PowerStore Alerts: Platform STIG Enable Required alert
Summary: This KB explains the Platform Security Technical Implementation Guide (STIG) Enable Required alert.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
When Dell PowerStore encounters a problem, an error alert is generated to help identify the issue. This article explains the different possible causes and the relevant solutions for these error alerts. If your problem is not resolved despite the solution that is provided, check the technical support contact options.
Note: Cannot find the information that you need? Let us know using the feedback form at the bottom of this article.
Cause
The cause is mentioned in the Resolution section under the respective alerts.
Resolution
| Alert ID | PLATFORM_STIG_ENABLE_REQUIRED_REQUIRED |
| Alert Text | System partitions must be encrypted as part of STIG compliance. |
| Error Code | 0x00400A01 |
| Description | When a STIG enabled system is updated from a pre PowerStoreOS 4.1.0 release to PowerStoreOS 4.1.0, the root partition is not encrypted. STIG must be reenabled to bring the system into full compliance. |
| Impact | There is no impact to host I/O. The appliance must have a new mitigation applied related to encryption of the root partition. This enhances the STIG security policy to meet another requirement. |
| Resolution | Cause: PowerStoreOS 4.1.0 introduces root partition encryption. Solution: Reenable STIG over REST or PowerStore CLI. Using PowerStoreCLI: pstcli -user admin -password <Password> -destination <IP> security_config -id 1 set -is_stig_enabled true -asyncUsing RestAPI: curl -sk 'https://<system ip>/api/rest/security_config/1?is_async=true' --user <user:password> -X PATCH -d '{"is_stig_enabled": true}' -H 'Content-Type: application/json' | jq '.' |
Each controller reboots one at a time to complete the root partition encryption.
To confirm that the root partition is encrypted, run the svc command svc_compliance_mode status and both STIG and RPE should show ENABLED.
[SVC:service@lab-b user]$ svc_compliance_mode status
STIG is currently ENABLED.
RPE is currently ENABLED.
The alert for PLATFORM_STIG_ENABLE_REQUIRED_REQUIRED clears on its own once the root partition encryption is complete.
Affected Products
PowerStoreArticle Properties
Article Number: 000247120
Article Type: Solution
Last Modified: 03 Sept 2025
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.