Vormetric® Data Security Platform
Release Notes for Windows Agents Release 5 Version 5.2.3
MAY 29, 2015 D O C U M E N T VE R S I O N 1
Vormetric Data Security Release Notes Release 5, Version 5.2.3 May 29, 2015, Document Version 1 Produced in the United States of America Copyright © 2009 ‐ 2015 Vormetric, Inc. All rights reserved. NOTICES, LICENSES, AND USE RESTRICTIONS Vormetric is a registered trademark of Vormetric, Inc. in the United States (U.S.) and certain other countries. Microsoft, Windows, Windows XP, Windows NT, SQL Server and the Windows logo are trademarks of Microsoft Corporation in the U.S., other countries, or both. UNIX is a registered trademark of The Open Group in the U.S. and other countries. Linux is a trademark of Linus Torvalds in the U.S., other countries, or both. Java and all Java‐based trademarks (including Java, JavaServer Pages, Javadoc, JavaMail, and JavaBeans) are logos and trademarks or registered trademarks of Oracle, Inc., in the U.S. and other countries, and are used under license. Oracle, Oracle ASM, Solaris, SPARC, Oracle Enterprise Linux and Java are registered trademarks of Oracle Corporation and/or its affiliates. IBM, IBM logo, ibm.com, AIX, DB2, PowerPC, DB2 Universal Database and Informix are trademarks of International Business Machines Corporation in the U.S., other countries, or both. Intel, Intel logo, Intel Xeon, Itanium, and Pentium are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the U.S. and other countries. HP‐UX is registered trademark of Hewlett‐Packard Company in the U.S., other countries, or both. Adobe, Acrobat, PostScript and all Adobe‐based trademarks are either registered trademarks or trademarks of Adobe Systems Incorporated in the U.S., other countries, or both. X Window System is a trademark of the Massachusetts Institute of Technology. Red Hat and Red Hat Enterprise Linux, are trademarks of Red Hat, Inc., registered in the United States and other countries. SUSE and SLES are a registered Trademarks of Novell, Inc. All other products described in this document are trademarks of their respective holders. The Software and documentation contains confidential and proprietary information that is the property of Vormetric, Inc. The Software and documentation are furnished under Vormetric's Standard Master License Software Agreement (Agreement) and may be used only in accordance with the terms of the Agreement. No part of the Software and documentation may be reproduced, transmitted, translated, or reversed engineered, in any form or by any means, electronic, mechanical, manual, optical, or otherwise. Licensee shall comply with all applicable laws and regulations (including local laws of the country where the Software is being used) pertaining to the Software including, without limitation, restrictions on use of products containing encryption, import or export laws and regulations, and domestic and international laws and regulations pertaining to privacy and the protection of financial, medical, or personally identifiable information. Without limiting the generality of the foregoing, Licensee shall not export or re‐export the Software, or allow access to the Software to any third party including, without limitation, any customer of Licensee, in violation of U.S. laws and regulations, including, without limitation, the Export Administration Act of 1979, as amended, and successor legislation, and the Export Administration Regulations issued by the Department of Commerce. Any provision of any Software to the U.S. Government is with "Restricted Rights" as follows: Use, duplication, or disclosure by the government is subject to restrictions as set forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.277.7013, and in subparagraphs (a) through (d) of the Commercial Computer‐Restricted Rights clause at FAR 52.227‐19, and in similar clauses in the NASA FAR Supplement, when applicable. The Software is a "commercial item" as that term is defined at 48 CFR 2.101, consisting of "commercial computer software" and "commercial computer software documentation", as such terms are used in 48 CFR 12.212 and is provided to the U.S. Government and all of its agencies only as a commercial end item. Consistent with 48 CFR 12.212 and DFARS 227.7202‐1 through 227.7202‐4, all U.S. Government end users acquire the Software with only those rights set forth herein. Any provision of Software to the U.S. Government is with Limited Rights. Vormetric is Vormetric, Inc. at 2545 N 1st St., San Jose, CA, 95131‐1003, (408) 433‐6000.
