Skip to main content
NetApp Knowledge Base

Volume Encryption Keys (VEKs) report as not restored for non-existent volumes

Views:
197
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
CORE
Last Updated:

Applies to

  • ONTAP 9.7
  • Onboard Key Management (OKM)
  • Upgrade Advisor

Issue

  • When running >> security key-manager key show -restored no, some Volume Encryption Keys (VEKs) are reported as not restored

Cluster::> security key-manager key show -restored no

Node: Cluster-01
Key Store: onboard
Used By
--------
VEK    Key ID: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

  • Performing >> security key-manager onboard sync is successful (no errors) but does not show VEKs as restored
  • All other encryption key types are restored, only VEKs are not
  • This check is sometimes recommended by Upgrade Advisor before performing an ONTAP upgrade
  • ONTAP Upgrade Prechecks do not have any warnings related to encryption
  • VEKs referenced as not restored are not in use by any volume currently on the cluster

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.