Disk encrypted and locked due to the encryption key is not available
search cancel

Disk encrypted and locked due to the encryption key is not available

book

Article ID: 411168

calendar_today

Updated On:

Products

VMware vSAN

Issue/Introduction

After moving vSAN to a new KMS provider or a Native Key Provider (NKP) there are alarms in vSAN health for keys not available. This can also be seen after an upgrade to the key provider. 

Environment

vSAN with Data at Rest Encryption (All versions) 

Cause

During the key provider change a shallow rekey was not performed on the vSAN cluster. This is causing the new key provider to not have the expected keys. 

Resolution

Do not reboot or make any changes to the disk groups in this condition. Follow the below steps:

  1. Manually perform a shallow rekey to generate new KEK keys from the new key provider on the vSAN cluster by following the steps in Generate New Encryption Keys

  2. Confirm the alarms relate to "encryption keys not available" are no longer triggered in the vSAN health check. 

Additional Information

How to move vSAN encryption to Native Key Provider (NKP)

Troubleshooting vSAN Encryption