<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NVE:  Force immediate deletion of keys from external key manager in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145928#M32409</link>
    <description>&lt;P&gt;Hi there!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have&amp;nbsp;&lt;A href="http://docs.netapp.com/ontap-9/topic/com.netapp.doc.pow-nve/GUID-A1ABF868-6945-4E98-9358-BED342872454.html?cp=13_2_3_14_2" target="_self"&gt;this document&lt;/A&gt; available which outlines how to make data inaccessible in given scenarios - while it is written for self encrypting drives, many of the concepts are the same for NVE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I acknowledge it doesn't directly answer your question -I am providing it to perhaps help inform testing and use scenarios for encrypted volumes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't have any luck here with a direct answer, I suggest that you should submit a support case.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jan 2019 02:55:26 GMT</pubDate>
    <dc:creator>AlexDawson</dc:creator>
    <dc:date>2019-01-16T02:55:26Z</dc:date>
    <item>
      <title>NVE:  Force immediate deletion of keys from external key manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145922#M32407</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I'm doing extensive external key manager testing, and am being throttled by not being able to delete the key manager configuration because it says there are encrypted volumes.&amp;nbsp; All the encrypted volumes have been deleted, but I have found from testing that the keys for these volumes aren't deleted from the key manager until some batch process runs in the middle of the night.&amp;nbsp; As long as the keys are still hanging around,&amp;nbsp; the cluster won't let me delete the configuration so I can re-test.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Does anyone know of a way to force the deletion of these keys?&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I've tried working around this by creating an encrypted volume for testing purposes and then using the "volume move start" command to unencrypt it, but I'm being told that operation isn't supported for the encrypted volume for some reason.&amp;nbsp; &amp;nbsp; Is that because an external key manager is involved?&amp;nbsp; &amp;nbsp; I assume that command would otherwise work.&lt;BR /&gt;&lt;BR /&gt;All the relevant commands I'm trying and the responses are below.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;Jane&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SAT-NVE::*&amp;gt; security key-manager delete-kmip-config&lt;/P&gt;
&lt;P&gt;Error: command failed:&lt;BR /&gt; Encrypted volumes are found in the cluster. Use the "volume show&lt;BR /&gt; -encryption-state !none" command to view all such volumes. Move these&lt;BR /&gt; volumes to plain-text volumes using the "volume move start &amp;lt;vol_name&amp;gt;&lt;BR /&gt; -vserver &amp;lt;vserver_name&amp;gt; -destination-aggregate &amp;lt;aggr_name&amp;gt;&lt;BR /&gt; -encrypt-destination false " command before attempting to disable&lt;BR /&gt; external key management by removing all the keys.&lt;BR /&gt;&lt;BR /&gt;SAT-NVE::*&amp;gt; volume show -encryption-state !none&lt;BR /&gt;There are no entries matching your query.&lt;BR /&gt;&lt;BR /&gt;After creating a new encrypted volume to test the volume move start command...&lt;BR /&gt;&lt;BR /&gt;SAT-NVE::*&amp;gt; volume show -encryption-state !none&lt;BR /&gt;Vserver Volume Aggregate State Type Size Available Used%&lt;BR /&gt;--------- ------------ ------------ ---------- ---- ---------- ---------- -----&lt;BR /&gt;SAT-01 vol_jane SAT_NVE_01_SSD_1&lt;BR /&gt; online RW 1GB 972.5MB 0%&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;SAT-NVE::*&amp;gt; volume move start vol_jane -vserver SAT-NVE -destination-aggregate SAT_VNE_01_SSD_2 -encrypt-destination false&lt;/P&gt;
&lt;P&gt;Error: command failed: This operation is not supported for the system volume "vol_jane".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:57:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145922#M32407</guid>
      <dc:creator>JaneGil</dc:creator>
      <dc:date>2025-06-04T12:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: NVE:  Force immediate deletion of keys from external key manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145928#M32409</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have&amp;nbsp;&lt;A href="http://docs.netapp.com/ontap-9/topic/com.netapp.doc.pow-nve/GUID-A1ABF868-6945-4E98-9358-BED342872454.html?cp=13_2_3_14_2" target="_self"&gt;this document&lt;/A&gt; available which outlines how to make data inaccessible in given scenarios - while it is written for self encrypting drives, many of the concepts are the same for NVE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I acknowledge it doesn't directly answer your question -I am providing it to perhaps help inform testing and use scenarios for encrypted volumes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't have any luck here with a direct answer, I suggest that you should submit a support case.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 02:55:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145928#M32409</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2019-01-16T02:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: NVE:  Force immediate deletion of keys from external key manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145974#M32420</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, NSE was a little different to work with since taking them back to MSID deleted the keys off the external key manager immediately enabling you to wipe out out the key manager config.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I'm working around it with NVE by just not creating any encrypted volumes now just to test the certificate installation process and TLS session establishment.&amp;nbsp; &amp;nbsp;As long as I don't create any keys, I can retest as much as I want in any give day.&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;BR /&gt;&lt;BR /&gt;Jane&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 21:07:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/145974#M32420</guid>
      <dc:creator>JaneGil</dc:creator>
      <dc:date>2019-01-16T21:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: NVE:  Force immediate deletion of keys from external key manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/148125#M33001</link>
      <description>&lt;P&gt;You need to purge the deleted volume from the recovery-queue, then the keys on kmip server will be removed.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 17:52:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/148125#M33001</guid>
      <dc:creator>anemic_iceman</dc:creator>
      <dc:date>2019-04-25T17:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: NVE:  Force immediate deletion of keys from external key manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/148137#M33004</link>
      <description>&lt;P&gt;Thanks for this!!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 13:43:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NVE-Force-immediate-deletion-of-keys-from-external-key-manager/m-p/148137#M33004</guid>
      <dc:creator>JaneGil</dc:creator>
      <dc:date>2019-04-26T13:43:21Z</dc:date>
    </item>
  </channel>
</rss>

