Appendix F: Troubleshooting
Reset DSM Appliance and Remove All Data
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
175
1. Log on to the DSM CLI console using the CLI Administrator credentials.
2. To enter the maintenance menu, type:
$ maintenance
3. Reset the configuration, type:
0001:maintenance$ config reset
System Response
Reset configuration will wipe out all the configuration data and set the configuration data
to the manufacture default.
System will reboot automatically.
Continue? (yes|no)[no]:yes
config reset SUCCESS.
You can reboot the Security Server now or it will reboot automatically in 60 seconds.
0002:maintenance$
Regenerating the DSM certificate authority
You will need to generate the DSM certificate authority (CA) again. This will require a quorum from the original ACS
used to create the Security World. Wait until the system has rebooted and the
vormetric$
prompt is displayed, then
run the
security genca
command.
1. Type
up
at the prompt to return to the main menu.
2. Type
system
to access the System category sub-menu.
3. To generate the CA, type:
0004:system$ security genca
System Response
WARNING: All Agents and Peer node certificates will need to be re-signed after CA and
server certificate regenerated, and the security server software will be restarted
automatically!
Continue? (yes|no)[no]:yes
4. The following message displays. Read it, enter the required information to generate the CA, and ensure the DSM
host name is correct, press enter:
This node may have multiple IP addresses. All the agents will have to connect to Security
Server using same IP.
Enter the host name of this node. This will be used by Agents to talk to this Security
Server.
This Security Server host name[mycompany.com]:
Please enter the following information for key and certificate generation.
What is the name of your organizational unit? []:
What is the name of your organization? []:
What is the name of your City or Locality? []:
What is the name of your State or Province? []:
What is your two-letter country code? [US]:
What is your email address? []:
What is the validity period of the generated certificate (from 2 to 10 years)? [10]:
Regenerating the CA and server certificates now...