# Check iSCSI client digest support before enforcing Elastic SAN CRC protection

> Volume-group checksum enforcement can reject clients that cannot supply the required header or data digests.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-295-check-iscsi-client-digest-support-before-enforcing-elastic-san-crc-protection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:01+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Volume-group checksum enforcement can reject clients that cannot supply the required header or data digests.

## Potentially affected

Azure Elastic SAN volume groups and iSCSI clients using their volumes.

## DSE recommendation

Verify every client's digest capabilities and configuration before enforcing CRC protection at volume-group scope.

## Article

## Source facts

Elastic SAN supports CRC-32C verification for iSCSI headers and data. A volume-group property can enforce it, and every volume in that group inherits the setting. With enforcement enabled, connections lacking the required digest configuration are rejected.

Microsoft warns that some operating systems lack header or data digest support, specifically identifying Fedora and downstream distributions as lacking data digests. It advises against enabling group enforcement for clients that cannot support those digests because their connections fail. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-networking).

## Applicability

Inventory all clients of the volume group, including less frequently used recovery or maintenance hosts. Verify support against the actual operating system and initiator configuration.

## DSE recommendation

DSE recommends a client-by-client compatibility record before a group-wide change. Resolve unsupported clients through an approved storage design rather than assuming they negotiate the new requirement automatically. Keep the previous setting and a controlled recovery plan available. Treat this as an integrity and connection-compatibility decision, not a replacement for reviewing the separate network-access configuration.

## Verification

In a controlled test, confirm the intended digest settings and reconnect representative supported clients. Check application reads and writes as well as session establishment. Record any rejected or unsupported client explicitly before extending enforcement to the shared group. A successful connection from one operating system is not sufficient evidence for the other clients that inherit the same volume-group policy.

## Official references

[Microsoft Learn: Azure Elastic SAN networking concepts](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-networking). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Elastic SAN networking concepts | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-networking
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check iSCSI client digest support before enforcing Elastic SAN CRC protection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-295-check-iscsi-client-digest-support-before-enforcing-elastic-san-crc-protection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
