Changing the onboard key management passphrase
It is a security best practice to change the onboard key management passphrase periodically. You should copy the new onboard key management passphrase to a secure location outside the storage system for future use.
Before you begin
You must be a cluster or SVM administrator to perform this task.
Advanced privileges are required for this task.
After you finish
In a MetroCluster environment, you must update the passphrase on the partner cluster:
In ONTAP 9.5 and earlier, you must run security key-manager update-passphrase with the same passphrase on the partner cluster.
In ONTAP 9.6 and later, you are prompted to run security key-manager onboard sync with the same passphrase on the partner cluster.
You should copy the onboard key management passphrase to a secure location outside the storage system for future use.
You should back up key management information manually whenever you change the onboard key management passphrase.