Skip to content

disable FileVault rotation if the server talks to an old fleetd - #21004

Merged
roperzh merged 2 commits into
mainfrom
disable-fv-on-old-fleetd
Aug 2, 2024
Merged

disable FileVault rotation if the server talks to an old fleetd#21004
roperzh merged 2 commits into
mainfrom
disable-fv-on-old-fleetd

Conversation

@roperzh

@roperzh roperzh commented Aug 2, 2024

Copy link
Copy Markdown
Contributor

for https://github.com/fleetdm/confidential/issues/7522 and part of #13157, support map is defined as:

fleetd < v1.30 fleetd >= v1.30
Server < 4.55 OK/FileVault rotation uses system prompt OK/FileVault rotation uses system prompt
Server >= 4.55 FileVault rotation disabled Escrow Buddy

Checklist for submitter

If some of the following don't apply, delete the relevant line.

  • Added/updated tests
  • Manual QA for all new/changed functionality
  • For Orbit and Fleet Desktop changes:
    • Orbit runs on macOS, Linux and Windows. Check if the orbit feature/bugfix should only apply to one platform (runtime.GOOS).
    • Manual QA must be performed in the three main OSs, macOS, Windows and Linux.
    • Auto-update manual QA, from released version of component to new version (see tools/tuf/test).

for https://github.com/fleetdm/confidential/issues/7522, support map is defined as:

|                | fleetd < v1.30                           | fleetd >= v1.30                          |
| -------------- | ---------------------------------------- | ---------------------------------------- |
| Server < 4.55  | OK/FileVault rotation uses system prompt | OK/FileVault rotation uses system prompt |
| Server >= 4.55 | FileVault rotation disabled              | Escrow Buddy                             |
@roperzh
roperzh marked this pull request as ready for review August 2, 2024 18:06
@roperzh
roperzh requested a review from a team as a code owner August 2, 2024 18:06
@roperzh
roperzh merged commit b294709 into main Aug 2, 2024
@roperzh
roperzh deleted the disable-fv-on-old-fleetd branch August 2, 2024 19:06
roperzh added a commit that referenced this pull request Aug 2, 2024
for https://github.com/fleetdm/confidential/issues/7522 and part of
#13157, support map is defined as:

| | fleetd < v1.30 | fleetd >= v1.30 |
| -------------- | ---------------------------------------- |
---------------------------------------- |
| Server < 4.55 | OK/FileVault rotation uses system prompt |
OK/FileVault rotation uses system prompt |
| Server >= 4.55 | FileVault rotation disabled | Escrow Buddy |

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
- For Orbit and Fleet Desktop changes:
- [ ] Orbit runs on macOS, Linux and Windows. Check if the orbit
feature/bugfix should only apply to one platform (`runtime.GOOS`).
- [ ] Manual QA must be performed in the three main OSs, macOS, Windows
and Linux.
- [ ] Auto-update manual QA, from released version of component to new
version (see [tools/tuf/test](../tools/tuf/test/README.md)).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants