ONTAP 9 giveback operation was vetoed by keymanager
Applies to
- ONTAP 9
- Onboard Key Manager (OKM)
- NetApp Volume Encryption (NVE)
- NetApp Storage Encryption (NSE)
- Giveback operation
- NDU pause operation
Issue
-
Storage failover show-giveback
command indicates the giveback is vetoed due to keymanager
::*> storage failover show-giveback
Partner
Node Aggregate Giveback Status
-------------- ----------------- ---------------------------------------------
<node1>
CFO Aggregates Done
aggr1
Failed: Operation was vetoed by keymanager.
Check the event log
- Event log show may have gb.sfo.veto.kmgr.keymissing errors
::*> event log show -node * -event gb*
Time Node Severity Event
------------------- ---------------- ------------- ---------------------------
<Time> <node> ERROR gb.sfo.veto.kmgr.keysmissing: Giveback of aggregate aggr1 failed due to unavailability of volume encryption keys for the encrypted volumes of the aggregate on the partner node
ALERT crypto.import.failed: ERROR: Import of key with key ID <key> failed. Additional information: wrapping key not found.
ALERT sfo.sendhome.subsystemAbort: The giveback operation of '<aggr>' was aborted by 'keymanager'
Security key-manager key show -detail
may have NSE-AK keys that are not restored