HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 223

Loss of encryption group leader after power outage

Page 223 highlights

Loss of encryption group leader after power outage 6 Loss of encryption group leader after power outage When all nodes in an encryption group, HA Cluster, or DEK Cluster are powered down due to catastrophic disaster or power outage to whole data center, and the group leader node either fails to come back up when the other nodes are powered on, or the group leader is kept powered down, the member nodes lose information and knowledge about the encryption group. If this happens, no crypto operations or commands (except node initialization) are available on the member node after the power-cycle. This condition persists until the group leader back is online. When a group leader node fails to come back up, the group leader node can be replaced. You can do this in one of two ways: • Promote an existing member node to group leader. • Replace the failed group leader node with a new node. Use the following procedure to make one of existing member nodes into a group leader node, and make the encryption group functional again: 1. On one of the member nodes, create the encryption group with same encryption group name. That node then becomes the group leader node, and the related configurations are kept intact for the encryption group. 2. For any containers hosted on the failed group leader node, issue the cryptocfg - -replace command to change the WWN association of containers from failed group leader node to the new group leader node for all containers on the encryption engine. Use the following procedure to replace the failed group leader node with a new node: 1. On the new node, perform the switch/node initialization steps as described in Chapter 3. 2. Create an encryption group on the new node with the same encryption group name as before. 3. Use the configdownload command to download previously uploaded group leader node and encryption group configuration files to the new node. 4. For any containers hosted on the failed group leader node, issue the cryptocfg - -replace command to change the WWN association of containers from failed group leader node to the new group leader node for all containers on the encryption engine. Fabric OS Encryption Administrator's Guide 205 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
205
53-1001864-01
Loss of encryption group leader after power outage
6
Loss of encryption group leader after power outage
When all nodes in an encryption group, HA Cluster, or DEK Cluster are powered down due to
catastrophic disaster or power outage to whole data center, and the group leader node either fails
to come back up when the other nodes are powered on, or the group leader is kept powered down,
the member nodes lose information and knowledge about the encryption group. If this happens, no
crypto operations or commands (except node initialization) are available on the member node after
the power-cycle. This condition persists until the group leader back is online.
When a group leader node fails to come back up, the group leader node can be replaced. You can
do this in one of two ways:
Promote an existing member node to group leader.
Replace the failed group leader node with a new node.
Use the following procedure to make one of existing member nodes into a group leader node, and
make the encryption group functional again:
1.
On one of the member nodes, create the encryption group with same encryption group name.
That node then becomes the group leader node, and the related configurations are kept intact
for the encryption group.
2.
For any containers hosted on the failed group leader node, issue the
cryptocfg - -replace
command to change the WWN association of containers from failed group leader node to the
new group leader node for all containers on the encryption engine.
Use the following procedure to replace the failed group leader node with a new node:
1.
On the new node, perform the switch/node initialization steps as described in Chapter 3.
2.
Create an encryption group on the new node with the same encryption group name as before.
3.
Use the
configdownload
command to download previously uploaded group leader node and
encryption group configuration files to the new node.
4.
For any containers hosted on the failed group leader node, issue the
cryptocfg - -replace
command to change the WWN association of containers from failed group leader node to the
new group leader node for all containers on the encryption engine.