![]() | Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition | ||
|
|
![]() |
||||||||||||||||
Solution Type Problem Resolution Sure Solution 2404597.1 : Oracle ZFS Storage Appliance: Unable to Use Keys From OKM to create new shares or replications.
ZFS Array is unable to retrieve keys from OKM either during replication or share creation in a encrypted project. The error below is returned: "The action could not be completed because the specified encryption key is not in a useable state" In this Document
Created from <SR 3-17568953891> Applies to:Oracle ZFS Storage Appliance Racked System ZS5-4 - Version All Versions to All Versions [Release All Releases]Oracle ZFS Storage ZS5-4 - Version All Versions to All Versions [Release All Releases] Oracle ZFS Storage ZS3-2 - Version All Versions to All Versions [Release All Releases] Oracle ZFS Storage ZS4-4 - Version All Versions to All Versions [Release All Releases] Sun ZFS Storage 7420 - Version All Versions to All Versions [Release All Releases] 7000 Appliance OS (Fishworks) Share or project is using encryption keys from an OKM (Oracle Key Management) system. SymptomsUnable to create new share in a project or replication is failing on the target. Below error is returned: "The action could not be completed because the specified encryption key is not in a useable state" Replication target logs will report: "Ensure encryption key is available"
CauseThis can be caused by an a Key used for project/share that has the Encryption period expired, see below description. Key Policies specify the Encryption Period and the Cryptoperiod for a Key. The Encryption Period is the length of time a Key SolutionIf the Encryption period has expired, you will need to perform a key change on the project/share. This can be done at anytime while the Project/Share is in use. First you must add a new key to the keystore. ZFSSA:> shares encryption okm keys create ZFSSA:shares encryption okm key-004 (uncommitted)> ls
Next change the key on the Project/Share. ZFSSA:> shares select okm-project
Now we can verify the project and underlying shares have the new key. ZFSSA:shares okm-project> select TEST get keyname
Attachments This solution has no attachment |
||||||||||||||||
|