• If the KeyManager type displays onboard and the Restored column displays yes , you need to
complete some additional steps.
• If the
KeyManager type displays external and the Restored column displays anything other than yes ,
you need to complete some additional steps.
• If the
KeyManager type displays external and the Restored column displays anything other than yes ,
you need to complete some additional steps.
Step 2. If the
KeyManager type displays onboard and the Restored column displays yes , manually backup the
OKM information:
a. Go to advanced privilege mode and enter
y when prompted to continue: set -priv advanced
b. Enter the command to display the key management information: security key-manager onboard
show-backup
c. Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
d. Return to admin mode: set -priv admin
e. You can safely shutdown the node.
Step 3. If the
KeyManager type displays external and the Restored column displays anything other than yes :
a. Enter the onboard security key-manager sync command:
security key-manager external syncIf the
command fails, contact Lenovo Support.
https://datacentersupport.lenovo.com/
b. Verify that the Restored column equals yes for all authentication keys: security key-manager key
query
c. You can safely shutdown the node.
Step 4. If the
KeyManager type displays onboard and the Restored column displays anything other than yes :
a. Enter the onboard security key-manager sync command:
security key-manager onboard syncEnter
the customer's onboard key management passphrase at the prompt. If the passphrase cannot
be provided, contact Lenovo Support.
https://datacentersupport.lenovo.com/
b. Verify the Restored column shows yes for all authentication keys: security key-manager key query
c. Verify that the
KeyManager type shows onboard , manually backup the OKM information.
d. Go to advanced privilege mode and enter y when prompted to continue: set -priv advanced
e. Enter the command to display the key management backup information: security key-manager
onboard show-backup
f. Copy the contents of the backup information to a separate file or your log file. You'll need it in
disaster scenarios where you might need to manually recover OKM.
g. Return to admin mode: set -priv admin
h. You can safely shutdown the node.
Shutting down the impaired controller
You can shut down or take over the impaired controller using different procedures, depending on the storage
system hardware configuration.
Completing node shutdown
After completing the LVE or Lenovo Storage Encryption (LSE) tasks, you need to complete the shutdown of
the impaired node.
50
ThinkSystem DG5000 Hardware Installation and Maintenance Guide