See below for the known Vault issues in 10.6.1
- Upgrade failures during ISO upload on slow networks
- PKCS#11 vault metadata export fails with non-unicode labels
- SNMP trap delivery does not match the configured SNMP state
- Temporary password not displayed when SMTP is disabled
- OIDC unsupported for PKCS#11 Vault deployments
- VMware virtual hardware changes trigger Admin Key Recovery
- KeySafe5 agent runs only on the Compliance Manager master node
- Upgrade prerequisites for Vault Management and vault appliances
- KMIP TLS 1.3 selection restricts the protocol version
- Key-value text secrets cannot be checked out in the Secrets web GUI
- Multi-node upgrades can fail because of latency
- Clear Cache clears all Cryptographic APIs caches
- Unsupported SSH key algorithms and sizes
- Unsupported KMIP RSA key sizes
- vSAN trust requires an IP address when no FQDN DNS entry exists
- AD administrators require a rescue user
- Reverting a Vault cluster requires all prior-version nodes
- AWS XKS network latency limit
- Restore recovery can take a long time
- Two-factor authentication is limited to local users
- Upgrade must be completed on the initiating node
- OIDC is unavailable during backup restoration
- Browser cache must be cleared after upgrading
- System Recovery cannot restore access after simultaneous hardware and IP changes
- KC node hostname and domain name cannot be changed
- Cloud VM Set names must be unique
- Degraded-cluster alerts are delayed
- Custom SSL certificates require a webserver restart from the web GUI
- Expiration date changes can fail because of UTC time
- Corrupted audit log entries do not display correctly
- Longer cluster timeouts delay degraded-state processing
Upgrade failures during ISO upload on slow networks
On slow network connections, upgrades may fail during ISO upload. Retrying the upgrade usually resolves the issue.
This issue is fixed in the 10.6.1 release.
PKCS#11 vault metadata export fails with non-unicode labels
Metadata export for PKCS#11 vaults fails when object labels contain non-Unicode characters.
SNMP trap delivery does not match the configured SNMP state
For vaults, SNMP trap delivery is inverted. Traps are not received by the NNMi SNMP server when SNMP trap settings are enabled, but continue to be received when SNMP is disabled. As a result, SNMP-based alerting does not reflect the configured SNMP state of the vault.
Temporary password not displayed when SMTP is disabled
When SMTP is disabled, the system-generated temporary password is not displayed in the CSP Vault WebGUI after an administrator resets another user's password. As a workaround, retrieve the password using the API/Postman scripts or from the browser's Network tab. When SMTP is enabled, the system-generated temporary password is sent to the user's email address following a password reset.
OIDC unsupported for PKCS#11 Vault deployments
This release does not support OIDC authentication for PKCS#11 Vault deployments.
VMware virtual hardware changes trigger Admin Key Recovery
Changing the VMware virtual hardware version of a CSP Vault appliance will trigger the Admin Key Recovery process.
KeySafe5 agent runs only on the Compliance Manager master node
Because the KeySafe5 agent does not support clustering, it only runs on the master node of the Cryptographic Security Platform Compliance Manager cluster. If you remove that node, the KeySafe5 agent will stop working.
To fix this issue:
- Disconnect and reconnect your connection to Cryptographic Security Platform Compliance Manager.
- You must be connected as an Appliance Cluster, not a Data Source.
- Create the connection using the Compliance Manager master node IP, not a load balancer IP or hostname.
- Disable and re-enable the KeySafe5 agent from the HSM settings page.
This will reestablish the connection between the KeySafe5 agent and the Compliance Manager.
Upgrade prerequisites for Vault Management and vault appliances
Before you can upgrade to 10.6.1:
- The Cryptographic Security Platform Vault Management appliance and all vaults must be connected to the Cryptographic Security Platform Compliance Manager at version 10.6.1 or 10.5.3.
- All appliances and vaults must be able to fetch the relevant license information from the Cryptographic Security Platform Compliance Manager
- The license should not be expired. If you are not in compliance with your current license, you will not be able to upgrade.
KMIP TLS 1.3 selection restricts the protocol version
By default, the Cryptographic Security Platform Vault for KMIP enables both TLS 1.2 and TLS 1.3. If you select the TLS 1.3 option, the protocol will be restricted to TLS 1.3 only.
Key-value text secrets cannot be checked out in the Secrets web GUI
If you create a text secret with a key-value value, you will get an error when checking it out from the Cryptographic Security Platform Vault for Secrets web GUI. However, you can still check out the secret from the CLI. To fix this issue, delete the secret and re-create it, specifying the secret type as "Key-Value". This should allow checkouts to succeed from the web GUI.
Multi-node upgrades can fail because of latency
If you attempt to upgrade multiple nodes, the upgrade may fail due to latency. Contact Support if this happens.
