For the complete documentation index, see llms.txt. This page is also available as Markdown.

32.xx Known Issues

The following table lists the known issues for 32.00 release.

Known Issues

ISSUE ID

DESCRIPTION

CWP-59435

Enabling FIPS with TLS 1.3 does not work for WAAS In-Line

Due to a compatibility issue in Go programming language’s package, the HTTP server is unable to operate with both FIPS mode and TLS 1.3 enabled simultaneously. This limitation is preventing WAAS In-Line from supporting the configuration.

CWP-53375

In Inventory > Compute Workloads, for users logged in with a role other than the built-in system admin role, currently only data about cloud provider managed registry images and VM instances can be viewed.

In particular, for such roles currently data about the following types of assets is not displayed:

  • Run stage images

  • Private registry images

  • Build stage images

  • On-premises hosts/hosts managed by cloud providers unsupported by Compute

CWP-58896

With the support for ACI in cloud discovery, here are the two issues:

  • Status: The status field currently utilizes Properties > ProvisioningState, which does not reflect the container status. For more information, refer to Azure Container Instances states.

  • Defend: The Defend functionality does not support Azure Container Instances (ACI). The Defend is enabled across all accounts and services, and when selected, it redirects to Images > Registry Settings.

CWP-58709

Duplicate Admission Rules

Six admission rules released in Version 32, Update 2 were found to be duplicates of older existing rules. If you need the functionality provided by these rules, we recommend disabling the old rules and using the new corresponding rules, as the older rules will be removed in an upcoming release.

The old rules and their corresponding new rules are as follows:

  • Old rule: Twistlock Labs - CIS - Pod created in host process ID namespace. New rule: Twistlock Labs - PSS - Baseline - Pod with containers that share host process ID (hostPID) namespace

  • Old rule: Twistlock Labs - CIS - Pod created on host IPC namespace. New rule: Twistlock Labs - PSS - Baseline - Pod with containers that share host IPC namespace

  • Old rule: Twistlock Labs - CIS - Pod created on host network. New rule: Twistlock Labs - PSS - Baseline - Pod that allows containers to share the host network namespace

  • Old rule: Twistlock Labs - Pod created with sensitive host file system mount. New rule: Twistlock Labs - PSS - Baseline - Pod created with sensitive host file system mount

  • Old rule: Twistlock Labs - CIS - Privileged pod created. New rule: Twistlock Labs - PSS - Baseline - Pod should not run privileged containers

  • Old rule: Twistlock Labs - CIS - Privilege escalation pod created. New rule: Twistlock Labs - PSS - Restricted - Pod that allows container privilege escalation

Note: Even though both the new and old rules are enabled by default, you will not receive duplicate alerts as only the first encountered rule is enforced.

CWP-58350

CVE Exclusions Update

The following CVEs that are included in the Intelligence Stream feed are ignored:

CWP-52710

While upgrading consoles from the 30.03 release to a 32.xx release, the error log failed to retrieve "size" specification option value during the migration doesn’t impact the migration process and can be ignored.

Last updated

Was this helpful?