Release Notes VORMETRIC, INC., PROVIDES THIS SOFTWARE AND DOCUMENTATION "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON‐INFRINGEMENT OF THIRD PARTY RIGHTS, AND ANY WARRANTIES ARISING OUT OF CONDUCT OR INDUSTRY PRACTICE. ACCORDINGLY, VORMETRIC DISCLAIMS ANY LIABILITY, AND SHALL HAVE NO RESPONSIBILITY, ARISING OUT OF ANY FAILURE OF THE SOFTWARE TO OPERATE IN ANY ENVIRONMENT OR IN CONNECTION WITH ANY HARDWARE OR TECHNOLOGY, INCLUDING, WITHOUT LIMITATION, ANY FAILURE OF DATA TO BE PROPERLY PROCESSED OR TRANSFERRED TO, IN OR THROUGH LICENSEE'S COMPUTER ENVIRONMENT OR ANY FAILURE OF ANY TRANSMISSION HARDWARE, TECHNOLOGY, OR SYSTEM USED BY LICENSEE OR ANY LICENSEE CUSTOMER. VORMETRIC SHALL HAVE NO LIABILITY FOR, AND LICENSEE SHALL DEFEND, INDEMNIFY, AND HOLD VORMETRIC HARMLESS FROM AND AGAINST, ANY SHORTFALL IN PERFORMANCE OF THE SOFTWARE, OTHER HARDWARE OR TECHNOLOGY, OR FOR ANY INFRINGEMENT OF THIRD PARTY INTELLECTUAL PROPERTY RIGHTS, AS A RESULT OF THE USE OF THE SOFTWARE IN ANY ENVIRONMENT. LICENSEE SHALL DEFEND, INDEMNIFY, AND HOLD VORMETRIC HARMLESS FROM AND AGAINST ANY COSTS, CLAIMS, OR LIABILITIES ARISING OUT OF ANY AGREEMENT BETWEEN LICENSEE AND ANY THIRD PARTY. NO PROVISION OF ANY AGREEMENT BETWEEN LICENSEE AND ANY THIRD PARTY SHALL BE BINDING ON VORMETRIC. Protected by U.S. patents: 6,678,828; 6,931,530; 7,143,288; 7,283,538; 7,334,124 Vormetric Data Security includes a restricted license to the embedded IBM DB2 database. That license stipulates that the database may only be used in conjunction with the Vormetric Security Server. The license for the embedded DB2 database may not be transferred and does not authorize the use of IBM or 3rd party tools to access the database directly.
.....
1
.....
Contents ...................................
Document Version History . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 Resolved Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 Known Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 End of Life Notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Discontinued Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Vormetric Data Security Agent v5.2.3 for Windows ‐ Compatibility Matrix . . . . . . 4 Interoperability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 Windows File Systems Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 Getting Help . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Document Version 1
Document Version 1
.....
2
Vormetric Data Security Platform
.....
...................................
1
Release Notes for Windows Agents Release 5, Version 5.2.3 Date: May 29, 2015
Document Version History
..................................................................... The following table describes the documentation changes made for each document version. Table 1: Documentation Changes Documentation Version
Date
Changes
5.2.3 v1
5/29/2015
First GA Release.
Resolved Issues
..................................................................... (AGT‐9378) Files were not encrypted after running RoboCopy files from a clear to a guarded folder on the same EMC NAS. This issue has been resolved. (AGT‐9104) Upgrading the Agent from 5.2.1.33 to any higher version on File Server Cluster (DFSR) resulted in deadlock errors in cluster logs and subsequent bluescreens. Windows Patch Release 5.2.2.44 resolved this issue and now upgrades proceed normally. (AGT‐9135) Copying files or doing a "save as" within a GuardPoint resulted in occasional file corruption for certain file types. Windows Patch Release 5.2.2.44 resolved this issue so that copied files and “save as” files within a GuardPoint maintain their integrity.
Known Issues
..................................................................... (AGT‐9539) C/R failure with error of "Hardware signature changed" when system comes back from hibernation.
Document Version 1
Release Notes Version 5.2.3 for the DSM
2
.....
Vo r m e t r i c D a t a S e c u r i t y P l a t fo r m Known Issues
This note applies to those systems where the user chose to associate the installation with the hardware of the machine during registration. On Windows systems using three or more network interfaces, an issue can occur due to a bug fix in the release. If this problems occurs, the system will not be able to access protected data nor communicate with the DSM after the upgrade without re‐registering the agent with the DSM, and this requires manual intervention at the DSM to remove the existing registration first. To avoid this problem, the existing version should be uninstalled before installing the 5.2.3 release. (AGT‐5755) On all Windows agents, following a data transform users experienced stale data. To avoid this issue, do the following: Prerequisites: • Verify that there is a good backup of the data to be encrypted. This step is vital. • Stop ALL access and services to the data to be encrypted. Make sure no processes, services, or users are currently accessing the data. • Ensure you have enough empty storage space to copy the data. • You will need a VDS production policy. If you must create one, see the VDS Getting Started Guide. NOTE: All services MUST be set to manual when running data transformation. 1. Apply the data transform policy. 2. Do the data transform. 3. Reboot the Windows host. 4. Apply the production policy for data access by the application. 5. Restart services as required. NOTE: If you cannot remove a GuardPoint after running data transformation, reboot the Windows host. (AGT‐8366) Windows 2012 x64 R2 systems fail to boot after Symantec EndPoint Protection v12.1 is installed on guarded drive. A local administrator must disable the BASH driver via the command prompt as a workaround: To disable the Symantec bash driver: 1. Windows 32‐bit systems: sc config bhdrvx86 start= disabled 2. Windows 64‐bit systems: sc config bhdrvx64 start= disabled
Document Version 1
Release Notes Version 5.2.3 for the DSM
3
.....