Clear Cache clears all Cryptographic APIs caches
If you run the Clear Cache command in the Cryptographic Security Platform Vault for Cryptographic APIs web GUI, all caches are cleared no matter which cache type you specify.
Unsupported SSH key algorithms and sizes
Cryptographic Security Platform Vault for Secrets administrators can no longer create SSH secrets that contain SSH keys with the ED25519 algorithm and RSA keys with a 1024-bit length.
Unsupported KMIP RSA key sizes
The Cryptographic Security Platform Vault for KMIP no longer supports creating 512-bit or 1024-bit RSA keys.
vSAN trust requires an IP address when no FQDN DNS entry exists
If you do not have the DNS entry for the FQDN for a Cryptographic Security Platform Vault node, use the IP address when establishing trust between vSAN and the KMIP Vault.
AD administrators require a rescue user
In the Cryptographic Security Platform Vault for Application Security, Cryptographic Security Platform Vault for KMIP, and Cryptographic Security Platform Vault for Secrets, when the authentication type is set to AD and the AD group is set up as an admin principal in the Admin Policy, set up a corresponding AD user from the group as a rescue user and add that user to the admin principal list as well as the AD Group.
Reverting a Vault cluster requires all prior-version nodes
Before reverting a Cryptographic Security Platform Vault cluster to an older version, ensure that all of the nodes that existed in the older version are available.
AWS XKS network latency limit
For AWS XKS, the maximum round-trip network latency between KMS in the AWS region and Cryptographic Security Platform Vault is 250 milliseconds. The KMS times out if it does not receive a response back from Cryptographic Security Platform Vault within 250 milliseconds. For more details, see the AWS documentation.
Restore recovery can take a long time
After restore, Cryptographic Security Platform Vault may display errors on the login screen. The recovery process works but takes a long time.
Two-factor authentication is limited to local users
Two-factor authentication is supported only for local users, not AD users.
Upgrade must be completed on the initiating node
Complete the Cryptographic Security Platform Vault upgrade on the same node where you initiated the upgrade.
OIDC is unavailable during backup restoration
When restoring a backup, the OpenID Connect (OIDC) service will not be available until the restore operation completes. Refreshing the login page will display the OIDC login once the process completes. Rebooting the node after the login page is available will also restore the OIDC service.
Browser cache must be cleared after upgrading
You must clear your browser's cache after upgrading Cryptographic Security Platform Vault.
System Recovery cannot restore access after simultaneous hardware and IP changes
If the hardware configuration and the IP address for a node change simultaneously, you cannot use the System Recovery option in the Cryptographic Security Platform Vault web GUI to restore access to Cryptographic Security Platform Vault. If this happens, contact Entrust Support.
KC node hostname and domain name cannot be changed
You cannot change a KC node's hostname or domain name once the system has been fully initialized. This is due to object store requirements. If you must make a change, remove the node from the cluster and reinstall it with the new hostname or domain name. Then you can add the node back to the cluster.
Cloud VM Set names must be unique
All Cloud VM Sets that the logged-in Cloud Admin can access must have unique names. If a Cloud Admin tries to edit or delete an existing VM Set with a duplicate name, they will first be prompted to change the VM Set name before they can continue with the edit or delete operation.
Degraded-cluster alerts are delayed
If a Cryptographic Security Platform Vault cluster is in the degraded state, alerts are not posted until the cluster becomes healthy. Email notifications and remote syslog messages, however, are delivered immediately even if the cluster is degraded.
Custom SSL certificates require a webserver restart from the web GUI
When you install a custom SSL certificate on a Cryptographic Security Platform Vault node, you must restart the webserver from the web GUI to use the new certificate. A Cryptographic Security Platform Vault node reboot does not have the same effect. After a node reboot, you must restart the web server from the web GUI to use the newly installed SSL certificate.
Expiration date changes can fail because of UTC time
The Cryptographic Security Platform Vault time zone is set to UTC (Coordinated Universal Time), whereas the web GUI translates the time to the browser's local time zone. While changing a key, device, or certificate expiration date from the browser, the operation might fail with the error "Expiration date must be in the future". This happens when the administrator sets the expiration date to the next day in local time, but the UTC date has already passed. For example, in Pacific Daylight Time (PDT), which is 7 hours behind UTC during daylight saving time, the UTC date has moved to the next day after 5 PM, so setting the expiration date to the next day fails.
Corrupted audit log entries do not display correctly
If the audit log contains corrupted entries, it will not display properly in the Cryptographic Security Platform Vault web GUI. If this issue arises, contact Entrust Support.
Longer cluster timeouts delay degraded-state processing
You can lengthen the Cryptographic Security Platform Vault cluster timeout to improve scalability. This causes delays when the cluster is degraded equal to twice the timeout value. These delays end a few minutes after the cluster enters the degraded state.