Before you begin
Reverting security hardening requires root privileges and can be performed only through the command-line interface. To log in as the root user on a hardened cluster, you must connect through a serial console session. Root SSH is not allowed on a hardened cluster.
You must have an active security hardening license to revert a hardening profile on OneFS. To obtain a license, contact your Isilon sales representative.
Procedure
- Open a serial console session on any node in the cluster and log in as root.
- Run the
isi hardening revert command.
OneFS checks whether the system is in an expected state.
- Resolve any configuration issues. At the prompt
Do you want to resolve the issue(s)?[Y/N], choose one of the following actions:
- To allow OneFS to resolve all issues, type
Y. OneFS sets the affected configurations to the expected state and then reverts the hardening profile.
- To defer resolution and fix all of the found issues manually, type
N. OneFS halts the revert process until all of the issues are fixed. After you have fixed all of the deferred issues, run the
isi hardening revert command again.
If OneFS encounters an issue that is considered catastrophic, the system will prompt you to resolve the issue manually. OneFS cannot resolve a catastrophic issue.