How to protect FIPS or SED drives from authentication lock out while troubleshooting KMIP reachability issues
Applies to
- ONTAP 9
- NetApp Storage Encryption (NSE)
- FIPS Drives
- SED Drives
- KMIP Servers
- External Key Manager
Description
- All ONTAP versions with fix for Bug 812801 will return to the LOADER prompt when KMIP servers are unreachable
- This is to avoid the 1024 "Try Limit" for authentication attempts applied to FIPS and SED drives
- The try limit is reset once the KMIP server is reached and authentication for the drive is successful
- Power cycling the drive does not reset the tries count as the Persistence setting is true for these drives
- If that limit is reached the drive will no longer be usable and all data will be lost
- If an HA pair has failed to power on because of KMIP server reachability and both nodes are at the LOADER prompt, follow the steps below to troubleshoot connectivity without incrementing the drive tries count
