If you have encrypted disks managed by Microsoft’s Windows Failover Clusters, you can decrypt or decommission one. By default, the encrypted disks are registered under more than one server, typically two servers. However, the encrypted disks are only attached to the active node. On the inactive node, the encrypted servers have the following status: GONE.
You can either decrypt the disks, or decommission them if the encrypted content is no longer needed.
The examples in the following procedure assume that you have two servers, Node 1 and Node 2, and the encrypted disks are currently attached to Node 1.
Important: The Policy Agent must be able to communicate with Cryptographic Security Platform Vault, and Cryptographic Security Platform Vault must be in a good state before attempting these this procedure.
- Run
hcl statuson Node 1 to list all encrypted disks. If you plan to decrypt the disks, run the following command on Node 1:
hcl decrypt <drive_letter>
Wait until the decryption is completed. Multiple disks can be run in parallel.
Important: Ensure that the disks are not failed over to the Node 2 while the disks are being decrypted.
After decryption, the disks will be removed.
If you plan to decommission the disks, run the following command on Node 1:
hcl rm <drive_letter>
Run
hcl statuson Node 1.The decrypted or decommissioned drives should have the following status:
Available.Run
hcl statuson Node 2.The encrypted disks are not listed, and the status should be:
GONEon the Cryptographic Security Platform Vault webGUI. The disks are not attached to this server.To remove the encrypted devices with status
GONE, run the following command on Node 2:hcl destroy <drive_letter>
- Verify that the disks are no longer displayed on the Cryptographic Security Platform Vault webGUI.