Brocade Fabric OS Encryption Administrator's Guide v7.1.0 (53-1002721-01, March 2013)

Table Of Contents
186 Fabric OS Encryption Administrators Guide (SKM/ESKM)
53-1002721-01
Force-enabling a decommissioned disk LUN for encryption
3
a. Decommission the primary LUN.
FabricAdmin:switch> cryptocfg --decommission -container <container name>
-initiator <initiator PWWN> -LUN <lun number>
b. Display the decommissioned key IDs.
FabricAdmin:switch> cryptocfg --show –decommissionedkeyids
c. Delete the respective key from the key vault. On the Brocade Encryption Switch, enter the
following command.
FabricAdmin:switch> cryptocfg --delete –decommissionedkeyids
d. Decommission the secondary LUN.
FabricAdmin:switch> cryptocfg --decommission -container <container name>
-initiator <initiator PWWN> -LUN <lun number>
Force-enabling a decommissioned disk LUN for encryption
When trying to re-use primary or secondary replicated LUNs, you must first decommission the
LUNs. When trying to re-use a decommissioned LUN, you must:
1. Delete the keys from the key vault.
2. Log in as Admin or FabricAdmin.
3. Delete the decommissioned LUN IDs from the Brocade Encryption Switch.
4. Display the decommissioned key IDs.
FabricAdmin:switch> cryptocfg --show –decommissionedkeyids
5. Delete the respective key from the Brocade Encryption Switch. Enter the following command.
FabricAdmin:switch> cryptocfg --delete –decommissionedkeyids
6. Add the LUN back into the container as cleartext.
FabricAdmin:switch> cryptocfg --add –LUN <crypto target container name> <LUN
Num | LUN Num Range> <Initiator PWWN> <Initiator NWWN> -lunstate cleartext
7. En a b le t h e LU N.
FabricAdmin:switch> cryptocfg --enable -LUN <crypto target container name>
<LUN Num> <Initiator PWWN>
8. Modify the LUN to encrypted.
FabricAdmin:switch> cryptocfg --modify -LUN <crypto target container name>
<LUN Num> <Initiator PWWN> 0 -lunstate encrypted -encryption_format native
-encrypt