Onboard keys not found after boot device replacement
Applies to
- ONTAP 9
- Onboard Key Management (OKM)
- NetApp Volume Encryption (NVE)
- Automated Non-Disruptive Upgrade (ANDU)
- Trusted Platform Module (TPM)
Issue
- The import of onboard keys fails on a node and the following events are reported:
[Node-01: sysinit_thread: crypto.okmrecovery.failed:alert]: Import of the Onboard Key Manager (OKM) hierarchy has failed: no onboard keys found. Additional information: Onboard keys not found.
[Node-01: svc_queue_thread: crypto.debug:info]: import_wrapped_key: crypto_import_onboard_key_hierarchy failed: 13.
- All the encryption keys are restored on the node:
::> security key-manager key query -restored false
There are no entries matching your query.
- During ANDU/node reboot, the giveback of the node is vetoed due to the unavailability of encryption keys:
[Node-02: cf_giveback: gb.sfo.veto.kmgr.keysmissing:error]: Giveback of aggregate "N01_aggr1" failed due to the unavailability of the volume encryption keys for the encrypted volumes of the aggregate on partner node "xir-pcstdot-06".
[Node-02: cf_giveback: sfo.sendhome.subsystemAbort:alert]: The giveback operation of 'N01_aggr1' was aborted by 'keymanager'.