Where are NVE and NAE encryption keys stored?
Applies to
- ONTAP 9
- NetApp Volume Encryption (NVE)
- NetApp Aggregate Encryption (NAE)
Answer
- With the onboard key manager, data volume encryption keys and aggregate keys are stored in the WAFL metadata, which is not accessible by the user, and the volume location database (VLDB).
- With an external key manager, data volume encryption keys and aggregate keys are stored directly on the KMIP server.
Additional Information
FAQ: NetApp Volume Encryption and NetApp Aggregate Encryption