During an offline headswap, what additional steps are needed when using encryption
Applies to
- ONTAP 9
- Encryption
- NSE
- NVE
- NAE
Answer
- If FIPS disks or self-encrypting disks are being used, it's recommended to rekey the disks to the default msid before shutting down the nodes
- Ensure that the cluster-wide passphrase is known if using Onboard Key Manager and collect an OKM backup
- Once the headswap is completed, during bootup, perform an 'Option 6' at the boot menu on both nodes
- Once the option 6 is completed, both nodes should boot up and restore the keys
- In the event that volumes are offline due to failed key-import, run the command below using the cluster-wide passphrase
security key-manager onboard sync
Additional Information
additionalInformation_text