New Known Issues in the 6.11.0 Release
The following known issues were identified in the ClearPass Policy Manager 6.11.0 release. Workarounds are included when possible.
|
Bug ID |
Description |
|---|---|
|
CP‑46913 |
During a operation, the warning message "echo GET failed. Will retry..." might be shown a few times before the API call to change the password succeeds. The API call should eventually succeed for each subscriber in the cluster. Users should be aware that this is expected behavior and is not an issue. |
|
Bug ID |
Description |
|---|---|
|
CP‑40416 |
Users should be aware that for the and commands, the input value should be enclosed within double quotes and the IP address should be enclosed in square brackets when an IPv6 address and port number are provided as inputs. For example: dump servercert "[0:0:0:0:0:0:0:1]:443" dump certchain "[0:0:0:0:0:0:0:1]:443"{} |
|
CP‑47967 |
For any cluster-related or database-related operation from the CLI, the default CLI timeout interval of 10 minutes might not be sufficient. It is therefore recommended to set the CLI timeout interval to a higher value before starting operations through the CLI such as a cluster join, backup or restore operation, patch installation, or upgrade. |
|
CP‑48351 |
If the first attempt to log in to the CLI fails due to an incorrect password, then during subsequent login attempts the username and password fields show unexpected behaviors. Each time the prompt for username and password is repeated, it actually uses the password that was entered in the previous attempt. If a wrong password is initially entered and this issue occurs, then when the correct password is entered at the prompt but rejected, it will next prompt you for the username. Enter the username and the login should succeed. Depending on the sequence of incorrect and correct entries, this might need to be done more than once. |
|
Bug ID |
|
|---|---|
|
CP‑46898 |
On a ClearPass 6.11 server in FIPS mode, if the AirGroup controller does not support FIPS-compliant ciphers, then when trying to read configurations the page shows the error message "Could not read configuration from controller (error 6: Cannot negotiate a secure session - possible FIPS or cipher lock down)" for the AirGroup controller. This is only an issue in FIPS mode. It is not an issue when ClearPass is not in FIPS mode. |
|
CP‑48002 CP‑48059 |
Imports and exports of Guest configuration files do not work while FIPS mode is enabled, and the error message "Invalid backup file..." is displayed in the dialog at . |
|
CP‑48060 |
Users should be aware that at , the gateway is now deprecated. ClearPass 6.11 is the final release where the gateway will be available. The service will be removed entirely in a future release of ClearPass. The service itself is no longer available. |
|
Bug ID |
Description |
||||||
|---|---|---|---|---|---|---|---|
|
CP‑53666 |
Under some circumstances customers might see alerts about partitions becoming full on ClearPass cluster members that are operating as Insight nodes. This issue is triggered by excessive RADIUS timeout events. This issue is present in 6.11.0 and later. Do one of the following:
|
|
Bug ID |
Description |
|||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
CP‑42309 |
If a database backup is made for ClearPass with a subscriber configured as the standby publisher, and if the backup is restored without using the flag, then after the backup is restored the command fails with the error message "Caught unexpected error while retrieving the Cluster Node List. Hint: If restore was performed, verify Standby Publisher setting." Do one of the following:
|
|||||||||
|
CP-45999 |
While deploying a new ESXi hypervisor through the VMware wizard, at the "VMware Ready to Complete" stage where the user reviews their settings the error message "At least one extra disk image was provided that will be ignored" is displayed. This message is harmless and can be ignored, and the installation completes correctly. The message refers to an .NVRAM file that is created as part of the OVF image. |
|||||||||
|
CP‑46158 |
If a database backup is made for a ClearPass system that is in Common Criteria (CC) mode and on a version lower than 6.11.0, trying to restore that backup on a non-FIPS 6.11.0 system ought to fail, but instead it succeeds. The system remains in non-FIPS mode, but the progress window incorrectly shows the database as restored and the footer shows it as in CC mode. Users should be aware that a backup made from a 6.9.x or 6.10.x system in CC mode should not be restored on a 6.11.0 system that is in non-FIPS mode. |
|||||||||
|
CP‑47167 |
On an Amazon Web Services (AWS) instance, the administrator password for the ClearPass user interface is not changed when the password is configured during the initial configuration but instead retains the default value, and the 503 error message " Platform.Cli SystemConfig Failed to update password for admin" is shown. This issue occurs during onboot because not all services are available yet when the HTTP request for the password update is sent. After AWS is deployed, wait 15 minutes before submitting the password change. |
|||||||||
|
CP‑47664 |
Beginning in ClearPass 6.11 the use of m4 Amazon Web Services is no longer supported. Amazon indicates that all customers must move to m5 instances to be able to support operating ClearPass. |
|||||||||
|
CP-47848 |
When a Hyper‑V live migration is performed from one ClearPass Hyper‑V instance to another while the instance is powered off, then the first time the destination Hyper‑V instance is powered on or restarted after the migration, the ClearPass IP address is lost. This issue only occurs if the migration is done while the Hyper‑V instance is powered off. It does not occur if the migration is performed while the instance is powered on. When performing a Hyper‑V live migration, do one of the following:
|
|||||||||
|
CP‑48004 |
Users should be aware that when creating database backup files from lower ClearPass versions to be restored on ClearPass 6.11.0, the backup files for the Configuration Database (tipsdb) and the Insight Database (insightdb) should be separate — each of these should be in its own backup file. This is recommended because otherwise backup files can grow too large due to the amount of data in them. Backing them up separately ensures that they will be restored correctly without overloading the system and blocking the restore operation. |
|||||||||
|
CP‑49298 CP‑50125 |
Trying to restore a backup sometimes fails due to a missing migration configuration. |
|||||||||
|
CP‑49394 |
During an Azure instance deployment, morphing sometimes fails because Azure does not pick up the additional solid-state drive (SSD) that is attached for the morphing process. This is an intermittent issue, and appears to be a timing issue. Avoid attaching the additional disk for morphing while ClearPass is running, as this sometimes causes the issue to occur. Instead, do the following:
|
|||||||||
|
CP‑50009 |
A maximum of 4096 bytes worth of data may exist as attributes associated with a single endpoint record. Customers must remove unused data from endpoint records that exceed 4096 bytes of data prior to upgrade. Failure to complete this prior to the 6.11 upgrade will prevent the endpoint attributes from being used in ClearPass versions later than 6.11.0. |
|||||||||
|
CP‑50060 |
Installing ClearPass 6.11.0 on a C2000 or C2010 appliance via iLO is not feasible because a limitation with the iLO standard license means remote console operation is not possible. Instructions will be added to the Installation Guide for installing C2000 and C2010 appliances using an ISO image. |
|||||||||
|
CP‑52950 CP‑54247 |
Starting with the 6.11.0 release, after the command is run during a ClearPass upgrade and the new disk is added, the existing hard disk cannot be removed. This is the expected behavior. Users should be aware that this is because the existing disk is used to extend the disk space for the server, and is included in the calculations to determine the required capacity of the additional hard disk. |
|||||||||
|
CP‑53551 |
In ClearPass 6.11.0 and later versions, the maximum single cluster size is limited to 32 servers. This includes the publisher, standby publisher, subscribers, dedicated Insight server, and standby Insight servers. |
|
Bug ID |
|
|---|---|
|
CP‑46824 |
In the 6.11.0 release, subscription-based licenses incorrectly reflect the original life of the subscription or evaluation rather than the correct remaining time. For example, a one-year contract that was activated for seven months in a previous release before it was added and activated in 6.11.0 will now show 12 months validity rather than the five months that actually remain. Until this issue is resolved, please refer to the existing support contracts and data in the HPE Networking Support Portal and License Management System (LMS), which reflect the actual end of the subscription. |
|
Bug ID |
Description |
|||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
CP‑40843 |
Users should be aware that starting with ClearPass 6.11.0, configuring trust settings is now mandatory for Android, ensuring compliance with WPA3 specifications for server certificate validation. To configure the mandatory trust settings for Android:
