Download Print this page

NetApp AFF A200 Manual page 7

Ontap systems
Hide thumbs Also See for AFF A200:

Advertisement

3. If you saw the message This command is not supported when onboard key management is enabled,
display the keys stored in the onboard key manager:
a. If the
Restored
▪ Go to advanced privilege mode and enter
▪ Enter the command to display the OKM backup information:
show
▪ Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ Shut down the impaired controller.
b. If the
Restored
▪ Run the key-manager setup wizard:
target/impaired node name
▪ Verify that the
manager key show -detail
▪ Go to advanced privilege mode and enter
▪ Enter the command to back up the OKM information:
▪ Copy the contents of the backup information to a separate file or your log. You'll need it in disaster
scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ You can safely shut down the controller.
Option 2: Checking NVE or NSE on systems running ONTAP 9.6 and later
Before shutting down the impaired controller, you need to verify whether the system has either NetApp Volume
Encryption (NVE) or NetApp Storage Encryption (NSE) enabled. If so, you need to verify the configuration.
1. Verify whether NVE is in use for any volumes in the cluster:
If any volumes are listed in the output, NVE is configured and you need to verify the NVE configuration. If
no volumes are listed, check whether NSE is configured and in use.
2. Verify whether NSE is configured and in use:
◦ If the command output lists the drive details with Mode & Key ID information, NSE is configured and
you need to verify the NSE configuration and in use.
◦ If no disks are shown, NSE is not configured.
column displays yes, manually back up the onboard key management information:
set -priv admin
column displays anything other than yes:
Enter the customer's OKM passphrase at the prompt. If the passphrase cannot be
provided, contact
mysupport.netapp.com
column shows
Restored
Make sure that OKM information is saved in your log file. This information will be
needed in disaster scenarios where OKM might need to be manually recovered.
set -priv admin
security key-manager key show -detail
when prompted to continue:
y
security key-manager setup -node
for all authentication keys:
yes
when prompted to continue:
y
security key-manager backup show
volume show -is-encrypted true
storage encryption disk show
set -priv advanced
security key-manager backup
security key-
set -priv advanced
5

Advertisement

loading
Need help?

Need help?

Do you have a question about the AFF A200 and is the answer not in the manual?

Subscribe to Our Youtube Channel