Certificate error while adding KMIP server
Applies to
- ONTAP 9
- External Key Management (EKM)
- Key Management Interoperability Protocol (KMIP)
- Certificate
Issue
- A newly added KMIP server is in an
unknown
state and the status detail shows "SSL_PEER_VALIDATION
"
Cluster::> security key-manager external show-status
Node Vserver Primary Key Server Status
---- ------- ------------------------------------------------- ------------
Node-01
Vserver-1
10.XX.XX.11:6001 unknown
Status Details: SSL_PEER_VALIDATION
Node-02
Vserver-1
10.XX.XX.11:6001 unknown
Status Details: SSL_PEER_VALIDATION
- Getting the below error when we try re-adding the KMIP server:
Error: command failed: The following issues were found: Unable to establish secure connection to KMIP server "10.35.17.11". Verify correct server-ca certificate has been installed for the specified KMIP server.