|
|||||||||
|
CP‑46762 |
After OnBoard provisioning, some Android users are requested for a username and password while connecting to a TLS SSID. This is related to a known Android behaviour. For more information, refer to the Android developer site at https://developer.android.com/guide/topics/connectivity/wifi-suggest. To have the Android device connect to the ClearPass Onboard provisioned network:
|
|
Bug ID |
Description |
|---|---|
|
CP‑44685 CP‑45557 |
In the area of the tab, the drop-down list is sometimes hidden if the browser's display is enlarged or resized and its scroll bar no longer appears. Refresh the page to display the scroll bar again. |
|
CP‑46753 |
Users should be aware that Agentless OnGuard is not supported in FIPS or CC mode. |
|
CP‑47896 CP‑47897 |
Starting with ClearPass 6.11.0, OnGuard is not supported on Ubuntu 16.04. |
|
CP‑48086 CP‑48087 |
When the Agent Enforcement profile is enabled at , the OnGuard Agent does not validate the file server. |
|
CP‑48692 CP‑48694 |
When trying to auto-update the ClearPass OnGuard Agent from 6.11.0 to 6.11.1 on macOS in IPv6-only mode, the upgrade fails and ClearPass OnGuard Agent remains on the 6.11.0 version. |
|
CP‑52911 CP‑53486 |
macOS clients connected to a wired network through an external/USB Ethernet adaptor do not trigger RADIUS requests after the interface is bounced by the OnGuard Agent using Agent Bounce. Use RADIUS dynamic authorization (DA) or a switch port bounce instead. |
|
Bug ID |
Description |
||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
CP-39092 |
In an Amazon Web Services instance (AWS), if a data port is not configured, the data port IP address is displayed as (localhost) at . |
||||||||||||
|
CP‑42931 |
Corrected an issue where, at , the policy hit count was not reflected for the service and always showed the value as zero. The policy hit count is now correctly shown in the column. As part of this fix, the policy hit count can also be used in ClearPass Insight to generate a report using the template. |
||||||||||||
|
CP-43931 |
Starting in ClearPass 6.11.0, the field name for storing the value of a data filter's type is changed internally from "qType" to "type" . This causes an issue where, when an administrator tries to import an XML file from a lower version of ClearPass to 6.11.0, the import fails and the error message "File contains invalid XML tags. Try export to see the valid XML tags" is shown in the user interface. Before importing the lower version of the data filter XML file into ClearPass 6.11.0, modify the field name from "qType" to "type" in the XML. |
||||||||||||
|
CP‑44382 CP‑45783 |
NTP authentication using the SHA algorithm fails and the error message "Error: Failed to configure date-time information" is shown in the dialog. Users should be aware that starting in ClearPass 6.11, only SHA1 is supported as an NTP authentication algorithm type. While restoring backups on 6.11.0 installations, if there are any NTP servers configured with the SHA algorithm, the algorithm corresponding to those servers will be automatically changed to SHA1 as part of the upgrade procedure. |
||||||||||||
|
CP‑44429 |
The RADIUS server crashes and reloads with a new PID if RADIUS traffic with the password type as sha512 is configured in a MSSQL authentication source. Users should be aware that MSSQL varchar(max) is not supported. Please define the column with a reasonable varchar limit. |
||||||||||||
|
CP‑45041 |
An Active Directory (AD) join fails for Windows 2008 server and Windows 2008 Server R2 while FIPS mode is enabled. Users should be aware that for Windows 2008 Server and Windows 2008 Server R2, Active Directory is not supported in FIPS or CC mode. |
||||||||||||
|
CP‑45130 CP‑45324 |
Users should be aware that, starting with ClearPass 6.11, the OpenSSL cryptography library in ClearPass does not support TLS 1.0 or TLS 1.1 when FIPS mode is enabled, since the SHA-1 and MD5 hash algorithms are disabled in that version. As part of this change, the and options are hidden on the tab when FIPS mode is enabled. |
||||||||||||
|
CP‑45341 |
Users should be aware that certificates with SHA‑1 or SHA‑224 digest algorithms are not supported in FIPS mode. |
||||||||||||
|
CP‑45377 |
When a system with a RadSec tunnel in CC mode is upgraded to ClearPass 6.11, the RadSec tunnel does not come up after the upgrade and errors such as "EE certificate key too weak" and "tls_process_client_certificate:certificate verify failed" are seen in the logs. Users should be aware that starting with ClearPass 6.11, when in FIPS and CC mode, cipher suites that use RSA, DSA, or DH keys shorter than 2048 bits or ECC keys shorter than 224 bits are not supported. |
