ONTAP Upgrade Advisor Plan: Validate encryption keys are in sync for all nodes
Applies to
- ONTAP 9
- NetApp Volume Encryption (NVE)
- Onboard Key Manager (OKM)
- ONTAP Upgrade Advisor
Issue
ONTAP Upgrade Advisor Plan gets the following warning in the pre-check section:
If nodes have been added to an NVE cluster it is possible that security key-manager setup (pre-ONTAP 9.6) or security key-manager onboard enable (ONTAP 9.6 and later) were not run and the encryption keys are not in sync. To prevent issues on upgrade, validate whether encryption keys are in sync for all nodes. This can be done via running the command
CLUSTER::*>security key-manager key show -restored no