See below for the Linux-specific Policy Agent issues in 10.6.1.

RHEL 10 root disk encryption requires Dropbear

Linux root disk encryption on RHEL 10 may fail because EPEL does not include Dropbear. To fix this issue:

  1. Manually install Dropbear using the following command:
    yum install https://dl.fedoraproject.org/pub/epel/10.2/Everything/x86_64/Packages/d/dropbear-2025.88-1.el10_1.x86_64.rpm
  2. Restart the root disk encryption script, htroot.
  3. When you are prompted to install Dropbear, select No.

SUSE15 Dropbear and debug console configuration

On SUSE15, either install dropbear manually or do not enable the debug console in the htroot setup.

Amazon Linux 2 root drive encryption

Root drive encryption does not work for Amazon Linux 2 AMI - Kernel 5.10.

RHEL 8.5 DHCP root encryption requires dhclient

For RHEL 8.5 and later, you must install "dhclient" to configure htroot with DHCP.

RHEL 8 access control requires Python 3.9

On RHEL 8. x machines, the Linux policy agent access control policy requires Python 3.9 or greater.

Do not revert a VM during a root-device rekey

Do not revert to a VM snapshot when a system/root device has a rekey in progress.

Update GRUB and shim before secure boot

Update the grub and shim packages before running "htdrv secure-boot".

Red Hat 8 shim-x64 compatibility

On Red Hat 8.x, the online encryption driver does not work with the default "shim-x64" package. To fix this issue, downgrade the shim-x64 package version to 15-11.

Azure RHEL 8.1 Gen 1 LVM root encryption

Root drive encryption is not supported in the RHEL 8.1 (LVM) - Gen 1 image on Azure.

BTRFS multiple-disk encryption

If you use BTRFS with multiple disks for root or any system mount, only the disk shown in /etc/fstab can be encrypted.

Online rekey filesystem display after reboot

If the VM is rebooted in the middle of an online rekey, the rekey completes successfully after the VM reboots. However, the lsblk -fs command no longer shows the correct file system for the clear text device. To fix this, the admin can run partprobe manually.

Linux Access Controls on LVM devices

Linux Access Controls is currently not supported on LVM devices. Users should refrain from applying Access Control Policy on LVM devices.

AWS BIOS boot partition

Linux Policy Agent on AWS will show the BIOS boot partition as an available device. This partition should not be encrypted.

HTCrypt Driver during encryption operations

Do not install the HTCrypt Driver on a VM if any device in the VM is being encrypted, rekeyed, or decrypted. If you do so, you will need to remove the HTCrypt Driver rpm before you can finish encrypting, rekeying, or decrypting the devices in the VM. After these processes finish, you can reinstall the HTCrypt Driver.

HTCrypt Driver kernel taint message

When the HTCrypt Driver is loaded, it may show the following kernel message: "htcrypt: loading out-of-tree module taints kernel". You can safely ignore this message because Entrust provides and supports the HTCrypt Driver.

Access Control Policy filesystem support

On Linux, you can't enforce an Access Control Policy on an encrypted disk unless it uses one of the supported filesystems.

Rebuilding HTCrypt Driver after kernel package updates

If the kernel-devel and kernel-headers packages are updated separately from the kernel package, then a reboot is required to rebuild the HTCrypt Driver for the updated kernel.

WebGUI root partition encryption

Encryption of the Linux root partition from the Cryptographic Security Platform Vault webGUI using the Encrypt Disk action is not supported.

Amazon and Azure root encryption boot disk swap

The Linux Policy Agent in Amazon and Azure requires a manual swap of boot and root disks for root encryption before rebooting. See the Administration Guide for more information.