启动设备更换后未找到板载密钥
适用于
- ONTAP 9
- 板载密钥管理 (OKM)
- NetApp 卷加密 (NetApp Volume Encryption, NVE)
- 自动无中断升级(ANDU)
- 受信任的平台模块 (TPM)
问题描述
- 在节点上导入板载密钥失败,并报告以下事件:
[Node-01: sysinit_thread: crypto.okmrecovery.failed:alert]: Import of the Onboard Key Manager (OKM) hierarchy has failed: no onboard keys found. Additional information: Onboard keys not found.
[Node-01: svc_queue_thread: crypto.debug:info]: import_wrapped_key: crypto_import_onboard_key_hierarchy failed: 13.
- 所有加密密钥都已在节点上还原:
::> security key-manager key query -restored false
There are no entries matching your query.
- 在 ANDU/节点重新启动期间,由于加密密钥不可用,节点的交还被否决:
[Node-02: cf_giveback: gb.sfo.veto.kmgr.keysmissing:error]: Giveback of aggregate "N01_aggr1" failed due to the unavailability of the volume encryption keys for the encrypted volumes of the aggregate on partner node "xir-pcstdot-06".
[Node-02: cf_giveback: sfo.sendhome.subsystemAbort:alert]: The giveback operation of 'N01_aggr1' was aborted by 'keymanager'.