Virtual TapeServer 6.04.03 for NonStop Servers Release Notes
Known Issues | 19
SecureVTS
If invalid license key is used, SecureVTS appears to be configured though it is
not. If an invalid license key is used, no key generator is created. The server should
indicate that the license key is not valid. (TL-3549)
Cannot encrypt or decrypt after upgrade to 6.04.x. If you upgrade to 6.04.x, you
cannot decrypt cartridges that were encrypted before the upgrade and cannot encrypt
existing cartridges. SecureVTS-upgrade.log shows the following. (TL-3692)
Copied /VAULT00/.vts-upgrade/LocalKSBackup.tar.gz to
/VAULT01/.ks_backups/LocalKSBackup.tar.gz
Unable to restore key database from
/VAULT00/.vts-upgrade/LocalKSBackup.tar.gz; rc = 61
Also, in vts-post-install.log, the following is listed at the end of the log:
/VAULT00/.vts-upgrade/bill-cronjobs.txt
/VAULT00/.vts-upgrade/pre604.pgdump
/VAULT00/.vts-upgrade/root-cronjobs.txt
Copying /etc/resolv.conf to /etc/resolv.conf.predhclient
FATAL: Could not load /lib/modules/2.6.18-92.el5/modules.dep: No such
file or directory
cp: cannot create regular file `/VAULT01/.ks_backups/
LocalKSBackup.tar.gz': No such file or directory
WORKAROUND: Restore the database from a remote server and then re-establish the
connection to the key-generator.
SecureVTS fails to restore after upgrade if VAULT00 does not have the most free
space. If VAULT00 does not have the most free space, the key server backup will be
stored elsewhere and that location will be deleted (in the case of / or /boot) or not yet
mounted (in the case of any other vaults). (TL-3701)
WORKAROUND: Restore from a remote backup and then ensure that the expected vault
is mounted so that it may be used for local backups.
Encryption key backup must occur before you can add a remote host. Until the
encryption key is backed up, the remote host cannot be set. (TL-3463)
Pool is shown as encrypted though encryption failed. If no key generator is
configured and you set a pool to be encrypted, the operation will fail but the Pool
Maintenance and Virtual Media pages indicate that the pool is encrypted. (TL-3756)
No indication that configuration is incomplete and encryption/decryption will
fail. If no remote key generator backup host is defined and working, encryption or
decryption may fail with no indication other than rc=254 or rc=-2 in a log. The keys are
not cached until a remote host is defined. Encryption and decryption is not possible until a
remote backup host is defined. (TL-3686)
SecureVTS with remote key generator does not encrypt cartridges. If SecureVTS
is configured to use a remote key generator, the local host cannot encrypt cartridges. (TL-
3171)
WORKAROUND: Backup the remote keyserver database, delete the “localhost”
keyserver on the remote server, re-add the localhost keyserver on the remote server,
restore the keyserver database from backup.