▪ Verify that the
manager key show -detail
▪ Go to advanced privilege mode and enter
advanced
▪ Enter the command to display the OKM backup information:
backup show
▪ Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
▪ Return to admin mode:
▪ You can safely shutdown the controller.
== Verify NSE configuration
.Steps
. Display the key IDs of the authentication keys that are stored on the key management servers:
security key-manager query
If the
column displays
Restored
down the impaired controller.
If the
column displays anything other than yes, or if any key manager displays unavailable,
Restored
you need to complete some additional steps.
** If you see the message This command is not supported when onboard key management is enabled,
you need to complete some other additional steps
. If the
column displayed anything other than yes, or if any key manager displayed
Restored
unavailable:
.. Retrieve and restore all authentication keys and associated key IDs:
restore -address *
+
If the command fails, contact NetApp Support.
+
mysupport.netapp.com
a. Verify that the
Restored
display available:
b. Shut down the impaired controller.
1. If you saw the message This command is not supported when onboard key management is
enabled, display the keys stored in the onboard key manager:
show -detail
c. If the
column displays yes, manually back up the onboard key management information:
Restored
◦ Go to advanced privilege mode and enter
◦ Enter the command to display the OKM backup information:
show
◦ Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
◦ Return to admin mode:
◦ Shut down the impaired controller.
Restored
column displays
set -priv admin
and all key managers display available, it's safe to shut
yes
column displays
yes
security key-manager query
set -priv admin
yes
for all authentication key:
when prompted to continue:
y
security key-manager
security key-manager
for all authentication keys and that all key managers
security key-manager key
when prompted to continue:
y
security key-manager backup
security key-
set -priv
set -priv advanced
223
Need help?
Do you have a question about the ASA C Series and is the answer not in the manual?