Running this command against a particular disk takes effect immediately. However, the rekey throttle setting is effective for that disk only until the system is rebooted.
Before You Begin
To locate the disk number, run the hcl status command.
Summary ------------------------------------------------------------------------------- KeyControl: 10.238.67.241:443 KeyControl list: 10.238.67.241:443 10.238.67.242:443 Status: Connected Last heartbeat: Thu May 7 16:36:29 2020 (successful) AES_NI: enabled Device details ------------------------------------------------------------------------------- Drive Disk Part Cipher Status GUID ------------------------------------------------------------------------------- C: 0 2 none Avail-Sys N/A E: 1 1 AES-XTS-512 Attached 758704BF-8E41-4BED-AD8E-2753EED5F469
Procedure
- Log into the Windows VM as an administrator.
Enter the following command:
hcl set_rekey_throttle [DiskNumber] PendingIoCount PollInterval MaxWaitTimeWhere:
DiskNumberis the number of the disk whose configuration you want to set. The changes take effect immediately if a rekey operation is in progress, and are saved until the server is rebooted. If you want to set these values permanently for the VM, use theconfigoption.PendingIoCount—The background rekey task only runs if the number of pending I/O requests is less than this value. The default is 1, which means that Cryptographic Security Platform Vault will wait for the length of time specified inMaxWaitTimebefore it continues processing if there are any I/O requests on the server. If you want to remove all throttling, set this value to 0 (zero).We recommend that you only remove throttling if the server is not running any mission-critical applications or if you have four or more CPUs on your system. Even in these cases, we recommend that you monitor the disk performance during a rekey operation before you set this value to 0 in the default configuration.
PollIntervalis the number of seconds to wait before Cryptographic Security Platform Vault polls the queue to see if there are any pending I/O requests. The default is 1 second.MaxWaitTimeis the maximum number of seconds to wait before Cryptographic Security Platform Vault rekeys one block of data even if the pending I/O count exceeds the value set inPendingIoCount. This ensures that the rekey task will complete eventually with minimal impact to the applications running on the server. The default is 60 seconds.