跳转到主内容

丢失 FIPS 身份验证密钥后,如何将 SED 恢复到出厂配置的设置

Views:
74
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core
Last Updated:

适用于

  • ONTAP 9
  • NetApp Storage Encryption (NSE)
  • FIPS 驱动器
  • SED 驱动器
  • 驱动器上设置的 FIPS 140-2 认证密钥

说明

  • SED 驱动器显示不支持的容器类型,无法从 nodeshell 显示磁盘,因为 SED 驱动器具有带电源循环保护的身份验证密钥,并且解锁驱动器所需的身份验证密钥丢失。
  • 如果您永久丢失了 FIPS 驱动器或 SED 的身份验证密钥,并且无法从 KMIP 服务器检索它们,系统会将其视为已损坏。
  • 虽然您无法访问或恢复磁盘上的数据,但您可以采取措施,通过将 SED 驱动器恢复到 MSID 为 0x0 的制造状态,使 SED 的未使用空间再次可用于数据。
Clustershell 输出

Cluster::>storage disk show -container-type unsupported

          Usable             Disk    Container
Disk         Size      Shelf   Bay   Type    Type   
1.0.7        -        0   7   unknown  unsupported

Cluster::>storage encryption disk show -fields data-key-id,fips-key-id

disk   data-key-id  fips-key-id
1.0.7  n/a      n/a

 

维护模式输出

*>disk show -v

0d.11.9     FAILED
0d.11.14    FAILED

*>sysconfig -v

10.1 : NETAPP   X358_TPM5V3T8ATE NA55   0.0GB (0 520B/sect) (Startup failed.)

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.