ONTAP upgrade image validation fails with encryption key migration status error
Applies to
- ONTAP 9
- Automated non disruptive upgrade (ANDU)
- External Key Manager
Issue
- ONTAP image validation fails with error:
Encryption key migration status: Error
Error: The following data Vservers with external key management enabled have encryption keys managed by the admin Vserver: svm1.
Action: For each data Vserver listed above, migrate the encryption keys from the admin Vserver to the data Vserver using the (privilege: advanced) 'security key-manager key migrate' command.
- Attempting to migrate the keys as per the above action plan fails:
Category: ekmip_server
Status: FAILED
Details: eKMIP Server:
kmip_server:5696, hosted
node: cluster-01, status: unknown,
status-detail: Response status: OPERATION_FAILED.
Reason: AUTHENTICATION_NOT_SUCCESSFUL. Message:
CERT_AUTH_FAILED.
- Expired SSL certificates exist on this SVM per security certificate show output:
SVM1 123456789ABCDEF keyvault.vault.azure.net client
Certificate Authority: keyvault.vault.azure.net
Expiration Date: Fri Nov 15 12:18:57 2024