Enabling encryption on an existing volume with the volume move start command
You can use the volume move start command to enable encryption by moving an existing volume. You can use the same aggregate or a different aggregate.
Before you begin
You must be a cluster administrator to perform this task, or an SVM administrator to whom the cluster administrator has delegated authority.
About this task
You cannot use volume move start to enable encryption on a SnapLock or FlexGroup volume.
If you enable cc-mode
when you set up the Onboard Key Manager, volumes you create with the volume move start command are automatically encrypted. You need not specify -encrypt-destination true.
Starting with ONTAP 9.6, you can use aggregate-level encryption to assign keys to the containing aggregate for the volumes to be moved. A volume encrypted with a unique key is called an LVE volume. A volume encrypted with an aggregate-level key is called an LAE volume (for Lenovo Aggregate Encryption). Plaintext volumes are not supported in LAE aggregates.
Result
If you are using a KMIP server to store the encryption keys for a node, ONTAP automaticallypushesan encryption key to the server when you encrypt a volume.