Skip to main content
Install and maintain

Recable and give back the controller - AFF C30 and AFF C60

Contributors netapp-jsnyder

Give back the controller.

Give back the controller

Reset encryption if enabled and return the controller to normal operation.

No encryption
  1. From the LOADER prompt, enter boot_ontap.

  2. Press <enter> when console messages stop.

    • If you see the login prompt, go to the next step at the end of this section.

    • If you see Waiting for giveback, press the <enter> key, log into the partner node, and then go to the next step at the end of this section.

  3. Return the impaired controller to normal operation by giving back its storage: storage failover giveback -ofnode impaired_node_name

  4. If automatic giveback was disabled, reenable it: storage failover modify -node local -auto-giveback true

  5. If AutoSupport is enabled, restore/unsuppress automatic case creation: system node autosupport invoke -node * -type all -message MAINT=END

Onboard encryption (OKM)
  1. From the LOADER prompt, enter boot_ontap maint.

  2. Boot to the ONTAP menu from the LOADER prompt boot_ontap menu and select option 10.

  3. Enter the OKM passphrase.

    Note You are prompted twice for the passphrase.
  4. Enter the backup key data when prompted.

  5. At the boot menu, enter option 1 for normal boot.

  6. Press <enter> when Waiting for giveback is displayed.

  7. Move the console cable to the partner node and login as admin.

  8. Give back only the CFO aggregates (the root aggregate): storage failover giveback -fromnode local -only-cfo-aggregates true

  9. Wait 5 minutes after the giveback report completes, and check failover status and giveback status: storage failover show and storage failover show-giveback.

  10. Synchronize and verify status of the keys:

    1. Move the console cable back to the replacement controller.

    2. Synchronize missing keys: security key-manager onboard sync

      Note You are prompted for the cluster-wide passphrase of OKM for the cluster.
    3. Verify status of the keys: security key-manager key query -restored false

      The output should show no results when when properly synchronized.

      If the output shows results (the key IDs of keys that are not present in the system's internal key table), contact NetApp Support.

  11. Return the impaired controller to normal operation by giving back its storage: storage failover giveback -ofnode impaired_node_name

  12. If automatic giveback was disabled, reenable it: storage failover modify -node local -auto-giveback true

  13. If AutoSupport is enabled, restore/unsuppress automatic case creation: system node autosupport invoke -node * -type all -message MAINT=END

External key manager (EKM)
  1. If the root volume is encrypted with External Key Manager and the console cable is connected to the replacement node, enter boot_ontap menu and select option 11.

  2. Answer y or n to the following questions:

    Do you have a copy of the /cfcard/kmip/certs/client.crt file? {y/n}

    Do you have a copy of the /cfcard/kmip/certs/client.key file? {y/n}

    Do you have a copy of the /cfcard/kmip/certs/CA.pem file? {y/n}

    OR

    Do you have a copy of the /cfcard/kmip/servers.cfg file? {y/n}

    Do you know the KMIP server address? {y/n}

    Do you know the KMIP port? {y/n}

    Note Contact NetApp Support if you have issues.
  3. Supply the information for:

    • The client certificate (client.crt) file contents

    • The client key (client.key) file contents

    • The KMIP server CA(s) (CA.pem) file contents

    • The IP address for the KMIP server

    • The port for the KMIP server

  4. Once the system processes, you see the Boot Menu. Select '1' for normal boot.

  5. Check the takeover status: storage failover show

  6. Ensure any core dumps on the repaired node are saved by going to advanced mode set -privilege advanced and then run local partner nosavecore.

  7. Return the impaired controller to normal operation by giving back its storage: storage failover giveback -ofnode impaired_node_name

  8. If automatic giveback was disabled, reenable it: storage failover modify -node local -auto-giveback true

  9. If AutoSupport is enabled, restore/unsuppress automatic case creation: system node autosupport invoke -node * -type all -message MAINT=END