||||||||||||
|
CP‑46018 CP‑47882 |
If a subscriber that is down or unreachable is force-dropped from the publisher and later brought back up before it is marked as disabled on the publisher, running the CLI command on the subscriber returns the error message "Caught unexpected error while retrieving the Cluster Node List. Hint - If restore was performed, verify Standby Publisher setting." While the subscriber is in this state, it cannot be added back to the cluster and some of the services such as policy server, TACACS+ server, DB replication service, and DB change notification service stop running. To avoid this issue, do one of the following:
|
||||||||||||
|
CP‑46050 |
In a cluster of three or more servers, it is not recommended to run a manual promotion operation with the force option () when a subscriber is down. There is a remote chance that doing so might lead to an inconsistent behavior on the disabled subscriber where it might still be in sync with the new publisher but is marked as disabled. This corner case is seen when the disabled subscriber is back online within a few minutes of the manual promotion operation completing. Drop the disabled subscriber from the current publisher, reset the database on the disabled subscriber, and then rejoin it to the cluster. |
||||||||||||
|
CP-46268 |
After installing a cluster that has Insight enabled on one of the servers, the Access Tracker and the policy server logs show the error message "Failed to connect to datasource: FATAL: database "insightdb" does not exist." Users should be aware of the following configuration requirements starting with the ClearPass 6.11.0 release:
|
||||||||||||
|
CP-46461 |
Users should be aware when running an IPv6 subnet scan that IPv6 subnets might have very large IP spaces. If a scan is triggered for a large IPv6 subnet (for example, /64 or more), it will take a very long time to complete. We recommend users to configure smaller subnets so that the number of the host space is small in order for the scan to finish within a reasonable amount of time. |
||||||||||||
|
CP‑46716 |
A subscriber that is out of synchronization for 24 hours is marked disabled and becomes a standalone server. On the publisher, this subscriber is listed as part of the cluster with its replication status disabled. However, since it has become a standalone, it cannot be rejoined to the cluster through the user interface by using the "join back to cluster" option. First, you will need to drop the subscriber manually from publisher. Then to join the disabled subscriber back to the cluster, do a make-subscriber operation through either the CLI or the user interface. |
||||||||||||
|
CP-46809 CP-47842 |
If a database backup is made for ClearPass with publisher failover enabled and a subscriber configured as the standby publisher, and if the backup is restored without using the flag, then during the restoration it fails to start the service. This issue occurs because without the option the only entry retained in the cluster list is that of the local server, and the command tries to fetch the information of the standby publisher but it is not present in the cluster list. It is not recommended to restore a backup without the option if a standby publisher is configured in the backup. If this issue occurs after a restore operation, manually disable publisher failover and clear the designated standby publisher configuration. On the tab, set the value to , and set the value to . The replication service should then come up. |
||||||||||||
|
CP‑47074 CP‑47476 |
On an active ClearPass system, sometimes when traffic causes a server's disk to reach 100% percent capacity no alert is shown in the and aggressive cleanup is not triggered. Users should be aware that the aggressive cleanup behavior is now changed as part of the partition schema changes in ClearPass 6.11. Cleanup tasks and alerts are now triggered separately for the "/", "/var", and "/var/log" partitions. This differs from previous ClearPass releases, where all of the system logs, application logs, backed up configurations, stored reports, and past authentication records where cleared as part of the "/" partition. |
||||||||||||
|
CP-47214 |
