f. Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
g. Return to admin mode:
h. You can safely shut down the controller.
== Verify NSE configuration
1. Display the key IDs of the authentication keys that are stored on the key management servers:
security key-manager key query -key-type NSE-AK
After the ONTAP 9.6 release, you may have additional key manager types. The types
are KMIP, AKV, and GCP. The process for confirming these types is the same as
confirming
◦ If the
Key Manager
to shut down the impaired controller.
◦ If the
Key Manager
to complete some additional steps.
◦ If the
Key Manager
than yes, you need to complete some additional steps.
◦ If the
Key Manager
than yes, you need to complete some additional steps.
2. If the
Key Manager
up the OKM information:
a. Go to advanced privilege mode and enter
b. Enter the command to display the key management information:
onboard show-backup
c. Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
d. Return to admin mode:
e. You can safely shut down the controller.
3. If the
Key Manager
than yes:
a. Restore the external key management authentication keys to all nodes in the cluster:
key-manager external restore
If the command fails, contact NetApp Support.
mysupport.netapp.com
b. Verify that the
manager key query
c. You can safely shut down the controller.
4. If the
Key Manager
yes:
226
set -priv admin
or
external
onboard
type displays
external
type displays
onboard
type displays
external
type displays
external
type displays
onboard
set -priv admin
type displays
external
column equals
Restored
type displays
onboard
key manager types.
and the
Restored
and the
Restored
and the
Restored
and the
Restored
and the
column displays yes, manually back
Restored
when prompted to continue:
y
and the
column displays anything other
Restored
for all authentication keys:
yes
and the
column displays anything other than
Restored
column displays yes, it's safe
column displays yes, you need
column displays anything other
column displays anything other
set -priv advanced
security key-manager
security
security key-
Need help?
Do you have a question about the ASA C Series and is the answer not in the manual?