NetApp AFF A200 System Documentation page 9

Ontap systems
Hide thumbs Also See for AFF A200:
Table of Contents

Advertisement

If the command fails, contact NetApp Support.
mysupport.netapp.com
b. Verify that the
Restored
display available:
c. Shut down the impaired node.
3. If you saw the message This command is not supported when onboard key management is enabled,
display the keys stored in the onboard key manager:
a. If the
Restored
▪ Go to advanced privilege mode and enter
▪ Enter the command to display the OKM backup information:
show
▪ Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ Shut down the impaired node.
b. If the
Restored
▪ Run the key-manager setup wizard:
target/impaired node name
▪ Verify that the
manager key show -detail
▪ Go to advanced privilege mode and enter
▪ Enter the command to backup the OKM
▪ Copy the contents of the backup information to a separate file or your log. You'll need it in disaster
scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ You can safely shutdown the node.
Option 2: Checking NVE or NSE on systems running ONTAP 9.6 and later
Before shutting down the impaired node, you need to verify whether the system has
either NetApp Volume Encryption (NVE) or NetApp Storage Encryption (NSE) enabled. If
so, you need to verify the configuration.
1. Verify whether NVE is configured for any volumes in the cluster:
6
column displays
security key-manager query
column displays yes, manually backup the onboard key management information:
set -priv admin
column displays anything other than yes:
Enter the customer's OKM passphrase at the prompt. If the passphrase cannot be
provided, contact
mysupport.netapp.com
column shows
Restored
Make sure that OKM information is saved in your log file. This info will be needed in
disaster scenarios where OKM might need to be manually recovered.
set -priv admin
for all authentication keys and that all key managers
yes
security key-manager key show -detail
when prompted to continue:
y
security key-manager setup -node
for all authentication keys:
yes
when prompted to continue:
y
information:security key-manager backup show
volume show -is-encrypted true
set -priv advanced
security key-manager backup
security key-
set -priv advanced

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the AFF A200 and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents