In VMware vSAN environments configured with Data-at-Rest Encryption using a Standard Key Provider, the vSAN Skyline Health check VMware vCenter and all hosts are connected to Key Management Servers intermittently flaps between Green, Yellow, and Red status. The vSphere Client UI displays the issue Failed to get KMS status.
Reviewing /var/log/vmware/vsan-health/vmware-vsan-health-service.log on the vCenter Server Appliance reveals failures during key attribute lookups followed by health query timeouts:
ERROR vsan-mgmt [VsanVcEncryption::GetKmipKeyAttributes] Error reason: Failed to get key <ECRET> attributes from KMS <IP>:5696, reason: QLC_ERR_NONE
ERROR vsan-mgmt [VsanHealthEncUtil::GetKmipEncryptionKeyExpirationInfo] GetKmipKeyAttributes failed, please check you pass correct keyId and attribute names
INFO vsan-mgmt [VsanHealthEncUtil::GetClusterEncryptionConfig] RetrieveKmipServers result: running, Timed out
WARNING vsan-mgmt [VsanHealthEncUtil::_AggregateEncryptionConfigHealth] Host: HOSTNAMEVMware vSAN (All Versions)
KMS
This issue occurs when vCenter attempts to retrieve key attributes from one or more unreachable or unresponsive KMS provider endpoints. Because vCenter performs individual attribute queries against each configured KMS IP, an unresponsive node causes the health polling thread to exceed the default 15-second execution window, triggering a timeout alarm across the cluster.
nc -z -v -w 5 <KMS_IP> 5696vmon-cli -r vsan-healthvSAN Health Alarm - vCenter and all hosts are connected to Key Management Servers
For general KMIP port requirements, see VMware Ports and Protocols.
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.