LINUXOR.SK ... open source notes ...

NetApp - ONTAP Onboard Key Manager and volume encryption (NVE)

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Encryption and certificates

noteThe passphrase is a placeholder. The output of security key-manager backup show is key material: it is described in the Article and must never be pasted into a document like this one.

The commands that enable the Onboard Key Manager on both clusters of a MetroCluster and encrypt existing data volumes by moving them within their aggregate.

ItemValue
Runs oncluster shell of DC1-A-XNAS001 and DC1-B-XNAS001, as admin
Shown heresite 1, volumes DC1_S_VCVSM001_data and DC1_S_VCVSM002_data
Also applied toDC1_S_VCVSM005_data, DC1_S_VCVSM006_data and the four data volumes of site 2, by the design; the notes hold no commands for them
Licenceve on every node
ONTAP version at the time9.1P8

The command set

bash
# 0. On each cluster: check that the build contains volume encryption.
#    "1no-DARE" in the output would mean that it does not.
version -v

# 1. On DC1-A-XNAS001: start the key manager wizard, answer "yes" and enter
#    the cluster-wide passphrase twice: <KEY_MANAGER_PASSPHRASE>
security key-manager setup

# 2. On DC1-B-XNAS001: the same wizard with the SAME passphrase
security key-manager setup

# 3. On each cluster: verify that keys exist for both nodes
#    (two key IDs per node, key store "onboard")
security key-manager key show

# 4. Copy the passphrase to a secure location outside the storage system

# 5. Display the key manager backup and copy it to a secure location outside
#    the storage system. Site 1 notes: on DC1-A-XNAS001 only.
#    Site 2 notes: on DC2-A-XNAS001 and on DC2-B-XNAS001.
security key-manager backup show

# 6. Encrypt an existing volume: find its aggregate, move the volume onto the
#    same aggregate with encryption of the destination, watch the progress,
#    verify
volume show -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -field aggregate
volume move start -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -destination-aggregate DC1_A_ANAS002_data1 -encrypt-destination true
volume move show -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -field percent-complete
volume show -vserver DC1-S-VCVSM001 -volume DC1_S_VCVSM001_data -field is-encrypted

# 7. The same for the KVM volume. The first attempt failed with "There is
#    2.77TB of available space on the aggregate DC1_A_ANAS001_data1 which is
#    not enough to accommodate a volume"; disks were added to the aggregate
#    and the command repeated.
volume show -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -field aggregate
volume move start -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -destination-aggregate DC1_A_ANAS001_data1 -encrypt-destination true
volume move show -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -field percent-complete
volume show -vserver DC1-S-VCVSM002 -volume DC1_S_VCVSM002_data -field is-encrypted

The notes do not contain the installation of the ve licence, and nothing for a restore of the key manager from the backup; a restore was never exercised.

Checked against ONTAP 9.19.1

As builtToday
security key-manager setup on cluster A, then on cluster B with the same passphraseReplaced in ONTAP 9.6 by security key-manager onboard enable on the first cluster and security key-manager onboard sync on the MetroCluster partner with the same passphrase. setup is marked deprecated in the 9.16.1 command reference and absent from 9.17.1 on
security key-manager key showDeprecated in favour of security key-manager key query; absent from the command reference from 9.13.1 on
security key-manager backup showDeprecated in favour of security key-manager onboard show-backup; absent from the command reference from 9.13.1 on
volume move start … -encrypt-destination true onto the same aggregateStill valid, on the same or another aggregate
not used: in-place conversionvolume encryption conversion start encrypts an existing volume without moving it and is the first method the documentation lists. Whether it avoids the free-space requirement that stopped the move in 2017 was not checked
not used: encrypted from creationvolume create -encrypt true

What the notes did, the wizard on both clusters with one passphrase, matches the documented rule for releases before 9.6. A runbook written from this command set fails on a current release at the first command. The check for 1no-DARE in version -v was not verified again.

← solutionz