See below for the changes in the 10.6.1 release.
- SNMP v3 Support
- Lenovo SR250/SR630 Appliance Deployment Support
- PKCS#11 Vault Support
- Microsoft External Key Manager Support
- Fine-Grained Administrative Roles and Permissions
- GitLab Secrets Vault Integration
- AWS IAM and STS Secrets Vault Integration
- Azure Entra ID Secrets Vault Integration
- Offline Cloud Encryption Key Generation
- OCI EKM Management Interface Decoupling
- Generic Authentication Error Responses
- ECDSA 384-bit Certificate and Trust Validation Enhancements
- Database Vault TDE and Platform Support Enhancements
- Vault Administrator Continuity and Alert Recipient Enhancements
- CSR Country Code Flexibility
- Interactive Swagger API Documentation
SNMP v3 Support
Added support for SNMP v3, SNMP v2c is no longer supported.
Lenovo SR250/SR630 Appliance Deployment Support
Added support for the deployment of the CSP Vault appliance on Lenovo SR250/SR630 physical server models.
PKCS#11 Vault Support
Implemented a new vault type and a lightweight client to add support for the PKCS#11 Cryptographic Token Interface Base Specification.
Microsoft External Key Manager Support
Added support for Microsoft's External Key Manager protocol.
Fine-Grained Administrative Roles and Permissions
Introduced fine-grained administrative roles and permission controls for CSP Vault appliance management tasks.
GitLab Secrets Vault Integration
Added GitLab integration for Secrets Vault, enabling CI/CD pipelines to securely retrieve and inject application credentials directly from Secrets Vault at runtime.
AWS IAM and STS Secrets Vault Integration
Introduced a dedicated Secrets Vault integration that enables secure storage and rotation of AWS IAM user access keys, as well as on-demand issuance of short-lived AWS STS session tokens and AssumeRole credentials with federated console sign-in.
Azure Entra ID Secrets Vault Integration
Added a dedicated Secrets Vault integration for securely storing and rotating Azure Entra ID (App Registration and Service Principal) credentials, including client secrets and certificates, and for issuing short-lived Azure AD access tokens on demand for Azure management and Microsoft Graph scopes.
Offline Cloud Encryption Key Generation
Added support for generating cloud encryption keys for AWS, Azure, GCP, Salesforce, and OCI offline within CSP Vault, eliminating the need for direct connectivity to the respective cloud providers.
OCI EKM Management Interface Decoupling
Decoupled Oracle Cloud Infrastructure External Key Management (OCI EKM) from the Cloud Key Vault management interface.
Generic Authentication Error Responses
Enhanced security by using generic authentication error responses across vaults to help prevent username enumeration.
ECDSA 384-bit Certificate and Trust Validation Enhancements
Enhanced certificate management and trust validation by adding support for ECDSA 384-bit certificates across internal and external web servers and KMIP servers, optimizing certificate chains to include only the required intermediate certificates, and enabling the use of custom CA certificates for email notification trust verification.
Database Vault TDE and Platform Support Enhancements
Enhanced Database Vault platform support by extending Transparent Data Encryption (TDE) capabilities to Oracle Exadata Cloud@Customer (ExaCC) environments, adding key export and import functionality for seamless TDE key forwarding between database instances, and expanding the officially tested database platform matrix to include PostgreSQL 18.
Vault Administrator Continuity and Alert Recipient Enhancements
Enhanced administrative continuity by allowing organizations to update or replace the primary Vault Administrator account when personnel changes occur, and by enabling email distribution lists (DLs) to be configured as alert recipients across all Vaults and appliances.
CSR Country Code Flexibility
Enhanced CSR generation flexibility by allowing empty or period ('.') values in the Country Code field during Web GUI certificate signing request (CSR) creation, improving compatibility with enterprise CA policies.
Interactive Swagger API Documentation
Replaced the API documentation at /apidoc with an interactive Swagger (OpenAPI 3.1) UI that lets you run APIs directly from the browser.