Do not change lun configuration while rekeying, Kac certificate registration expiry, Changing ip addresses in encryption groups – Brocade Fabric OS Encryption Administrator’s Guide Supporting HP Secure Key Manager (SKM) and HP Enterprise Secure Key Manager (ESKM) Environments (Supporting Fabric OS v7.2.0) User Manual
Page 254

234
Fabric OS Encryption Administrator’s Guide (SKM/ESKM)
53-1002923-01
KAC certificate registration expiry
5
Do not change LUN configuration while rekeying
Never change the configuration of any LUN that belongs to a CryptoTarget container/LUN 
configuration while the rekeying process for that LUN is active. If you change the LUN’s settings 
during manual or auto, rekeying or first-time encryption, the system reports a warning message 
stating that the encryption engine is busy and a forced commit is required for the changes to take 
effect. A forced commit command halts all active rekeying progresses running in all CryptoTarget 
containers and corrupts any LUN engaged in a rekeying operation. There is no recovery for this type 
of failure.
Recommendation for Host I/O traffic during online rekeying and first- 
time encryption
You may see failed I/Os if writes are done to a LUN that is undergoing first-time encryption or 
rekeying. It is recommended that host I/O operations are quiesced and not started again until 
rekey operations or first-time encryption operations for the LUN are complete.
KAC certificate registration expiry
It is important to keep track as to when your signed KAC certificates will expire. Failure to work with 
valid certificates causes certain commands to not work as expected. If you are using the certificate 
expiry feature and the certificate expires, the key vault server will not respond as expected. For 
example, the Group Leader in an encryption group might show that the key vault is connected; 
however, a member node reports that the key vault is not responding.
To verify the certificate expiration date, use the following command:
openssl x509 –in signed_kac_cert.pem -dates –noout
Output:
Not Before: Dec 4 18:03:14 2009 GMT
Not After : Dec 4 18:03:14 2010 GMT
In the example above, the certificate validity is active until “Dec 4 18:03:14 2010 GMT.” After the 
KAC certificate has expired, the registration process must be redone. 
Changing IP addresses in encryption groups
Generally, when IP addresses are assigned to the Ge0 and Ge1 ports, they should not be changed. 
If an encryption group member node IP address must be changed, refer to 
