Disks are encrypted with a key created and safeguarded by Cryptographic Security Platform Vault. If the key is lost, the encrypted data on the disk cannot be accessed because it cannot be decrypted. When a disk is rekeyed, each block of data is decrypted using the old key and then re-encrypted using the new key.
You should immediately rekey a disk if you believe there has been a security breach. As a precaution, you can also have Cryptographic Security Platform Vault rekey all or selected disks in the system on a periodic basis. The trade off is in performance—rekeying a disk increases the security but takes system resources and may adversely affect the applications running on the server that is being rekeyed.
Important: After you rekey one or more disks, you should create a new Cryptographic Security Platform Vault backup file that contains the new keys. If you restore Cryptographic Security Platform Vault from a backup file made before the disks were rekeyed, the new keys will be lost and you will not be able to access the encrypted data.
This section includes: