Accessing the root shell in lockdown mode
If your appliance is in lockdown mode and you need assistance from Veritas Support, you need to generate a One-Time Password (OTP) to allow your representative to access the root shell. The OTP has a two-hour expiration period, after which you need to generate the OTP again; so make sure that you have opened a support case with Veritas Support and your support representative is ready before you generate the OTP.
To access the root shell when the appliance is in lockdown mode:
- From any one of the nodes in the cluster, log in to Veritas Appliance Shell menu.
- Run the support generate-otp command to generate the OTP. A 10-digit number, which is the OTP, is displayed as shown in the following example:
[access 8.0] appnode-01 > support generate-otp One-time password: 3279459335 Operation completed successfully
- Mention the OTP in the support case. If you forget the OTP, you can use the support show-otp command to view it again. Your support representative uses this OTP to generate a security key, which you later need to specify when prompted.
- When your representative asks you to, enter the support unlock command. You are prompted for the security key, which your representative must generate using the OTP. Enter the security key and press Enter.
- To get root access for the current node, run the support elevate command. The other node remains locked. Enter the passphrase, which your representative specified while generating the security key. Press Enter.
- Enter the maintenance password to access the root shell.
- When your support representative is done troubleshooting the issue, enter the support lock command to close root access to the node. Root access to the node is closed automatically after 12 hours and all root sessions are terminated.