跳转到主内容

板载密钥管理器密钥在 MetroCluster 中的集群之间不匹配

Views:
290
Visibility:
Public
Votes:
0
Category:
metrocluster
Specialty:
metrocluster
Last Updated:

适用于

  • ONTAP 9
  • MetroCluster
  • 板载密钥管理器 (OKM)
  • NetApp Volume Encryption (NVE)

问题

  • 在 MetroCluster 系统上升级 ONTAP 后,MetroCluster 运行状况报告为已降级:

::> system health subsystem  show
Subsystem         Health
----------------- ------------------
SAS-connect       ok
Environment       ok
Memory            ok
Service-Processor ok
Switch-Health     ok
CIFS-NDO          ok
Motherboard       ok
IO                ok
MetroCluster     degraded
MetroCluster_Node ok
FHM-Switch        ok
FHM-Bridge        ok
SAS-connect_Cluster ok
13 entries were displayed.

  • 在 MetroCluster 检查或切换模拟期间报告以下错误:

::> metrocluster operation show
Operation: switchover-simulate
State: failed
Errors: Failed to validate the node and cluster components before the switchover operation.
node1 (overridable veto): Internal Error. The "clus_salt" value in the Onboard Key Manager database was not properly updated

 Type of Check: onboard-key-management
                         Cluster Name: Cluster1
                  Result of the Check: warning
Additional Information/Recovery Steps: Internal Error. The "clus_salt" value in the Onboard Key Manager database was not properly updated.

  • 从以下命令的输出中,可以观察到集群之间的 SVM-KEK 和 NSE-AK 密钥匹配:

::> security key-manager key show -used-by SVM-KEK,NSE-AK

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.