<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enable FIPS on clean reinstall AFF300 in AFF</title>
    <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458256#M1386</link>
    <description>&lt;P&gt;And it looks like you should top out at the latest ONTAP 9.12.1P version. for a full re-init:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;from Loader&lt;UL&gt;&lt;LI&gt;set-defaults&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;setenv bootarg.storageencryption.support true&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;saveenv&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;ifconfig e0M -addr=192.168.100.10 -mask=255.255.255.0 -gw=192.168.100.1&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;netboot &lt;A href="http://9121P16_q_image.tgz" target="_blank"&gt;http://9121P16_q_image.tgz&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;This will automatically go to the special boot menu. When there, choose&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;option 7 (install new software)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Specify the same URL (the e0M will maintain the IP you gave it)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;When prompted about recovery, say no!&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;when prompted to reboot, say y&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Repeat on other node (or run simultaneously with a different IP)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Both will automatically reboot to the Menu at which point, you will need to do the 9/9a/9b process!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2025 18:20:58 GMT</pubDate>
    <dc:creator>TMACMD</dc:creator>
    <dc:date>2025-02-04T18:20:58Z</dc:date>
    <item>
      <title>How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458224#M1371</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have second hand AFF300 with 2 shelves 48 drives all all self encrypting SSDs.&lt;/P&gt;&lt;P&gt;The previous ontap was 9.11.1 I uploaded 9.15.1P7 and trying to install from scratch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no data to be saves and I do have license keys to the controllers.&lt;/P&gt;&lt;P&gt;When going to special boot option 5 i see error message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[NODENAME-01:disk.encryptNoSupport:ALERT]: Detected FIPS-certified encrypting drive 0d.02.0, but FIPS drives are not supported on this node. 48 of 48 disks checked are FIPS-certified.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously the FIPS are not supported on the node. How do I enable this?&lt;/P&gt;&lt;P&gt;There need to be some argument to set so when reboot the disk will be available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now disks are marked as failed:&lt;/P&gt;&lt;P&gt;[NODENAME-01:diskown.errorReadingOwnership:notice]: error 3 ( disk failed) while reading ownership on disk 0a.01.22 (S/N 9620AXXXXXXX)&lt;/P&gt;&lt;P&gt;Any Ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 23:21:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458224#M1371</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-03T23:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458225#M1372</link>
      <description>&lt;P&gt;a couple things here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;first FIPS mode won’t help. To enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;set advanced&lt;/P&gt;&lt;P&gt;&amp;nbsp;security config modify -interface ssl -FIPS true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it sounds like you grabbed the wrong ONTAP version&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;on the download page the first is for encryption enabled ONTAP. The second is for non-export countries that are not allowed to have encryption.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;i think you downloaded the wrong one my friend.&amp;nbsp;&lt;BR /&gt;try downloading again but the correct version. You may have to use the cli to push it. Have not tried in a long time (from non-enc version to enc version)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;the next issue: were the drives previously encrypted? If they were and you reinitialized the system did you check if the drives had the encryption key removed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you really won’t be able to do much until you get the correct code anyway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and if the drives are encrypted and have not been “opened” (meaning the drive is in encrypted mode) you are going to likely need to wipe again anyway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;easiest would be to do an option 9a on both nodes, then on one node go into maintenance mode and then sanitize the SSDs there. They can all be done at the same time and it’s pretty instant&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 23:40:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458225#M1372</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-03T23:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458226#M1373</link>
      <description>&lt;P&gt;Thank you for quick reply.&lt;/P&gt;&lt;P&gt;I can not really do&amp;nbsp;&lt;SPAN&gt;set advanced because there is no OS installed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have access to Loader &amp;gt; and&amp;nbsp;boot_ontap menu&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Option 9a does not really do anything since getting message that there are no disks available to the controller.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will try to reverse to 9.11, this is what the system came with anyway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The drives were previously encrypted. The system can not read them, getting error and fails them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;iskown.errorReadingOwnership:notice]: error 3 ( disk failed) while reading ownership&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am ok to erase all data from them anyway.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 00:10:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458226#M1373</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-04T00:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458227#M1374</link>
