Fabric OS Encryption Administrator's Guide

Fabric OS Encryption Administrator’s Guide 173
53-1002159-03
Data re-keying
3
5. Check the status of the re-keying session.
FabricAdmin:switch> cryptocfg --show -rekey -all
Number of rekey session(s): 1
Container name: cx320-157A
EE node: 10:00:00:05:1e:40:4c:00
EE slot: 9
Target: 50:06:01:60:30:20:db:34 50:06:01:60:b0:20:db:34
Target PID: 022900
VT: 20:00:00:05:1e:53:8d:cd 20:01:00:05:1e:53:8d:cd
VT PID: 06c001
Host: 10:00:00:00:c9:56:e4:7b 20:00:00:00:c9:56:e4:7b
Host PID: 066000
VI: 20:02:00:05:1e:53:8d:cd 20:03:00:05:1e:53:8d:cd
VI PID: 06c201
LUN number: 0x1
LUN serial number:
600601603FE2120014FC89130295DF1100010000000000000008000000000000
Rekey session number: 0
Percentage complete: 23
Rekey state: Write Phase
Rekey role: Primary/Active
Block size: 512
Number of blocks: 2097152
Current LBA: 488577
Operation succeeded.
Suspension and resumption of re-keying operations
A re-key may be suspended or fail to start for several reasons:
The LUN goes offline or the encryption switch fails and reboots. Re-key operations are resumed
automatically when the target comes back online or the switch comes back up. You cannot
abort an in-progress re-key operation.
An unrecoverable error is encountered on the LUN and the in-progress re-key operation halts.
The following LUN errors are considered unrecoverable:
SenseKey: 0x3 - Medium Error.
SenseKey: 0x4 - Hardware Error.
SenseKey: 0x7 - Data Protect.
An unrecoverable error is encountered during the re-key initialization phase. The re-key
operation does not begin and a CRITICAL error is logged. All host I/O comes to a halt. All cluster
members are notified.
For any unrecoverable errors that may occur during any other phase of the process, the re-key
operation is suspended at that point and a CRITICAL error is logged. All cluster members are
notified. Host I/O to all regions of the LUN is halted. Only READ operations are supported for
the scratch space region of the LUN used for storing the status block of the re-key operation.
After all errors have been corrected, you have two recovery options:
Resume the suspended re-key session. All DEK cluster or HA cluster members must be online
and reachable for this command to succeed. If successful, this command resumes the re-key
sessions from the point where it was interrupted.