LOADER prompt when KMIP servers are unreachable
  • This is to avoid the 1024 "Try Limit" for authentication attempts applied to FIPS and SED drives
  • The try limit is reset once the KMIP server is reached and authentication for the drive is successful
  • Power cycling the drive does not reset the tries count as the Persistence setting is true for these drives
  • If that limit is reached the drive will no longer be usable and all data will be lost
  • If an HA pair has failed to power on because of KMIP server reachability and both nodes are at the LOADER prompt, follow the steps below to troubleshoot connectivity without incrementing the drive tries count

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.