      <description>&lt;P&gt;When booting to maintenance more i get this message. Does this mean that this version is FIPS enabled?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cryptomod_fips: Cryptomod FIPS version: Cryptomod FIPS 3.0&lt;BR /&gt;cryptomod_fips: Executing Crypto FIPS Self Tests.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'CPU COMPATIBILITY' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'AES-128 ECB, AES-256 ECB' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'AES-128 CBC, AES-256 CBC' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'AES-128 GCM, AES-256 GCM' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'AES-128 CCM' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'AES-128, AES-256 CMAC' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'CTR_DRBG' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'KDF' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'SHA1, SHA256, SHA512' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'SHA3-256' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'HMAC-SHA1, HMAC-SHA256, HMAC-SHA512' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'PBKDF2' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'AES-XTS 128, AES-XTS 256' passed.&lt;BR /&gt;cryptomod_fips: Crypto FIPS self-test: 'Self-integrity' passed.&lt;BR /&gt;Feb 04 00:01:58 [CONTROLLER-01:raid.autoPart.disabled:ALERT]: Disk auto-partitioning is disabled on this system: the system needs a minimum of 8 usable internal hard disks.&lt;BR /&gt;Feb 04 00:01:58 [CONTROLLER-01:callhome.raid.adp.disabled:notice]: Disk auto-partitioning is disabled on this system: ADP DISABLED.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 00:19:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458227#M1374</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-04T00:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458228#M1375</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;P&gt;&amp;nbsp;boot both systems to the maintenance menu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;then choose option 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;then it will ask for an interface, say e0M. When asked to reboot say n then choose option 7 again&lt;/P&gt;&lt;P&gt;&amp;nbsp;define the ip and then specify a location to grab the correct code from. let the node reboot.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;let us know&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 00:19:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458228#M1375</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T00:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458229#M1376</link>
      <description>&lt;P&gt;Sounds like you will need to sanitize the disks. When I get back to my laptop I can send help. But it sounds like before the clearing , the encryption key was not removed. You’re stuck until the disks are cleared&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 00:29:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458229#M1376</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T00:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458247#M1377</link>
      <description>&lt;P&gt;To check you have the right ONTAP image that supports encryption..&lt;BR /&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/DM/Encryption/Encryption-KBs/How_to_determine_if_the_running_ONTAP_version_supports_NetApp_Volume_Encryption_NVE" target="_blank" rel="noopener"&gt;https://kb.netapp.com/on-prem/ontap/DM/Encryption/Encryption-KBs/How_to_determine_if_the_running_ONTAP_version_supports_NetApp_Volume_Encryption_NVE&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the FIPS/NSE drives were not set back to "open"/factory MSID 0x0 before decommissioning, they are probably still locked with authentication keys. Check out these articles:&lt;BR /&gt;&lt;BR /&gt;&lt;A class="go result-spacer mt-tracked-result" title="How to return SED to factory-configured settings after FIPS authentication key is lost" href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_return_SED_to_factory-configured_settings_after_FIPS_authentication_key_is_lost" target="_blank" rel="noopener" data-ga-label="Result 5" data-track-uri="https://kb.netapp.com/@api/deki/site/query/6103548?pageid=38013&amp;amp;rank=0.809331111640086&amp;amp;type=page&amp;amp;sessionId=284e5f8e-e321-11ef-8e9f-0621ac56a7e9&amp;amp;position=5" data-tracking="false"&gt;How to return SED to factory-configured settings after FIPS authentication key is lost&lt;/A&gt;&lt;BR /&gt;&lt;A class="go result-spacer mt-tracked-result" title="How to identify the PSID on a FIPs capable drive" href="https://kb.netapp.com/on-prem/E-Series/Hardware-KBs/How_to_identify_the_PSID_on_a_FIPs_capable_drive" target="_blank" rel="noopener" data-ga-label="Result 1" data-track-uri="https://kb.netapp.com/@api/deki/site/query/6103548?pageid=51473&amp;amp;rank=1&amp;amp;type=page&amp;amp;sessionId=284e5f8e-e321-11ef-8e9f-0621ac56a7e9&amp;amp;position=1" data-tracking="false"&gt;How to identify the PSID on a FIPs capable drive&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 17:58:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458247#M1377</guid>
