See below for the Linux-specific Policy Agent issues in 10.6.1.
- RHEL 10 root disk encryption requires Dropbear
- SUSE15 Dropbear and debug console configuration
- Amazon Linux 2 root drive encryption
- RHEL 8.5 DHCP root encryption requires dhclient
- RHEL 8 access control requires Python 3.9
- Do not revert a VM during a root-device rekey
- Update GRUB and shim before secure boot
- Red Hat 8 shim-x64 compatibility
- Azure RHEL 8.1 Gen 1 LVM root encryption
- BTRFS multiple-disk encryption
- Online rekey filesystem display after reboot
- Linux Access Controls on LVM devices
- AWS BIOS boot partition
- HTCrypt Driver during encryption operations
- HTCrypt Driver kernel taint message
- Access Control Policy filesystem support
- Rebuilding HTCrypt Driver after kernel package updates
- WebGUI root partition encryption
- Amazon and Azure root encryption boot disk swap
RHEL 10 root disk encryption requires Dropbear
Linux root disk encryption on RHEL 10 may fail because EPEL does not include Dropbear. To fix this issue:
- Manually install Dropbear using the following command:
yum install https://dl.fedoraproject.org/pub/epel/10.2/Everything/x86_64/Packages/d/dropbear-2025.88-1.el10_1.x86_64.rpm - Restart the root disk encryption script, htroot.
- When you are prompted to install Dropbear, select No.
SUSE15 Dropbear and debug console configuration
On SUSE15, either install dropbear manually or do not enable the debug console in the htroot setup.
Amazon Linux 2 root drive encryption
Root drive encryption does not work for Amazon Linux 2 AMI - Kernel 5.10.
RHEL 8.5 DHCP root encryption requires dhclient
For RHEL 8.5 and later, you must install "dhclient" to configure htroot with DHCP.
RHEL 8 access control requires Python 3.9
On RHEL 8. x machines, the Linux policy agent access control policy requires Python 3.9 or greater.
Do not revert a VM during a root-device rekey
Do not revert to a VM snapshot when a system/root device has a rekey in progress.
Update GRUB and shim before secure boot
Update the grub and shim packages before running "htdrv secure-boot".
Red Hat 8 shim-x64 compatibility
On Red Hat 8.x, the online encryption driver does not work with the default "shim-x64" package. To fix this issue, downgrade the shim-x64 package version to 15-11.
Azure RHEL 8.1 Gen 1 LVM root encryption
Root drive encryption is not supported in the RHEL 8.1 (LVM) - Gen 1 image on Azure.
BTRFS multiple-disk encryption
If you use BTRFS with multiple disks for root or any system mount, only the disk shown in /etc/fstab can be encrypted.
Online rekey filesystem display after reboot
If the VM is rebooted in the middle of an online rekey, the rekey completes successfully after the VM reboots. However, the lsblk -fs command no longer shows the correct file system for the clear text device. To fix this, the admin can run partprobe manually.
Linux Access Controls on LVM devices
Linux Access Controls is currently not supported on LVM devices. Users should refrain from applying Access Control Policy on LVM devices.
AWS BIOS boot partition
Linux Policy Agent on AWS will show the BIOS boot partition as an available device. This partition should not be encrypted.
HTCrypt Driver during encryption operations
Do not install the HTCrypt Driver on a VM if any device in the VM is being encrypted, rekeyed, or decrypted. If you do so, you will need to remove the HTCrypt Driver rpm before you can finish encrypting, rekeying, or decrypting the devices in the VM. After these processes finish, you can reinstall the HTCrypt Driver.
HTCrypt Driver kernel taint message
When the HTCrypt Driver is loaded, it may show the following kernel message: "htcrypt: loading out-of-tree module taints kernel". You can safely ignore this message because Entrust provides and supports the HTCrypt Driver.
Access Control Policy filesystem support
On Linux, you can't enforce an Access Control Policy on an encrypted disk unless it uses one of the supported filesystems.
Rebuilding HTCrypt Driver after kernel package updates
If the kernel-devel and kernel-headers packages are updated separately from the kernel package, then a reboot is required to rebuild the HTCrypt Driver for the updated kernel.
WebGUI root partition encryption
Encryption of the Linux root partition from the Cryptographic Security Platform Vault webGUI using the Encrypt Disk action is not supported.
Amazon and Azure root encryption boot disk swap
The Linux Policy Agent in Amazon and Azure requires a manual swap of boot and root disks for root encryption before rebooting. See the Administration Guide for more information.