1. For Linux, log into the VM as root. For Windows, log in as a System Administrator and open a Command Prompt or start Windows PowerShell.
  2. Run the hcl status command.

    Example: 
    # hcl status
    
    Summary
    --------------------------------------------------------------------------------
    KeyControl: 10.1.228.10:443
    KeyControl list: 10.1.228.10:443
    Vault ID: 6971c6a2-48c5-4dfa-9234-198ffcaa3999
    Status: Connected
    Last heartbeat: Fri Feb 16 13:00:28 2024 (successful)
    AES_NI: enabled
    Certificate Expiration: Feb 15 18:51:17 2025 GMT
    HTCRYPT: enabled
    
    Registered Devices
    --------------------------------------------------------------------------------
    Disk Name          Cipher       Status                   Clear
    --------------------------------------------------------------------------------
    sdb1               AES-XTS-512-FIPS Attached (RK 15.67%)     /dev/mapper/clear_sdb1
    '--> auto_attach=ENABLED, attach_handler=DEFAULT, detach_handler=DEFAULT, 
    
    Available Devices
    --------------------------------------------------------------------------------
    Disk Name            Device Node                      Size (in MB)
    --------------------------------------------------------------------------------
    sde7                 /dev/sde7                        580
    sdc1                 /dev/sdc1                        118
    							
    Other Devices
    --------------------------------------------------------------------------------
    Disk Name            Device Node                      Status
    --------------------------------------------------------------------------------
    sda2                 /dev/sda2                        Mounted (/)
    
    

    Note: In this example, sbd1 is currently being encrypted.

    The VM status can be one of the following:

    • Not registered — The Policy Agent software is installed but the VM has not yet been registered with Cryptographic Security Platform Vault.
    • Connected — The VM can communicate with the Cryptographic Security Platform Vault for VM Encryption and everything is running normally.
    • Could not connect — The Cryptographic Security Platform Vault for VM Encryption is not reachable. If this condition continues, the VM will need to be re-authenticated with the Cryptographic Security Platform Vault for VM Encryption when communication is re-established.
    • Need to update certificate — The certificate for the is VM is no longer valid and should be updated.
    • Reauth needed — The VM needs to be re-authenticated.
    • Virtual Machine not authenticated — VM permissions have been revoked from the Cryptographic Security Platform Vault for VM Encryption. To fix this issue, see Reactivating a Revoked Disk.
    • Identity verification failed — Permissions are not available because the VM heartbeat has timed out or its IP address or hardware signature has changed. This can occur if you have changed the IP address on a VM or copied the VM to a new server.
    • Unknown error from KeyControl cluster — An unknown error has occurred. Please contact Support if you see this message.