      <dc:creator>andris</dc:creator>
      <dc:date>2025-02-04T17:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458248#M1378</link>
      <description>&lt;P&gt;But your 1st step is to set the environment variable for FIPS/NSE drives.&lt;BR /&gt;See: &lt;A class="go result-spacer mt-tracked-result" title="All disk failed after reinstall ONTAP" href="https://kb.netapp.com/on-prem/ontap/OHW/OHW-KBs/All_disk_failed_after_reinstall_ONTAP" data-ga-label="Result 1" data-track-uri="https://kb.netapp.com/@api/deki/site/query/6103570?pageid=151156&amp;amp;rank=1&amp;amp;type=page&amp;amp;sessionId=c6fded16-e321-11ef-962d-c595ddf48b9d&amp;amp;position=1" data-tracking="false" target="_blank"&gt;All disk failed after reinstall ONTAP&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:00:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458248#M1378</guid>
      <dc:creator>andris</dc:creator>
      <dc:date>2025-02-04T18:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458249#M1379</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12128"&gt;@andris&lt;/a&gt;&amp;nbsp;Those will not help in hist case. I am digging out what he needs. He needs to boot to maintenance mode and sanitize there. I do noth think you can do those commands in the KB without the cluster being active. give me a few minutes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:01:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458249#M1379</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458250#M1380</link>
      <description>&lt;P&gt;I don't believe Sanitize is even possible if you don't have the AK. &lt;BR /&gt;The 1st KB link has the command while in Maintenance mode.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV class="editor-content mt-1 ml-0 mr-0 mb-1" title="Procedure"&gt;If this is a new setup or a repurposed system with no data on it, then the process is to boot (1) node to the maintenance mode then run the command from there:&lt;/DIV&gt;
&lt;DIV class="editor-content mt-1 ml-0 mr-0 mb-1" title="Procedure"&gt;&lt;SPAN class="click-to-copy-code-container"&gt;&lt;CODE&gt;*&amp;gt; disk encrypt revert_original &amp;lt;psid&amp;gt; &amp;lt;disk&amp;gt;&lt;/CODE&gt;&lt;/SPAN&gt;
&lt;DIV class="click-to-copy-button" title="Copy command to clipboard" data-clipboard-text="disk encrypt revert_original &amp;lt;psid&amp;gt; &amp;lt;disk&amp;gt;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:07:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458250#M1380</guid>
      <dc:creator>andris</dc:creator>
      <dc:date>2025-02-04T18:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458251#M1381</link>
      <description>&lt;P&gt;There is some progress, i was able to set in loader.&lt;/P&gt;&lt;P&gt;setenv bootarg.storageencryption.support true&lt;/P&gt;&lt;P&gt;I also went back to 9.11.1 since using&amp;nbsp;X365A&amp;nbsp; drives&amp;nbsp; in&amp;nbsp;&lt;SPAN&gt;DS224C. i think those drives do not go pass 9.11.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At least i see the drives in maintenance more. Still need to sanitize them and clear encryption.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:09:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458251#M1381</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-04T18:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458252#M1382</link>
      <description>&lt;P&gt;at the loader on both:&lt;/P&gt;&lt;P&gt;setenv bootarg.storageencryption.support true&lt;/P&gt;&lt;P&gt;printenv&amp;nbsp;bootarg.storageencryption.support -. make sure this is true!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see these:&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_long_does_disk_encrypt_sanitize_all_take" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_long_does_disk_encrypt_sanitize_all_take&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/disk_encrypt_show_hangs_after_sanitize" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/disk_encrypt_show_hangs_after_sanitize&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Get both nodes to loader.&lt;/P&gt;&lt;P&gt;BOOT ONE NODE ONLY into maintenance mode&lt;/P&gt;&lt;P&gt;run&lt;/P&gt;&lt;P&gt;disk encrypt sanitize -all -&amp;gt; pay attention to messages! this should run nearly instantly.&lt;/P&gt;&lt;P&gt;If you try to run "disk encrypt show" you node will hang....DO NOT DO IT&lt;/P&gt;&lt;P&gt;reboot the node into maintenance mode and then run&lt;/P&gt;&lt;P&gt;disk encrypt show&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All disks should be unlocked. Now, halt the node. and do this on both nodes&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;loader: set-defaults&lt;/LI&gt;&lt;LI&gt;loader: saveenv&lt;/LI&gt;&lt;LI&gt;loader:&amp;nbsp;printenv bootarg.storageencryption.support&lt;UL&gt;&lt;LI&gt;If false or undefined, set to true&lt;/LI&gt;&lt;LI&gt;setenv bootarg.storageencryption.support true&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;loader: boot_ontap menu&lt;/LI&gt;&lt;LI&gt;At the boot menu -&amp;gt; 9&lt;UL&gt;&lt;LI&gt;On one node only: 9a&lt;UL&gt;&lt;LI&gt;Affirm prompts and let it run. wait until prompt returns&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;On second node only: 9a&lt;UL&gt;&lt;LI&gt;Affirm prompts and let it run. wait until prompt returns&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;On one node only: 9b&lt;UL&gt;&lt;LI&gt;Affirm prompts and let it run. wait until ONTAP license appears&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;On second node: 9b&lt;UL&gt;&lt;LI&gt;Affirm prompts and let it run.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;When the second node gets to the license, setup the cluster&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:11:50 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458252#M1382</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458253#M1383</link>
