Release Note for CTE v7.5 for Linux
Release Note Version | Date |
---|---|
v7.5.0.78 | 2023-12-19 |
Release v7.5.0.78 of CipherTrust Transparent Encryption (CTE) for Linux adds new features, fixes known defects and addresses known vulnerabilities.
New Features and Enhancements
The major improvements to CTE for Linux in this release are:
-
Support for Load Balancer with CipherTrust Transparent Encryption & CipherTrust Manager
CTE agents can now communicate with a CipherTrust Manager cluster behind a network load balancer.
- See Load Balancer for more information.
-
Validate CipherTrust Manager at CTE client during registration
To ensure that registration by the CTE agent is serviced only by the expected key manager, you can provide a copy of the root CA certificate that will be used to authenticate the TLS communications with the key manager, during the registration process.
New Platform Support
The following platforms are supported starting with CTE v7.5.0.78:
RHEL
-
RHEL 8.9
-
RHEL 9.3
Ubuntu
- Ubuntu 22.04.2 with kernel 5.19 kernel
Secure Boot Advisory
For CipherTrust Transparent Encryption to support Secure Boot, the signing key for CTE kernel modules must be renewed every three years. Thales' current schedule for changing the signing key is the first week of 2024. For customers who take advantage of Secure Boot with CTE, the new certificate, matching the new signing key, must be added to their systems by the end of this year 2023 to ensure a smooth upgrade.
To obtain and install the new certificate, see CTE Agent Installation with UEFI Secure Boot.
Operating Support Advisory
This advisory covers changes planned for Operating System and Linux kernel support with CTE 7.5.0 scheduled to release in December 2023.
-
RHEL 7 reaches End-of-Support with CTE 7.5.0.
-
Red Hat Enterprise Linux (RHEL) new major and minor release SLA changes as follows.
-
Major: 60 Business Days
-
Minor/Service Pack: 30 Business Days
Note
There is NO change to critical kernel security patch SLA. Thales continues to support four business days.
-
-
Ending support for older Linux kernels as per the following table:
Operating System Last supported CTE release RHEL 7.5 - RHEL 7.9 7.4.0.x RHEL 8.0 - RHEL 8.6 7.4.0.x SLES-12 SP3 (all default kernels and up-to kernel 4.4.140-96.112.TDC-default for Teradata) 7.4.0.x SLES-12 SP4 (4.12.14-94.41-default to 4.12.14-95.54-default) 7.4.0.x SLES-12 SP5 (4.12.14-120-default to 4.12.14-122.63-default) 7.4.0.x SLES-15 SP0 to SLES 15 SP3 7.4.0.x
Resolved Issues
-
AGT-44996: Signature set is not working for
/sbin/dmsetup
on Teradata IDTDelays occurred, in CipherTrust Manager, when pushing entire signature sets to CTE hosts. The delays could make some of the signed binaries in the signature set unavailable on CTE hosts for authentication, hence causing denial of access on some of the binaries in the set. Delays are likely to occur with signature sets consisting of large numbers of binaries, such as CTE in Teradata clusters. This issue has been resolved.
-
AGT-48267: sfs_r_rk_lookup:1a assert failed after rotating key on Teradata DB
A potential problem with using LDT policies on GuardPoints in NAS shares has been resolved. This issue caused LDT primary hosts to reject valid responses from members of the LDT GuardPoint Groups.
Known Issues
-
AGT-48862: LDT GuardPoint Group Stopping secfsd service does not unguard CIFS GuardPoint
Work-around
Manually disable the GuardPoint in CipherTrust Manager.
End of Life
-
CTE-Efficient Storage for Linux is no longer supported.
-
Ubuntu 18.04 is no longer supported