HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 154

Use the following procedure to decommission a LUN., to obtain a list of all the currently

Page 154 highlights

3 Crypto LUN configuration When a device decommission operation fails on the encryption group leader for any reason, the crypto configuration remains uncommitted until a user-initiated commit or a subsequent device decommission operation issued on the encryption group leader completes successfully. Device decommission operations should always be issued from a committed configuration. If not, the operation will fail with the error message An outstanding transaction is pending in Switch/EG. IF this happens, you can resolve the problems by committing the configuration from the encryption group leader. Provided that the crypto configuration is not left uncommitted because of any crypto configuration changes or a failed device decommission operation issued on a encryption group leader node, this error message will not be seen for any device decommission operation issued serially on an encryption group member node. If more than one device decommission operation is tried in an encryption group from member nodes simultaneously, then this error message is transient and will go away after device decommission operation is complete. If the device decommissioning operation fails, wait briefly and retry the operation. If a LUN is removed when undergoing decommission or when it is in a decommissioned failed state, or if a container hosting the LUN is deleted, you must use the -force option on the commit operation (cryptocfg --commit -force). If you do not, the commit operation fails with a decommission in progress error. Use the following procedure to decommission a LUN. 1. Log into the node that hosts the container as Admin or FabricAdmin. 2. Enter the cryptocfg -decommission command. cryptocfg --decommission -container disk_ct0 -initiator 21:01:00:1b:32:29:5d:1c -LUN 0 3. Enter cryptocfg -show -decommissionedkeyids to obtain a list of all the currently decommissioned key IDs to be deleted after a decommissioning operation manually from the keyvault. cryptocfg -show -decommissionedkeyids 4. Delete the listed key IDs from the key vault. 5. Enter the cryptocfg -delete -decommissionedkeyids command to purge all the key IDs associated with decommissioned LUN. cryptocfg -delete -decommissionedkeyids 6. Enter the cryptocfg -show -decommissionedkeyids command to verify that the deleted key IDs are no longer listed. The cache is also cleared when cryptocfg --zeroizeEE is executed on the encryption engine. 136 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

136
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Crypto LUN configuration
3
When a device decommission operation fails on the encryption group leader for any reason, the
crypto configuration remains uncommitted until a user-initiated commit or a subsequent device
decommission operation issued on the encryption group leader completes successfully. Device
decommission operations should always be issued from a committed configuration. If not, the
operation will fail with the error message
An outstanding transaction is pending in Switch/EG
. IF
this happens, you can resolve the problems by committing the configuration from the encryption
group leader.
Provided that the crypto configuration is not left uncommitted because of any crypto configuration
changes or a failed device decommission operation issued on a encryption group leader node, this
error message will not be seen for any device decommission operation issued serially on an
encryption group member node. If more than one device decommission operation is tried in an
encryption group from member nodes simultaneously, then this error message is transient and will
go away after device decommission operation is complete. If the device decommissioning
operation fails, wait briefly and retry the operation. If a LUN is removed when undergoing
decommission or when it is in a decommissioned failed state, or if a container hosting the LUN is
deleted, you must use the
-force
option on the commit operation (
cryptocfg --commit -force
). If
you do not, the commit operation fails with a decommission in progress error.
Use the following procedure to decommission a LUN.
1.
Log into the node that hosts the container as Admin or FabricAdmin.
2.
Enter the
cryptocfg -decommission
command.
cryptocfg --decommission -container disk_ct0 -initiator
21:01:00:1b:32:29:5d:1c -LUN 0
3.
Enter
cryptocfg -show -decommissionedkeyids
to obtain a list of all the currently
decommissioned key IDs to be deleted after a decommissioning operation manually from the
keyvault.
cryptocfg -show
-decommissionedkeyids
4.
Delete the listed key IDs from the key vault.
5.
Enter the
cryptocfg -delete -decommissionedkeyids
command to purge all the key IDs
associated with decommissioned LUN.
cryptocfg -delete -decommissionedkeyids
6.
Enter the
cryptocfg -show -decommissionedkeyids
command to verify that the deleted key IDs
are no longer listed.
The cache is also cleared when
cryptocfg --zeroizeEE
is executed on the encryption engine.