ONTAP upgrade image validation fails with encryption key migration status error
Applies to
- ONTAP 9
- Automated non disruptive upgrade (ANDU)
- External Key Manager
Issue
- ONTAP image validation fails with error:
Encryption key migration status: ErrorError: The following data Vservers with external key management enabled have encryption keys managed by the admin Vserver: svm1.Action: For each data Vserver listed above, migrate the encryption keys from the admin Vserver to the data Vserver using the (privilege: advanced) 'security key-manager key migrate' command.- Attempting to migrate the keys as per the above action plan fails:
Category: ekmip_server Status: FAILED Details: eKMIP Server: kmip_server:5696, hosted node: cluster-01, status: unknown, status-detail: Response status: OPERATION_FAILED. Reason: AUTHENTICATION_NOT_SUCCESSFUL. Message: CERT_AUTH_FAILED.- Expired SSL certificates exist on this SVM per security certificate show output:
SVM1 123456789ABCDEF keyvault.vault.azure.net client Certificate Authority: keyvault.vault.azure.net Expiration Date: Fri Nov 15 12:18:57 2024