<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SED disk encryption key query in AFF</title>
    <link>https://community.netapp.com/t5/AFF/SED-disk-encryption-key-query/m-p/435251#M1076</link>
    <description>&lt;P&gt;Hi Experts.&lt;/P&gt;&lt;P&gt;On AFF cluster with 16 SED disks, I have assigned one of the key shown in the" security key-manager key show". Just wanted to check if this is ok, or do I need to assign a key from Node1 to node1 assigned disks and key from node2 to node2 assigned disks.&lt;/P&gt;&lt;P&gt;Also&amp;nbsp;" security key-manager key show" displays at least a dozen of keys. Is it ok to use any one of the key for encryption purpose?&lt;/P&gt;&lt;P&gt;Note below display is edited and the key is just a arbitrary key.&lt;/P&gt;&lt;P&gt;CLUS1&amp;gt; storage encryption disk show&lt;BR /&gt;Disk Mode Data Key ID&lt;BR /&gt;-------- ---- ----------------------------------------------------------------&lt;BR /&gt;1.0.0 data 00000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.1 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.2 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.3 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.4 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.5 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.6 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.7 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.16 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.17 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.18 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.19 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.20 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.21 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.22 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.23 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;16 entries were displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 10:00:59 GMT</pubDate>
    <dc:creator>Baiju625</dc:creator>
    <dc:date>2025-06-04T10:00:59Z</dc:date>
    <item>
      <title>SED disk encryption key query</title>
      <link>https://community.netapp.com/t5/AFF/SED-disk-encryption-key-query/m-p/435251#M1076</link>
      <description>&lt;P&gt;Hi Experts.&lt;/P&gt;&lt;P&gt;On AFF cluster with 16 SED disks, I have assigned one of the key shown in the" security key-manager key show". Just wanted to check if this is ok, or do I need to assign a key from Node1 to node1 assigned disks and key from node2 to node2 assigned disks.&lt;/P&gt;&lt;P&gt;Also&amp;nbsp;" security key-manager key show" displays at least a dozen of keys. Is it ok to use any one of the key for encryption purpose?&lt;/P&gt;&lt;P&gt;Note below display is edited and the key is just a arbitrary key.&lt;/P&gt;&lt;P&gt;CLUS1&amp;gt; storage encryption disk show&lt;BR /&gt;Disk Mode Data Key ID&lt;BR /&gt;-------- ---- ----------------------------------------------------------------&lt;BR /&gt;1.0.0 data 00000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.1 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.2 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.3 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.4 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.5 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.6 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.7 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.16 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.17 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.18 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.19 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.20 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.21 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.22 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;1.0.23 data 0000000000000000012345567788999000007AADFA22323929ADSDKSJ11111SS&lt;BR /&gt;16 entries were displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:00:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/SED-disk-encryption-key-query/m-p/435251#M1076</guid>
      <dc:creator>Baiju625</dc:creator>
      <dc:date>2025-06-04T10:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: SED disk encryption key query</title>
      <link>https://community.netapp.com/t5/AFF/SED-disk-encryption-key-query/m-p/435287#M1078</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/93760"&gt;@Baiju625&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless your security protocol requires you to use multiple keys then you are fine with just using on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference: &lt;A href="https://docs.netapp.com/us-en/ontap/encryption-at-rest/enable-onboard-key-management-96-later-nse-task.html" target="_blank" rel="noopener"&gt;Enable onboard key management in ONTAP 9.6 and later&lt;/A&gt; and &lt;A href="https://docs.netapp.com/us-en/ontap/encryption-at-rest/assign-authentication-keys-seds-onboard-task.html" target="_blank" rel="noopener"&gt;Assign a data authentication key to a FIPS drive or SED (onboard key management)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;You can also rotate the keys if that is required.&amp;nbsp; KB: &lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_rotate_encryption_keys_for_NetApp_Storage_Encryption_(NSE)" target="_blank" rel="noopener"&gt;How to rotate encryption keys for NetApp Storage Encryption (NSE)&lt;/A&gt;, explains the process of rotating the keys for both External and Onboard key manager (OKM).&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Let us know if you have any follow up questions.&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P data-unlink="true"&gt;Brad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 02:03:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/SED-disk-encryption-key-query/m-p/435287#M1078</guid>
      <dc:creator>darb0505</dc:creator>
      <dc:date>2022-05-25T02:03:30Z</dc:date>
    </item>
  </channel>
</rss>

