After rebuilding an ESA vSAN cluster in SDDC while keeping the ESXi instances, an object could not be deleted
vSAN 9.1
The previous vSAN instance prior to rebuild was encrypted and the new vSAN was not - leading to encryption errors when attempting to delete the object. The vmkernel.log contains entries similar to those below:
YYY-MM-DDT18:35:12.825Z -INFO vmkernel - [esx@4413] cpu96:2110503)DOM: DOMOwnerGetEncrCtxFromExtAttr:4576: ########-####-####-####-############: Fetched encrCtx from extAttr with encrActiveKey:0, encrEnabled:1, encrCompliant:1, encrGenNum:0, encrPersisted:1, encrPerObjKey: 1
YYY-MM-DDT18:35:12.825Z -INFO vmkernel - [esx@4413] cpu96:2110503)DOM: DOMOwnerCreateCipherHandle:5499: DOM Owner ########-####-####-####-############ DEK ID cached as (null), index 0, isEnable: 1, genNum: 0
YYY-MM-DDT18:35:12.825Z -INFO vmkernel - [esx@4413] cpu96:2110503)DOM: DOMOwnerLogEncrContext:5188: obj ########-####-####-####-############ host ########-####-####-####-############
YYY-MM-DDT18:35:12.825Z -INFO vmkernel - [esx@4413] cpu96:2110503)DOM: DOMOwnerLogEncrContext:5191: owner setup: latest generation.: obj ########-####-####-####-############ G:0 C:1 E:1 A:0 P:1 OK:1 MK:1 LLP:1
YYY-MM-DDT18:35:12.825Z -INFO vmkernel - [esx@4413] cpu96:2110503)DOM: DOMOwnerCryptoSetup:7176: ########-####-####-####-############: If encryption is enabled, one of the data and metadata cipher handle must be valid, active cipher idx 0
YYY-MM-DDT18:35:12.825Z -INFO vmkernel - [esx@4413] cpu96:2110503)DOM: DOMOwnerUnsubscribeClusterEncrState:6706: DOM Owner on ########-####-####-####-############ received premature cluster encryption state unsubscription
Encrypted the new vSAN instance and then the object could be deleted
vSAN was part of an SDDC instance