ONTAP 9 Manuals ( CA08871-402 )

ONTAP image validation

ONTAP provides mechanisms to ensure the ONTAP image is valid at upgrade and at boot time.

Upgrade image validation

Code signing helps verify that ONTAP images installed through nondisruptive image updates or automated nondisruptive image updates, and CLIs are authentically produced by our company and have not been tampered with.

This feature is a no-touch security enhancement to ONTAP upgrading or reversion. The user is not expected to do anything differently except for optionally verifying the top-level image.tgz signature.

Boot-time image validation

Unified Extensible Firmware Interface (UEFI) secure boot is enabled for ETERNUS AX2100, ETERNUS HX2200, and ETERNUS HX2100 series and subsequent next-generation systems that employ UEFI BIOS.

During power on, the bootloader validates the whitelist database of secure boot keys with the signature associated with each module that is loaded. After each module is validated and loaded, the boot process continues with the ONTAP initialization. If signature validation fails for any module, the system reboots.

These items apply to ONTAP images and the platform BIOS.
Top of Page