◦ If NVE and NSE are not configured, it's safe to shut down the impaired controller.
== Verify NVE configuration
Steps
1. Display the key IDs of the authentication keys that are stored on the key management servers:
security key-manager query
◦ If the
Restored
down the impaired controller.
◦ If the
Restored
unavailable, you need to complete some additional steps.
◦ If you see the message This command is not supported when onboard key management is
enabled, you need to complete some other additional steps.
2. If the
column displayed anything other than yes, or if any key manager displayed
Restored
unavailable:
a. Retrieve and restore all authentication keys and associated key IDs:
restore -address *
If the command fails, contact NetApp Support.
mysupport.netapp.com
b. Verify that the
managers display available:
c. Shut down the impaired controller.
3. If you saw the message This command is not supported when onboard key management is enabled,
display the keys stored in the onboard key manager:
-detail
a. If the
Restored
information:
▪ Go to advanced privilege mode and enter
advanced
▪ Enter the command to display the OKM backup information:
backup show
▪ Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ Shut down the impaired controller.
b. If the
Restored
▪ Run the key-manager setup wizard:
target/impaired node name
222
column displays
yes
column displays anything other than yes, or if any key manager displays
column displays
Restored
security key-manager query
column displays
yes
set -priv admin
column displays anything other than yes:
Enter the customer's onboard key management passphrase at the prompt. If
the passphrase cannot be provided, contact
and all key managers display available, it's safe to shut
for all authentication keys and that all key
yes
security key-manager key show
manually back up the onboard key management
when prompted to continue:
y
security key-manager setup -node
mysupport.netapp.com
security key-manager
set -priv
security key-manager
Need help?
Do you have a question about the ASA C Series and is the answer not in the manual?