Vo r m e t r i c D a t a S e c u r i t y P l a t fo r m End of Life Notification
3. Reboot the Windows host. (AGT‐8640) Duplicate GuardPoints appear in the host registry and unguard fails following an upgrade from 5.0.1. To avoid this issue, do either of the following work‐arounds: NOTE: Before disabling a GuardPoint, all applications or services that access the GuardPoint must be stopped. No application or service can access a GuardPoint during the work‐around. 1. Before attempting an upgrade from 5.0.1 to 5.2.1 or 5.2.2: a. Disable all the GPs on the DSM. This removes all the references to GuardPoints in the registry files. b. Do the upgrade. c. After the upgrade is complete, enable all the existing GPs from the DSM. This creates the correct GuardPoint list without any duplication. or do: 2. This work‐around will prevent the duplication of GuardPoints if done before upgrading from 5.0.1 or correct the duplication of GuardPoints if done following an upgrade from 5.0.1. a. Uninstall the existing agent. b. Reinstall the new agent.
End of Life Notification
..................................................................... Release 5 will be the last major release to support the following: • Windows XP • Windows 2003
Discontinued Features
..................................................................... As of Release 5.2.3, there will be no support for the following: • Vormetric DB2 backup agent • Vormetric IDS backup agent
Document Version 1
Release Notes Version 5.2.3 for the DSM
4
.....
Vo r m e t r i c D a t a S e c u r i t y P l a t fo r m Vormetric Data Security Agent v5.2.3 for Windows ‐ Compatibility Matrix
Vormetric Data Security Agent v5.2.3 for Windows - Compatibility Matrix
.....................................................................
Interoperability Table 2: Table 22: Windows interoperability with IBM Infosphere Guardium and Imperva Securesphere Product IBM Infosphere Guardium Imperva Securesphere
Version v8.0, v9.0 v9.0, v9.5
OS Windows Windows
Notes Compatible Compatible
Windows File Systems Support Table 3: Table 23: Windows File System Support File System
Windows
2003 SP2/R2 (32/64 bit) (X86/x86_64) 2008 SP2 (32/64-bit) (X86/x86_64) 2008 R2 SP1 64-bita,b 2012/R2 (X86/ x86_64)a,b XP SP3 Vista SP2 (X86/x86_64) 7 SP1 (X86/x86_64)b 8/8.1 (X86/ x86_64)a,b
Database
Apps. MS SQL 2005 2008 MongoDB 2008R2 2012 2014 NTFS
Unstructured data
Oracle 10gR1 11gR1 11gR2 12c
DB2 95/9.7 10.1 10.5
Informix 11.5 11.7 12.1
MySQL 5.5 5.6
NTFS/CIFS
NTFS
NTFS
NTFS
NTFS
NTFS/CIFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS/CIFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS/CIFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS
NTFS/CIFS NTFS/CIFS
NTFS NTFS
NTFS/CIFS
NTFS
NTFS
NTFS/CIFS
NTFS
NTFS
SharePoint 2010/2013
a. Supports NTFS only. No ReFS support. b. Supports AES‐NI Document Version 1
Release Notes Version 5.2.3 for the DSM
5
.....
Vo r m e t r i c D a t a S e c u r i t y P l a t fo r m Getting Help
Getting Help
..................................................................... To get help from Vormetric Support: • Open a help ticket at https://help.vormetric.com • Email us at
[email protected] • Call us at 877‐267‐3247
Document Version 1
Release Notes Version 5.2.3 for the DSM
Document Version 1
6
.....
Vo r m e t r i c D a t a S e c u r i t y P l a t fo r m Getting Help
Release Notes Version 5.2.3 for the DSM