Skip to main content
NetApp Knowledge Base

What are the phases during a volume encryption rekey?

Views:
97
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core
Last Updated:

Applies to

  • ONTAP 9
  • NetApp Volume Sncryption (NVE)
  • Volume encryption rekey start

Answer

  • Phase 1 scan (rekey)
    The blocks of a volume are read sequentially, and ONTAP rekeys them using the new key. Once that is complete, the operation moves to phase two.
  • Phase 2 scan (redirect fixup)
    When the sequential scan is completed in phase 1, some metadata blocks might not have the correct physical block mapping in the volume file metadata block. To correct it, we trigger the redirect fix-up scan. Once the phase 2 scan is completed, the older key is deleted. Until this point, both keys will be active and available to use.
NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.