vCenter VSAN Skyline Health KMS key state Red, Host KMS status, ESXi key status Red
search cancel

vCenter VSAN Skyline Health KMS key state Red, Host KMS status, ESXi key status Red

book

Article ID: 450624

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • Added new key provider-Connection between KMS and vCenter healthy.

  • KMS in a remote site from vCenter.
  • Re-encrypted VSAN DataStore.

  • Generated new Host Keys.

VSAN Skyline Health KMS errors:

  • KMS Key State Red.

  • Host KMS Status:

    • ESX Key Status Red.

  • No KMS, Cipher or TLS errors in ESX host /var/log/hostd/log or /var/log/vmkernel.log.

Passes Encryption testing and Re-Key.

 

Environment

ESX

Cause

False positive. Check for a latent connection between remote KMS site and local vCenter site.

Resolution

Continue to monitor. Re-check VSAN encryption, Re-Key and check for latent connection between remote KMS and vCenter.

 

Additional Information

Guidance for resolving vSAN encryption failures. Symptoms include the inability to configure encryption, encrypted disks failing to mount, and vSAN health warnings regarding KMS configuration.