Trying to import a default authentication source to ClearPass 6.11 from an earlier version fails, and error messages such as "Default filter query cannot be modified" and "Custom SQL must not contain any data-modifying SQL statements" are displayed at . Users should be aware that exports, imports, and display of default data in authentication sources and services are now validated. After an authentication source configuration that contains default data or queries is exported to ClearPass 6.11 from a lower version, and before you import it:
The ClearPass default AuthSource name is contained in "[<AuthSource-name>]". For example: <AuthSource description="Authenticate users against Policy Manager local user database" name="[Local User Repository]" isAuthorizationSource="true" type="Local">
|
||||||||||||
|
CP‑47369 CP-47719 |
In an AWS instance with Luks enabled, the command works correctly the first time it is used while morphing the instance; however, if the command is used again after a reboot the instance stops working with the error message "Cannot open access to console, the root account is locked," and the instance cannot be recovered. This issue only occurs in ClearPass 6.11. It is not an issue in earlier ClearPass versions. It will be fixed in a later version. Until then, do not use the command. |
||||||||||||
|
CP‑47441 |
On the tab, the and graphs do not show any data for the process. This issue is seen in ClearPass 6.9.x, 6.10.x, and 6.11.0. |
||||||||||||
|
CP-47853 CP-47854 |
When a subscriber that is out of synchronization is disabled after 24 hours and is dropped from the cluster, the command throws an exception if the cluster has publisher failover enabled and a standby publisher configured. This issue occurs because the only entry retained in the cluster list is that of the local server, and the command tries to fetch the information of the standby publisher but it is not present in the cluster list. If this issue occurs, manually disable publisher failover and clear the designated standby publisher configuration. At , set the value to , and the value to . The command will then display the list without any error. |
||||||||||||
|
CP‑47734 CP‑47902 |
In the CLI and in the UI's window, incorrect percentages are shown for free and that are much lower than the actual percentages. Although the displayed percentages are incorrect, the actual gigabyte counts shown are correct. To calculate the actual percentage of free disk or memory, divide the amount of free space by the total space. |
||||||||||||
|
CP‑47959 |
Changing the Syslog Export Interval from the default value of 120 seconds to a custom value does not take effect in ClearPass 6.11.0. The Syslog still queries for data over a 120-second window even if the Syslog Export Interval is changed to a custom value. Restart the system auxiliary service [ cpass-system-auxiliary-server ]. After the system auxiliary service is restarted, the Syslog Export Interval will be read from the database and the custom value will be used. |
||||||||||||
|
CP‑47980 CP-48057 |
If an HTTPS ECC server certificate is disabled on a ClearPass server in FIPS mode, then the dashboard widget shows the server as down, the window shows a "bad certificate (SSL certificate alert number 42)" error message, and the tab for the server shows the error message "handshake failure." This issue occurs on a system in FIPS mode if the HTTPS(ECC) Server Certificate is disabled at . |
||||||||||||
|
CP‑48007 |
While deploying ClearPass on an ESXi, Hyper‑V, or KVM hypervisor, during the steps for indicating whether to encrypt data there is no space between the instruction text and the user's response. |
||||||||||||
|
CP‑48049 CP‑48050 |
In the case of large clusters or setups that handle a high load, an increase in the size of auto-backups is sometimes seen at . Users should be aware of the following:
|
||||||||||||
|
CP‑48248 |
Microsoft Azure Defender sometimes identifies components within OnGuard as malware. The ClearPass base images for 6.11.0, 6.11.1, 6.12.0 include the Impacket package as part of ClearPass Agentless OnGuard. Azure Defender may flag these components as malware or hacktools on fresh deployments of ClearPass 6.11.0, 6.11.1, or 6.12.0. Users should be aware that the ClearPass built-in restricted shell already mitigates any associated risk, and non-essential modules were removed in 6.11.9, 6.12.2, and later. Immediate patching with the latest 6.11.x or 6.12.x patch update is recommended after 6.11.0, 6.11.1, or 6.12.0 deployment. |
||||||||||||
|
CP‑48756 CP‑50386 |
At , an Active Directory (AD) authentication source with a primary and backup AD server configured sometimes displays the error message "Unable to connect to the server. Error: Failed to verify server certs. Please select the root certificate and try.” This issue occurs if is set to and is enabled. |
