vSAN OSA cluster is reporting: Skyline health error vSAN cluster configuration Consistency: Data is encrypted with an out of date Data Encryption Key
search cancel

vSAN OSA cluster is reporting: Skyline health error vSAN cluster configuration Consistency: Data is encrypted with an out of date Data Encryption Key

book

Article ID: 410102

calendar_today

Updated On:

Products

VMware vSAN

Issue/Introduction

vSAN health reports a vSAN cluster configuration consistency issue "Data is encrypted with an out of date Data Encryption Key", as seen in the below screenshot. 

 

Environment

VMware vSAN (all versions) 

Cause

"Data is encrypted with an out-of-date Data Encryption Key" is an error message indicating a discrepancy between the encryption key stored on a system and the actual encryption keys used to protect data, often occurring after upgrades, key management issues, or configuration changes. 

Resolution

Please reach out to your KMS vendor/team to see if they can assist in correcting any issues with the current key before attempting remediation.  If your KMS vendor / team  is not able to allow the out of date key for use, Click "Remediate inconsistent configuration" button to run the cluster configuration remediation action to fix hosts and disks which have inconsistent configurations.

Caution should be taken when remediating the inconsistency as this action has potential to initiate a deep rekey which will cause a large amount of data resync and this can have a negative impact on the performance of the cluster.

If the "Remediate inconsistent configuration" Fails or to investigate this issue please open a case with VMware Support for further investigation.