Running this command against a particular disk takes effect immediately. However, the rekey throttle setting is effective for that disk only until the system is rebooted.

Before You Begin 

To locate the disk number, run the hcl status command.

Summary
-------------------------------------------------------------------------------
KeyControl: 10.238.67.241:443
KeyControl list: 10.238.67.241:443 10.238.67.242:443
Status: Connected
Last heartbeat: Thu May  7 16:36:29 2020 (successful)
AES_NI: enabled

Device details
-------------------------------------------------------------------------------
Drive      Disk Part Cipher      Status    GUID
-------------------------------------------------------------------------------
C:         0    2    none        Avail-Sys N/A
E:         1    1    AES-XTS-512 Attached  758704BF-8E41-4BED-AD8E-2753EED5F469

Procedure 

  1. Log into the Windows VM as an administrator.
  2. Enter the following command:

    hcl set_rekey_throttle [DiskNumber] PendingIoCount PollInterval MaxWaitTime

    Where:

    • DiskNumber is the number of the disk whose configuration you want to set. The changes take effect immediately if a rekey operation is in progress, and are saved until the server is rebooted. If you want to set these values permanently for the VM, use the config option.
    • PendingIoCount—The background rekey task only runs if the number of pending I/O requests is less than this value. The default is 1, which means that Cryptographic Security Platform Vault will wait for the length of time specified in MaxWaitTime before it continues processing if there are any I/O requests on the server. If you want to remove all throttling, set this value to 0 (zero).

      We recommend that you only remove throttling if the server is not running any mission-critical applications or if you have four or more CPUs on your system. Even in these cases, we recommend that you monitor the disk performance during a rekey operation before you set this value to 0 in the default configuration.

    • PollInterval is the number of seconds to wait before Cryptographic Security Platform Vault polls the queue to see if there are any pending I/O requests. The default is 1 second.
    • MaxWaitTime is the maximum number of seconds to wait before Cryptographic Security Platform Vault rekeys one block of data even if the pending I/O count exceeds the value set in PendingIoCount. This ensures that the rekey task will complete eventually with minimal impact to the applications running on the server. The default is 60 seconds.