ONTAP 升级导致 TPM 禁用和密码短语失败
适用于
- AFF/FAS/ASA
- ONTAP 9
- 带有自加密驱动器/NetApp 存储加密 (SED/NSE) 的板载密钥管理器 (OKM)
- 受信任的平台模块 (TPM)
问题描述
- 将 ONTAP 从 9.16.1P1 DAR 升级到 9.16.1P8 NODAR 映像后,将生成以下紧急警报:
[cluster-01:statd:callhome.nse.ak.check.failed:EMERGENCY]: Callhome for AuthenticationKeyCheckFailed, disk "0n.1".[cluster-02:statd:callhome.nse.ak.check.failed:EMERGENCY]: Callhome for AuthenticationKeyCheckFailed, disk "0n.10".
- 尝试使用可用密码短语同步板载密钥管理器 (OKM) 失败:
::> security key-manager onboard syncError: command failed: Cluster-wide passphrase is incorrect.
- 进一步的磁盘加密修改尝试(将 data-key-id 设置为 0x0)也会失败,并出现身份验证错误:
ERROR disk.encryptCmdFailed: Encrypting disk 0n.0 failed disk encrypt modify command with error status Could not authenticate with disk. (0xe)