Online volume encryption at rest

Last published : Jun 12, 2026
Volume Manager (VxVM) provides the online volume encryption at rest feature that lets you migrate unencrypted volumes to encrypted ones. Using this feature a volume can be migrated without application downtime, that is, while the file system is mounted and the I/Os are running. It also avoids complexities, like having to modify application configurations, and has a controlled impact on the application I/O performance.
The online migration process involves mirroring the existing storage configured under a volume, which requires an equal amount of additional storage that gets used in the background.
Online migration involves the Start phase, in which the process is initiated, and the Commit phase, in which the background changes made to the volume are finalized. The unencrypted volume is migrated to an encrypted one when both these phases are completed successfully.
After the Start phase is complete and before you can initiate the Commit phase, you can abort the migration or switch plexes. The switching of reads between the source (unencrypted) plex and the target (unencrypted) plex helps verify the data copied during the Start phase. Meanwhile, the writes continue to happen on both the plexes.
Note: After the online migration is committed successfully, volume encryption cannot be disabled.
Limitations:
  • Online migration is not supported in the following cases:
    • RAID 5 volumes
    • Volumes with mixed layouts
    • Volumes configured for VVR replication
  • Online migration cannot be initiated on an unencrypted volume when SecureFS is enabled. Also, SecureFS cannot be enabled on a volume while online migration is in progress; it can be done only after the migration process is committed successfully.
  • Only one online migration can be performed on an unencrypted volume at a time.
You can use either the VEA GUI or VxVM commands to migrate unencrypted volumes to encrypted ones. For details, refer to the Storage Foundation Administrator's Guide - Windows.
Alternatively, you can use the Management Server console of InfoScale Operations Manager. For details, refer to the InfoScale Operations Manager User's Guide.