What are the phases during a volume encryption rekey?
Applies to
- ONTAP 9
- NetApp Volume Sncryption (NVE)
- Volume encryption rekey start
Answer
- Phase 1 scan (rekey)
The blocks of a volume are read sequentially, and ONTAP rekeys them using the new key. Once that is complete, the operation moves to phase two. - Phase 2 scan (redirect fixup)
When the sequential scan is completed in phase 1, some metadata blocks might not have the correct physical block mapping in the volume file metadata block. To correct it, we trigger the redirect fix-up scan. Once the phase 2 scan is completed, the older key is deleted. Until this point, both keys will be active and available to use.