Data Domain: How to decrypt the encryption at rest data on a Data Domain file system
Summary: This KB describe the steps on how to decrypt the encryption at rest data on a Data Domain file system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Instructions
Data Domain file system has encryption at rest enabled. The steps of how to decrypt the encryption at rest data on a Data Domain file system.
From DD CLI:
- Disable encryption:
filesys encryption disable - Restart file system:
filesys restart - Export current encryption keys for record purpose:
filesys encryption keys export - Note current key IDs:
filesys encryption keys show - Mark the key for destroyed:
(xx = key ID returned from step 4)filesys encryption keys destroy xx - Apply the changes:
filesys encryption apply-changes - Start file system cleaning:
filesys clean start - Monitor GC status
filesys clean watch - Once GC is completed, the key state should change to the destroyed state. Verify by:
filesys encryption keys show - Delete the key:
(xx = key ID returned from step 4)filesys encryption keys delete xx
Affected Products
Data DomainProducts
Data Domain, Data Domain EncryptionArticle Properties
Article Number: 000019767
Article Type: How To
Last Modified: 22 نيسان 2026
Version: 4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.