使用默认制造商安全 ID 时 SED 数据密钥分配失败,出现错误 0xe
适用于
- ONTAP 9.x
- 板载密钥管理器 (OKM)
问题描述
- 客户丢失密码短语且无法执行
security key-manager onboard sync - 按照 如何在使用 ONTAP 板载加密和 NVE 时从丢失的密码短语恢复 磁盘不会从"data"变为"open"
- 运行
storage encryption disk show命令显示"0x0"
::> storage encryption disk show -fields disk,fips-key-id
disk fips-key-id
------ --------------
1.0.0 0x0
1.0.1 0x0
1.0.2 0x0
1.0.3 0x0
1.0.4 0x0
1.0.19 0x0
1.0.20 0x0
1.0.21 0x0
1.0.22 0x0
1.0.23 0x0
10 entries were displayed.
- 但
storage encryption disk show您 仍然会看到"data"而不是"open"
::*> storage encryption disk show
Disk Mode Data Key ID
-------- ---- ----------------------------------------------------------------
1.0.0 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.1 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.2 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.3 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.4 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.19 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.20 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.21 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.22 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
1.0.23 data 000000000000000002000000000001000FC0A4132E37E3777B854E578823E6D8
10 entries were displayed.
- EMS 日志显示如下
storage encryption disk modify -data-key-id 0x0 -disk *
8/12/2025 15:20:16 AK-01 ERROR disk.encryptCmdFailed: Encrypting disk 0n.22 failed disk encrypt modify command with error status Could not authenticate with disk. (0xe).
8/12/2025 15:23:00 AK-01 ERROR nse.op.failed: Control failure on self-encrypting drive 0n.19; security provider: Locking, authority: User1, during operation "opal_change_user1_pin_sm".