Data Domain: Cloud DDVE system recovery fails due to old encryption key format
Summary: This article explains an issue with the Data Domain Virtual Edition (DDVE) system recovery function caused by a different encryption key format between the old and new systems.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
DDVE has a system recovery option that allows restoration of the file system and its configuration. It returns the system to its prior operational condition using a new DDVE deployment if the original DDVE develops issues with its root disk or metadata disks.
Prior to
DDOS 7.6.x, the system recovery option requires exactly the same DDOS build version to restore the file system and its configuration.
With
DDOS 7.6.x and later, this is no longer required to recover the system. This was changed to allow customers to recover systems with older DDOS versions that may no longer be available on the cloud provider's marketplace for new deployment. The system recovery may fail if the file system was encrypted with an older key format.
Example:
DDOS version
- Original system:
DDOS 7.1.0.40 - New system:
DDOS 7.6.0.7
sysadmin@dd01# system recovery precheck from object-store
Recovery precheck passed. Use start command to start the recovery.
sysadmin@dd01# system recovery start from object-store
This command runs the system recovery.
It restores the filesystem, its configurations and returns the system
back to its prior operational conditions. The system will be rebooted
before resuming normal operations.
Are you sure? (yes|no) [no]: yes
ok, proceeding.
Please enter sysadmin password to confirm 'system recovery':
System recovery has started. Use status command to check the status.
sysadmin@dd01# system recovery status
System recovery is running: stage 2 of 6 (attaching object-store).
root@dd01# system recovery status
System recovery is running: stage 5 of 6 (rebooting system).
Broadcast message from root (Mon May 31 18:24:11 2021):
The system is going down for reboot NOW!
Status after reboot:
sysadmin@dd01# system recovery status
System recovery completed on Mon May 31 18:37:47 2021.
sysadmin@dd01# filesys status
The filesystem is starting. This may take some time.
File system enable fails with the following status:
sysadmin@dd01# filesys status
**** There was a problem bringing up the filesystem. Status: The filesystem is disabled and shutdown. [too many relaunches]Cause
In
DDOS 7.5.x and later, a new BSAFE encryption key format was introduced to enhance system security.
During a normal DDOS upgrade, the system automatically upgrades the old encryption key to the new format. However, the upgrade workflow for the encryption key is not included in the system recovery process.
Resolution
Data Domain Engineering is working on an enhancement that allows the system recovery process to update file system encryption keys. This will be available in a future DDOS release.
If your system encounters the above symptoms, contact your contracted support provider to obtain a workaround and restore the file system and its configuration.
Affected Products
Data DomainArticle Properties
Article Number: 000191517
Article Type: Solution
Last Modified: 18 يونيو 2026
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.