Skip to content

Commit 8bcfe8f

Browse files
[Elastic Agent] Add a known issue for DEB/RPM upgrades failing when Agent tamper protection is enabled (#2668)
This PR adds a known issue for DEB/RPM upgrades failing when "Agent tamper protection" is enabled. Closes #2636
1 parent 1eb144c commit 8bcfe8f

File tree

1 file changed

+38
-4
lines changed

1 file changed

+38
-4
lines changed

release-notes/fleet-elastic-agent/known-issues.md

Lines changed: 38 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ navigation_title: Known issues
33
---
44

55
# {{fleet}} and {{agent}} known issues [fleet-elastic-agent-known-issues]
6+
67
Known issues are significant defects or limitations that may impact your implementation. These issues are actively being worked on and will be addressed in a future release. Review the {{fleet}} and {{agent}} known issues to help you make informed decisions, such as upgrading to a new version.
78

89
% Use the following template to add entries to this page.
@@ -17,9 +18,42 @@ Known issues are significant defects or limitations that may impact your impleme
1718

1819
% :::
1920

21+
:::{dropdown} Manual DEB/RPM upgrades of {{fleet}}-managed agents fail when "Agent tamper protection" is enabled
22+
23+
**Applies to**: {{agent}} 8.19.2, 9.1.2
24+
25+
On August 19, 2025, a known issue was discovered where manual DEB/RPM upgrades of {{fleet}}-managed {{agents}} fail if the {{elastic-defend}} integration is installed and **Agent tamper protection** is enabled in the agent policy. When this occurs, the log contains an output similar to the following:
26+
27+
```
28+
Invalid uninstall token: exit status 28
29+
```
30+
31+
This issue only impacts manual DEB/RPM upgrades from {{agent}} 8.19.2 or 9.1.2. Managed upgrades performed through {{fleet}} are not affected.
32+
33+
For more information, refer to [PR #9462](https://github.com/elastic/elastic-agent/pull/9462).
34+
35+
**Workaround**
36+
37+
You can use one of the following workarounds to resolve the issue:
38+
39+
- Stop the `elastic-agent` service:
40+
41+
Before installing the {{agent}} DEB/RPM package, run `systemctl stop elastic-agent`, then proceed with the installation. This solution works even when reinstalling the same version of {{agent}}.
42+
43+
- Temporarily remove the {{elastic-defend}} integration:
44+
45+
Before upgrading, move the agent to an agent policy without the {{elastic-defend}} integration. Wait for the change to take effect, proceed with the upgrade, then move the agent to its previous policy.
46+
47+
- Disable **Agent tamper protection**:
48+
49+
Before upgrading, disable **Agent tamper protection** in the agent policy. Wait for the change to take effect, proceed with the upgrade, then move the agent back to its previous policy.
50+
51+
**Fixed in**: {{agent}} 8.19.3, 9.1.3
52+
:::
53+
2054
:::{dropdown} [Windows] {{agent}} does not process Windows security events
2155

22-
**Applies to: {{agent}} 8.19.0, 9.1.0 (Windows only)**
56+
**Applies to**: {{agent}} 8.19.0, 9.1.0 (Windows only)
2357

2458
On August 1, 2025, a known issue was discovered where {{agent}} does not process Windows security events on hosts running Windows 10, Windows 11, and Windows Server 2022.
2559

@@ -32,7 +66,7 @@ No workaround is available at the moment, but a fix is expected to be available
3266

3367
:::{dropdown} {{agents}} remain in an "Upgrade scheduled" state
3468

35-
**Applies to: {{agent}} 8.18.0, 8.18.1, 8.18.2, 8.18.3, 8.18.4, 8.19.0, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.1.0**
69+
**Applies to**: {{agent}} 8.18.0, 8.18.1, 8.18.2, 8.18.3, 8.18.4, 8.19.0, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.1.0
3670

3771
On July 2, 2025, a known issue was discovered where {{agent}} remains in an `Upgrade scheduled` state when a scheduled {{agent}} upgrade is cancelled. Attempting to restart the upgrade on the UI returns an error: `The selected agent is not upgradeable: agent is already being upgraded.`.
3872

@@ -65,7 +99,7 @@ curl --request POST \
6599

66100
:::{dropdown} [Windows] {{agent}} is unable to re-enroll into {{fleet}}
67101

68-
**Applies to: {{agent}} 9.0.0, 9.0.1, 9.0.2 (Windows only)**
102+
**Applies to**: {{agent}} 9.0.0, 9.0.1, 9.0.2 (Windows only)
69103

70104
On April 9, 2025, a known issue was discovered where an {{agent}} installed on Windows and previously enrolled into {{fleet}} is unable to re-enroll. Attempting to enroll the {{agent}} fails with the following error:
71105

@@ -91,7 +125,7 @@ Until a bug fix is available in a later release, you can resolve the issue tempo
91125

92126
:::{dropdown} [macOS] Osquery integration fails to start on fresh agent installs
93127

94-
**Applies to: {{agent}} 9.0.0 and 9.0.1 (macOS only)**
128+
**Applies to**: {{agent}} 9.0.0 and 9.0.1 (macOS only)
95129

96130
On May 26th, 2025, a known issue was discovered that causes the `osquery` integration to fail on new {{agent}} installations on macOS. During the installation process, the required `osquery.app/` directory is removed, which prevents the integration from starting.
97131

0 commit comments

Comments
 (0)