      <description>&lt;P&gt;Please reboot into 9.15! I think there were issues with 9.11 and sanitize&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:12:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458253#M1383</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458254#M1384</link>
      <description>&lt;P&gt;FYI, I have done this recently. It works.&lt;/P&gt;&lt;P&gt;Boot into maint, run the command, reboot&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:14:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458254#M1384</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458255#M1385</link>
      <description>&lt;P&gt;That dis not work when I tried it. need to sanitize. see below&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:14:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458255#M1385</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458256#M1386</link>
      <description>&lt;P&gt;And it looks like you should top out at the latest ONTAP 9.12.1P version. for a full re-init:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;from Loader&lt;UL&gt;&lt;LI&gt;set-defaults&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;setenv bootarg.storageencryption.support true&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;saveenv&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;ifconfig e0M -addr=192.168.100.10 -mask=255.255.255.0 -gw=192.168.100.1&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;netboot &lt;A href="http://9121P16_q_image.tgz" target="_blank"&gt;http://9121P16_q_image.tgz&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;This will automatically go to the special boot menu. When there, choose&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;option 7 (install new software)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Specify the same URL (the e0M will maintain the IP you gave it)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;When prompted about recovery, say no!&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;when prompted to reboot, say y&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Repeat on other node (or run simultaneously with a different IP)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Both will automatically reboot to the Menu at which point, you will need to do the 9/9a/9b process!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:20:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458256#M1386</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458257#M1387</link>
      <description>&lt;P&gt;Those drives are EOA(31-Dec-2017) / EOS (31-Jan-2023). Latest supported ONTAP 9.12.1P16 (or current)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:22:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458257#M1387</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-02-04T18:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458258#M1388</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;9.12.1P is based on the drive type?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;X365_TPM3V NA04 1.6tb SSD&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the AFF300 ends at 9.16.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would you say do not even try 9.15 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 18:24:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458258#M1388</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-04T18:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458306#M1389</link>
      <description>&lt;P&gt;I went with&amp;nbsp;&lt;SPAN&gt;disk encrypt sanitize -all&amp;nbsp; and it is running for 16 hours so far.&amp;nbsp; 48 drives 1.6tb each drive.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is still running, is this normal?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;*&amp;gt; disk sanitize status&lt;BR /&gt;ERROR: Failed to recognize disks: No disks to read.&lt;BR /&gt;Feb 05 14:46:15 [localhost:raid.assim.tree.noRootVol:error]: No usable root volume was found!&lt;BR /&gt;. Still continuing...&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Martin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 15:01:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458306#M1389</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-05T15:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable FIPS on clean reinstall AFF300</title>
      <link>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458359#M1390</link>
      <description>&lt;P&gt;I had 2 problems.&lt;/P&gt;&lt;P&gt;1st.&amp;nbsp;&lt;SPAN&gt;setenv bootarg.storageencryption.support was set to false.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Had to set it to true on both nodes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2nd. Ontap os version. Because of the type of drives 9.12 was the last supported version.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After changing settings and os version everything else was standard installation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/65619"&gt;@TMACMD&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12128"&gt;@andris&lt;/a&gt;&amp;nbsp;for valuable comments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Martin.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 00:51:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/AFF/How-to-enable-FIPS-on-clean-reinstall-AFF300/m-p/458359#M1390</guid>
      <dc:creator>marcinmf</dc:creator>
      <dc:date>2025-02-07T00:51:44Z</dc:date>
    </item>
  </channel>
</rss>

