ONTAP Upgrade Causes TPM Disablement and Passphrase Failure
Applies to
- AFF/FAS/ASA
- ONTAP 9.16.X
- Onboard Key Manager (OKM) with Self-Encrypting Drives (SED/NSE)
Issue
After upgrading ONTAP from 9.16.1P1 DAR to 9.16.1P8 NODAR image, the following emergency alerts were observed:
[ec2-lon-napp2:statd:callhome.nse.ak.check.failed:EMERGENCY]: Callhome for AuthenticationKeyCheckFailed, disk "0n.1".[ec2-lon-napp1:statd:callhome.nse.ak.check.failed:EMERGENCY]: Callhome for AuthenticationKeyCheckFailed, disk "0n.10".
Attempts to synchronize the Onboard Key Manager (OKM) using the available passphrase failed:
security key-manager onboard syncError: command failed: Cluster-wide passphrase is incorrect.
Further disk encryption modification attempts (setting data-key-id to 0x0) also failed with authentication errors:
ERROR disk.encryptCmdFailed: Encrypting disk 0n.0 failed disk encrypt modify command with error status Could not authenticate with disk. (0xe)
