KEK Retrieval after Full Cluster Restart

  1. Shutdown VMs in the Nutanix cluster.

  2. Stop Nutanix Cluster Services.

  3. Shutdown CVMs and Nutanix Hosts in the cluster, wait for 3 minutes to power drain and verify shutdown status.

  4. Shut down both Active nodes of KMS Server.

  5. Power on Hosts and verify status(CVMs power on automatically).

  6. Start Nutanix Cluster Services.

  7. Power on the VMs to test the KEK(Key Encryption Key) is not retrieved from the KMS, and the DEK(Data Encryption Key) cannot successfully unlock the Drives to boot the VMs.

  8. Power on and start services for the First Active KMS Nod,e and attempt to boot the Nutanix VMs and record behavior.

Expected Results

  • When both Active-Active KMS nodes are down, the cluster fails to retrieve the Key from KMS and decrypt the container. As a result, the test-VM using the disk from the container can read the disk but fails to boot.

85600d78-c058-4e90-8190-fdc187083bab.png


Active - Active KMS

9fd8f236-3bc8-4e09-8c96-5ca1c846f3c2.png


Failed to Boot

  • When  ESKM-1 is DOWN and ESKM-2 is UP in the Active-Active cluster, the cluster retrieves the Key from ESKM-2 and decrypts the container. As a result, the test-VM using the disk from the container reads the disk and the VM-boots successfully.

17ed234f-cb05-43c8-b079-138912f7fd13.png


Cluster Configuration

3bfde00b-c6be-4257-881e-8ab33d29b5fd.png


VM Boot Success

cbbda0ce-1742-4a45-a97b-b33eb1eeb460.png


Test- VM

  • When  ESKM-2 is DOWN and ESKM-1 is UP in the Active-Active cluster, the cluster retrieves the Key from ESKM-1 and decrypts the container. As a result, the test-VM using the disk from the container reads the disk and the VM-boots successfully.

2baee848-6f28-4866-a5a2-c63ee798f300.png



Cluster Configuration

9d475b77-2cf2-4934-826b-e723d795d41d.png


VM Boot Success

a7bdc782-d7dc-4b51-9931-ce3c9fe56aac.png


Test-VM