CONTAP-211443: Volume rehost from Cloud key-manager enabled vserver to vserver with no key-manager configured can lead to encrypted volumes becoming inaccessible and potentially unrecoverable
Issue
In a situation where 'volume rehost' is attempted
- from a Cloud key manager enabled vserver.
- to a vserver with no key manager.
- no key-manager configured in the admin vserver.
Will result in the cloud keystore being in a mixed state
- Vserver encryption will be in a state where encrypted volumes cannot be created, deleted or moved.
In this state, the cloud key manager SHOULD NOT be disabled.
Doing so would lead to
- the SVM-KEK being deleted.
- all encrypted volumes associated with the vserver becoming inaccessible after a subsequent node reboot.