1. Overview
This article provides an overview of new features and resolved issues in the Fortanix Filesystem Encryption (FSE) for Linux 2.0.170 release.
2. New Features
Added support for Encrypted Master Key rotation, enabling controlled key lifecycle management through Fortanix Data Security Manager (DSM) (JIRA: FSE-716).
For more information, refer to Filesystem Encryption for Linux Using Fortanix Data Security Manager - Client Configuration.
The Filesystem Encryption Lua plugin is now integrated into Fortanix DSM Plugin Library and adds support for rotating Encrypted Master Keys (JIRA: FSE-722).
For more information, refer to Filesystem Encryption for Linux Using Fortanix Data Security Manager - Client Configuration.
3. Bug Fixes
Fixed an issue where users could intermittently access files after their decryption permissions were revoked following a policy update, due to cached data when kernel caching (FUSE) was enabled during mount using –kernel-cache option, leading to an incorrect
PolicyPassedvalue (JIRA: FSE-736).
NOTE
You must have Fortanix Data Security Manager (DSM) version >=4.29 and FSE Agent version >=1.0.29 to access the FILE DECRYPTION POLICY tab in DSM user interface (UI).
For existing FSE-Linux users (with FSE Agent <1.0.29)
Install the latest Filesystem Encryption for Linux and update the FSE policy using the policy update command to automatically change the custom metadata and enable the FILE DECRYPTION POLICY tab in the Fortanix DSM UI. For more information, refer to Filesystem Encryption for Linux Using Fortanix Data Security Manager - Policies.
Uninstalling the previous Debian package is not necessary.
For information on installing or upgrading to the latest FSE-Linux version, refer to Filesystem Encryption for Linux Using Fortanix Data Security Manager - Installation.
For information on FSE Policy and the FILE DECRYPTION POLICY UI tab, refer to Filesystem Encryption for Linux Using Fortanix Data Security Manager - Policies.
4. Installation
To install the latest Filesystem Encryption package for Linux, click here.