||||||||||||
|
CP‑48934 |
Users should be aware that, in a ClearPass cluster with both IPv4 and IPv6 addresses configured, some services and modules always use the IPv4 management address to keep the cache of each appliance synchronized across the cluster. In a dual-stack environment the following modules do not use the IPv6 management address for synchronization when the cluster communication mode parameter is set to IPv6, and continue to use IPv4, regardless of configuration or actual interface address availability of IPv6:
|
||||||||||||
|
CP‑49296 CP‑49343 |
The file-to-database (FDB) service sometimes fails to update endpoints due to a log file permissions issue. |
||||||||||||
|
CP‑49353 |
On some Windows 10 devices that use a Trusted Platform Module (TPM), EAP-TLS authentications using certificates installed in the TPM fail with the error message “RSA_verify_PKCS1_PSS_mgf1:last octet invalid.” When the Windows 10 device uses the TPM certificate to create an rsa_pss_rsae_sha256 signature in a TLS 1.2 Certificate Verify message, instead of sending the signature it sends 256 zeros, causing the EAP-TLS authentication failure: Handshake Protocol: Certificate Verify Signature Algorithm: rsa_pss_rsae_sha256 (0x0804) Signature: 0000000000000000000000000000000000000… This issue is seen in ClearPass 6.11.x on some Windows 10 devices using TPM. It is not an issue in earlier ClearPass versions. Customers can work with Microsoft to update the Windows client. Until it is updated, dIsable the RSA PSS algorithm in the affected machine. |
||||||||||||
|
CP‑50092 |
An authorization query cannot be saved in ClearPass 6.11.x if it includes a semicolon character ( ; ). |
||||||||||||
|
CP‑51446 CP‑54528 |
On Gen10 servers, high disk usage is sometimes seen on the /var/log/ partition, and the shows the error message "System is running with low disk space. Aggressive cleanup for /var/log$ will be initiated when the available disk space falls below 20%." This issue occurs on Gen10 servers if the iLO version is below 3.09. Recent SPP versions include the fix. To correct this issue, update the custom SPP image to the latest version (April 2025 or later). |
||||||||||||
|
CP‑51979 |
A long-running query alert might be seen intermittently in the for the cluster diagnostics query "autovacuum: VACUUM public.tips_endpoints." If this alert is seen, it can be safely ignored. The autovacuum is triggered by postgres, which is an internal command. |
||||||||||||
|
CP‑53675 CP‑53727 |
If the CHAP authentication method is enabled on a network access device (NAD) for TACACS+ logins, attempts to log in to the NAD using Active Directory (AD) credentials fail and the Access Tracker shows the alert message "Method not implemented." Users should be aware that:
|
||||||||||||
|
CP‑53753 |
Users should be aware that the Remote Assistance feature is deprecated in ClearPass 6.11, 6.12, and later versions. Although the page still appears in the user interface in 6.11 and 6.12, the functionality is removed and it cannot be used. The page will be removed in the 6.14 release. |
||||||||||||
|
CP‑53824 |
Users should be aware that in ClearPass 6.11.0 and later, HTTP URL redirects are disabled. It is recommended to use direct URLs instead for corresponding fields that accept a URL (for example, in the Distribution URL field on the Add Certificate Revocation List form). |
||||||||||||
|
CP‑53992 |
Heavy CPU usage due to unstable Database Change Notice (DBCN) events is sometimes seen if expired licenses are present.
If you are on either ClearPass 6.11.x or 6.12.x:
If you are about to upgrade from 6.11.x to 6.12.0:
|
||||||||||||
|
CP‑55586 |
If a patch update is performed through the page, after the installation is complete the page does not show the message that indicates the Admin Service will restart and that the user should log in again after a while. Instead, the window shows the installation as still in progress. This behavior is harmless, and may be expected when the Admin Service restarts after a patch update. To verify whether the patch update completed, refer to the entries. |
|
Bug ID |
Description |
|---|---|
|
CP‑53977 CP‑54022 |
At this time we do not have enough unique fingerprint information to accurately profile iOS 18 devices. These devices are currently classified as Generic Apple devices. Additionally, if MAC randomization is enabled, iOS 18 devices are currently classified as Unknown. Accurate classification of iOS 18 devices will be provided in future releases when more distinct fingerprints specific to iOS 18 become available. |