Enabling Aggregate-level Encryption

You must use aggregate-level encryption if you plan to perform inline or background aggregate-level deduplication. Aggregate-level deduplication is otherwise not supported by NVE. ONTAP automatically “pushes” an encryption key to the Utimaco ESKM server when you encrypt a volume.

Note: Plain text volumes are not supported in NAE aggregates.

Enable or disable aggregate-level encryption:

1. The following command enables aggregate-level encryption on aggr1:

›_ Console

Cluster1::> storage aggregate create -aggregate aggr1 -diskcount 6 
tmp8jl3gqt1.jpg

Creating a new aggregate and enabling aggregate-level encryption

2. Verify that the aggregate is enabled for encryption:

›_ Console

Cluster1::> storage aggregate show -fields encrypt-with-aggr-key 
tmpbhubuq7e.jpg

Verifying encryption on aggregate