◦ If you see the message This command is not supported when onboard key management is enabled,
you need to complete some other additional steps
2. If the
column displayed anything other than yes, or if any key manager displayed
Restored
unavailable:
a. Retrieve and restore all authentication keys and associated key IDs:
restore -address *
If the command fails, contact NetApp Support.
mysupport.netapp.com
b. Verify that the
Restored
display available:
c. Shut down the impaired node.
3. If you saw the message This command is not supported when onboard key management is enabled,
display the keys stored in the onboard key manager:
a. If the
Restored
▪ Go to advanced privilege mode and enter
▪ Enter the command to display the OKM backup information:
show
▪ Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ Shut down the impaired node.
b. If the
Restored
▪ Run the key-manager setup wizard:
target/impaired node name
Enter the customer's OKM passphrase at the prompt. If the passphrase cannot be
provided, contact
▪ Verify that the
manager key show -detail
▪ Go to advanced privilege mode and enter
▪ Enter the command to backup the OKM
Make sure that OKM information is saved in your log file. This info will be needed in
disaster scenarios where OKM might need to be manually recovered.
▪ Copy the contents of the backup information to a separate file or your log. You'll need it in disaster
scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ You can safely shutdown the node.
column displays
security key-manager query
column displays yes, manually backup the onboard key management information:
set -priv admin
column displays anything other than yes:
security key-manager setup -node
mysupport.netapp.com
column shows
Restored
set -priv admin
for all authentication keys and that all key managers
yes
security key-manager key show -detail
when prompted to continue:
y
security key-manager backup
for all authentication keys:
yes
when prompted to continue:
y
information:security key-manager backup show
security key-manager
set -priv advanced
security key-
set -priv advanced
849
Need help?
Do you have a question about the AFF A200 and is the answer not in the manual?