In a vSAN environment utilizing Data-at-Rest Encryption, the Skyline Health check reports a red status for vCenter and all hosts are connected to Key Management Servers.
WARNING vsan-mgmt [VsanHealthEncUtil::_AggregateEncryptionConfigHealth] Key state {'<UUID>': 'KeyStateMissingInKMS'} is redERROR [VsanVcEncryption::GetKmipKeyAttributes] Error reason: Server Error:General Failure, Explanation:[NCERRResourceNotFound: Resource not found]This issue occurs when the Key Encryption Key (KEK) IDs registered in the vCenter/vSAN configuration no longer exist in the active Key Management Server (KMS) vault.
This is typically seen after:
If all vSAN disk groups remain mounted and operational (meaning the Disk Encryption Keys are still in the host memory), you can resolve the health alarm by generating a new KEK.
Note: A Shallow Rekey generates a new KEK on the active KMS server and re-wraps the existing Disk Encryption Keys (DEKs) without re-encrypting the data on disk, making it a non-disruptive operation.
For further troubleshooting of KMS connectivity, see Troubleshooting vSAN Encryption - KMS
To speak with a customer representative or a Support Engineer, Scroll to the bottom of the page and click on your respective region.