NetApp - ONTAP Onboard Key Manager and volume encryption (NVE)
NetApp Solution · Config document · referenced from Encryption and certificates
noteThe passphrase is a placeholder. The output of
security key-manager backup show is key material: it is described in the Article and must never be pasted into a document like this one.The commands that enable the Onboard Key Manager on both clusters of a MetroCluster and encrypt existing data volumes by moving them within their aggregate.
| Item | Value |
|---|---|
| Runs on | cluster shell of DC1-A-XNAS001 and DC1-B-XNAS001, as admin |
| Shown here | site 1, volumes DC1_S_VCVSM001_data and DC1_S_VCVSM002_data |
| Also applied to | DC1_S_VCVSM005_data, DC1_S_VCVSM006_data and the four data volumes of site 2, by the design; the notes hold no commands for them |
| Licence | ve on every node |
| ONTAP version at the time | 9.1P8 |
The command set
# 0. On each cluster: check that the build contains volume encryption. # "1no-DARE" in the output would mean that it does not. version -v # 1. On DC1-A-XNAS001: start the key manager wizard, answer "yes" and enter # the cluster-wide passphrase twice: <KEY_MANAGER_PASSPHRASE> security key-manager setup # 2. On DC1-B-XNAS001: the same wizard with the SAME passphrase security key-manager setup # 3. On each cluster: verify that keys exist for both nodes # (two key IDs per node, key store "onboard") security key-manager key show # 4. Copy the passphrase to a secure location outside the storage system # 5. Display the key manager backup and copy it to a secure location outside # the storage system. Site 1 notes: on DC1-A-XNAS001 only. # Site 2 notes: on DC2-A-XNAS001 and on DC2-B-XNAS001. security key-manager backup show # 6. Encrypt an existing volume: find its aggregate, move the volume onto the # same aggregate with encryption of the destination, watch the progress, # verify volume show -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -field aggregate volume move start -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -destination-aggregate DC1_A_ANAS002_data1 -encrypt-destination true volume move show -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -field percent-complete volume show -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -field is-encrypted # 7. The same for the KVM volume. The first attempt failed with "There is # 2.77TB of available space on the aggregate DC1_A_ANAS001_data1 which is # not enough to accommodate a volume"; disks were added to the aggregate # and the command repeated. volume show -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -field aggregate volume move start -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -destination-aggregate DC1_A_ANAS001_data1 -encrypt-destination true volume move show -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -field percent-complete volume show -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -field is-encrypted
The notes do not contain the installation of the ve licence, and nothing for a restore of the key manager from the backup; a restore was never exercised.
Checked against ONTAP 9.19.1
| As built | Today |
|---|---|
security key-manager setup on cluster A, then on cluster B with the same passphrase | Replaced in ONTAP 9.6 by security key-manager onboard enable on the first cluster and security key-manager onboard sync on the MetroCluster partner with the same passphrase. setup is marked deprecated in the 9.16.1 command reference and absent from 9.17.1 on |
security key-manager key show | Deprecated in favour of security key-manager key query; absent from the command reference from 9.13.1 on |
security key-manager backup show | Deprecated in favour of security key-manager onboard show-backup; absent from the command reference from 9.13.1 on |
volume move start … -encrypt-destination true onto the same aggregate | Still valid, on the same or another aggregate |
| not used: in-place conversion | volume encryption conversion start encrypts an existing volume without moving it and is the first method the documentation lists. Whether it avoids the free-space requirement that stopped the move in 2017 was not checked |
| not used: encrypted from creation | volume create -encrypt true |
What the notes did, the wizard on both clusters with one passphrase, matches the documented rule for releases before 9.6. A runbook written from this command set fails on a current release at the first command. The check for 1no-DARE in version -v was not verified again.