ONTAP 9.13

to Japanese version

Restore onboard key management encryption keys

The procedure you follow to restore your onboard key management encryption keys varies based on your version of ONTAP.

Before you begin

ONTAP 9.8 and later with encrypted root volume

If you are running ONTAP 9.8 or later and your root volume is not encrypted, follow the procedure for ONTAP 9.6 or later.

If you are running ONTAP 9.8 and later, and your root volume is encrypted, you must set an onboard key management recovery passphrase with the boot menu. This process is also necessary if you do a boot media replacement.

  1. Boot the node to the boot menu and select option (10) Set onboard key management recovery secrets.

  2. Enter y to use this option.

  3. At the prompt, enter the onboard key management passphrase for the cluster.

  4. At the prompt, enter the backup key data.

    The node returns to the boot menu.

  5. From the boot menu, select option (1) Normal Boot.

Steps for ONTAP 9.7 and later

  1. Verify that the key needs to be restored:
    security key-manager key query -node node

  2. Restore the key:
    security key-manager onboard sync

    For complete command syntax, see the man pages.

    The following ONTAP 9.7 command synchronize the keys in the onboard key hierarchy:

    cluster1::> security key-manager onboard sync
    
    Enter the cluster-wide passphrase for onboard key management in Vserver "cluster1"::    <32..256 ASCII characters long text>
  3. At the passphrase prompt, enter the onboard key management passphrase for the cluster.

Top of Page