Troubleshooting KeyControl from the Bootloader

If KeyControl requires master key recovery or if the startup passphrase is set, then admin input is required during boot to unlock the root volume. When this happens, the KeyControl webGUI displays the System Recovery dialog box, which is similar to the System Recovery Options dialog box. For more details, see Recovering Access to KeyControl

If you cannot recover your system, then you need to use the KeyControl Bootloader System Console to troubleshoot your issues. You can access the Bootloader System Console from either the KeyControl VM console or by using an SSH connection to your KeyControl IP address. You must log in as htadmin.

Note: If you log in using the VM console, you will see the following text. Enter y to start the System Console

Please recover KeyControl System Keys from WebGUI.

KeyControl System Keys are not accessible.

Do you want to start KeyControl System Console? (y/n): y

Important: If you access the System Console using the VM console, and then successfully recover your system, you must quit the TUI before the VM boot will proceed. This does not apply if you access the System Console over SSH.

After you have logged in, you will see the following: 

Option

Name

Description

1 

Show HT encryption log file

Displays the log generated during boot for encryption or rekey. Run this command if requested by Support.

2 

Set htsupport password

Enable the full support login account (htsupport). Enter the password and then confirm the password to enable.

3 

Show currently configured network

Displays the current network addresses and routes for your KeyControl node. If you set a temporary network, it displays the information for the new network.

4 

Show KeyControl network parameters

Displays the network configuration parameters currently configured for your KeyControl node. This includes IP address, netmask, gateway, DNS address, and domain name.

5 

Restart KeyControl network

Automatically restarts the KeyControl networking service .

6 

Set temporary network

Create a temporary network for your KeyControl node. This command prompts for the network interface name, IP address, netmask, gateway, DNS address, and domain name. You can also enable DHCP.

7 

Show temporary network

Displays the temporary network that you created. This includes the network interface name and MAC address, IP address, netmask, gateway, DNS address, and domain name.

8 

Quit TUI Session

Close the System Console and return to the prompt.