VEK key remains cached on node after NVE is deleted and removed from external key server
Applies to
- ONTAP 9
- External key server
- NetApp Volume Encryption (NVE)
Issue
- After deleting an NVE volume, the key-id for the deleted volume remains cached on the node:
Cluster::> security key-manager key query -restored false Node: cluster-01 Vserver: svm_cluster Key Manager: 10.XX.XX.XX:5696 Key Manager Type: KMIP
Key Tag Key Type Restored------------------------------------ -------- --------c9541486-4cc8-11ec-9221-00a0985b948b VEK false Key ID: 000000000000000002000000000005001b8ca4b682e533dfc5cfc5a77acb28c40000000000000000
- The following error is reported when an attempt is made to restore the key:
::> security key-manager external restore
Warning: Unable to list entries on node cluster-01. KMIP "Get" command failed on external key server "10.XX.XX.XX:5696". Cryptsoft error: "Response status: OPERATION_FAILED. Reason: ITEM_NOT_FOUND. Message: No Cryptographic Object found with given Unique Identifier".
