ISN 2023-07: Device Encryption Password Bug
First published 23 May 2023
CVSS 3.1: 2.3 (Low)
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Summary
A bug in the IGEL OS Setup application prevents users from setting a (new) password for Device Encryption, and from disabling Device Encryption. This affects the following IGEL products:
- IGEL OS 11.08.290
Details
Due to a bug in the IGEL OS Setup application, users of IGEL OS 11.08.290
- cannot set a (new) password for Device Encryption
- cannot deactivate Device Encryption
The severity of this issue is low. Device Encryption settings and passwords that have been set before upgrading to IGEL OS 11.08.290 are not affected by this bug. They remain the same.
Mitigation
If you cannot update to IGEL OS 11.08.330 yet, you can apply the following mitigation:
- Go to Setup > System > Firmware Customization> Custom Commands.
- Enter the following command in the Desktop initialization field:
systemctl start igel-kml-daemon
- Reboot the system.
Update Instructions
- Update to IGEL OS version 11.08.330 (and set a Device Encryption password after the upgrade, if desired).