The following changes were made in past Cryptographic Security Platform Vault releases.
- Changes in Release 10.5.3
- Changes in Release 10.5.1
- Changes in Release 10.4.7
- Changes in Release 10.4.5
- Changes in Release 10.4.3
- Changes in Release 10.4.1.1
- Changes in Release 10.4.1
- Changes in Release 10.3.1
- Changes in Release 10.2
- Changes in Release 10.1.1
- Changes in Release 10.1
- Changes in Release 10.0
For details about the current Cryptographic Security Platform Vault release and previous releases, visit trustedcare.entrust.com. If you do not have a login, please contact trustedcaresupport@entrust.com.
Changes in Release 10.5.3
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.6.1 from versions 10.5.1 and 10.5.3. For the Entrust Policy Agent, you can upgrade to 10.5.1 from versions 10.4.5, 10.4.7, 10.5.1, and 10.5.3.
Changes in this release:
- You can now encrypt multiple databases with one command.
- If you use geographically distributed nodes in your cluster and have performance issues, you can switch your master node to the server closest to where most data is generated.
- You can now choose which node will become the master node after the master node is removed from the cluster.
- You can now choose whether or not you want to enable audit logging for HYOK, EKM, and XKS operations at the Key Set level.
Changes in Release 10.5.1
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.5.1 from versions 10.4.3, 10.4.5, and 10.4.7. For the Entrust Policy Agent, you can upgrade to 10.5.1 from versions 10.4.3, 10.4.5, and 10.4.7.
Changes in this release:
- Licenses are now enforced in the Cryptographic Security Platform. You will see pop-up warnings in the webGUI when there are important license issues.
- Expanded support for Post-Quantum Encryption and Key Management, including support for ML-KEM, ML-DSA, and SLH-DSA keys, as well as encapsulation, decapsulation, sign, and verify operations using these keys. Also added improved PQ security for KMIP Server with support for PQ-TLS.
- You can now use KeySafe5 (part of the CSP appliance) to monitor your nShield HSM when configured with the Cryptographic Security Platform Vault.
Note: You can view the KeySafe5 GUI through the Cryptographic Security Platform Compliance Manager. - Azure updates including Multi-Vault keys and the ability to manage multiple Azure
- The Cryptographic Security Platform Vault for Cloud Keys now supports on-demand key rotation for AWS key versions with BYOK.
- The Cryptographic Security Platform Vault for Secrets now supports Microsoft SQL Server
- The Cryptographic Security Platform Vault for Secrets now supports EnterpriseDB Postgres.
- Added the Batch Encrypt, Batch Decrypt, and Batch encrypt-decrypt API and CLI commands in the Cryptographic Security Platform Vault for Cryptographic APIs.
- Added support for OCI users in non-default identity
- Added Authentication Inheritance, which enables Security Administrators to configure the Cryptographic Security Platform Vault Appliance with AD, OIDC, or OIDC with AD Authentication, and allows Vault Administrators to inherit that configuration in their vaults.
- Added the ImportClearKey API command in the Cryptographic Security Platform Vault for Cryptographic
- Made multiple enhancements to the Windows Policy Agent GUI, including support for TLS 3, increased launch speed, and reduced application size. You also have the ability to update mapping, perform encryption tasks on the drives, and view encryption details.
Changes in Release 10.4.7
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.4.7 from versions 10.4.1, 10.4.1.1, 10.4.3, and 10.4.5. For the Entrust Policy Agent, you can upgrade to 10.4.7 from versions 10.3.1, 10.3.3, 10.4.1, 10.4.1.1, 10.4.3, and 10.4.5.
Changes in this release:
The Cryptographic Security Platform Vault for Secrets now supports AWS user credential secrets.
The Cryptographic Security Platform Vault for Secrets now supports Postgres secrets.
Added support for EnterpriseDB (EDB) PostgreSQL Advanced Server.
Added support for AD groups.
Added mTLS authentication support for the Cryptographic Security Platform Vault for Cryptographic APIs and the Cryptographic Security Platform Vault for Secrets.
Changes in Release 10.4.5
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.4.5 from versions 10.4.1, 10.4.1.1, and 10.4.3. For the Entrust Policy Agent, you can upgrade to 10.4.5 from versions 10.3.1, 10.3.3, 10.4.1, 10.4.1.1, and 10.4.3.
Changes in this release:
KeyControl and KeyControl Compliance Manager have changed names.
KeyControl is now known as Cryptographic Security Platform Vault.
KeyControl Compliance Manager is now known as Cryptographic Security Platform Compliance Manager.
The KeyControl Vault for Application Security is now known as the Cryptographic Security Platform Vault for Cryptographic APIs.
If a CloudKey's cloud status is unavailable, you can remove it immediately using the Force Purge command.
You can now use certificate-based authentication with Azure BYOK.
You can now use BYOK and cache-only keys (HYOK) with Salesforce.
You can set up an automatic synchronization schedule to import all CloudKeys in a Key Set.
You can now cache your keys in the Cryptographic Security Platform Vault for Cryptographic APIs.
The Cryptographic Security Platform Vault for Secrets now supports Terraform secrets.
Cryptographic Security Platform Vault for Databases now supports column-level encryption for PostgreSQL.
You can now use mTLS authentication in the Cryptographic Security Platform Vault for Cryptographic APIs.
Changes in Release 10.4.3
Upgrade Path: For KeyControl, you can upgrade to 10.4.3 from versions 10.3.1, 10.3.3, 10.4.1, and 10.4.1.1. For the Policy Agent, you can upgrade to 10.4.1 from versions 10.3.1, 10.3.3, 10.4.1, and 10.4.1.1.
Changes in this release:
You can now use BYOK with Oracle Cloud Infrastructure (OCI).
You can now assign API users the BACKUP_USER role, which lets them manage backups but does not grant any other admin privileges.
Changes in Release 10.4.1.1
Release 10.4.1.1 is a cumulative release containing bug fixes and all new features from 10.4.1.
Upgrade Path: For KeyControl, you can upgrade to 10.4.1.1 from versions 10.3.1, 10.3.3, and 10.4.1. For the Policy Agent, you can upgrade to 10.4.1.1 from versions 10.3.1, 10.3.3, and 10.4.1.
Changes in Release 10.4.1
Version 10.4.1 is the first KeyControl release on Oracle Linux. The transition from CentOS to Oracle Linux allows Entrust to improve the security of the KeyControl operating system.
The main KeyControl components were ported directly to Oracle Linux and will continue to work as they did in earlier releases. The same applies to the KeyControl APIs.
Upgrade Path: For KeyControl, you can upgrade to 10.4.1 only from version 10.3.1. For the Policy Agent, you can upgrade to 10.4.1 from version 10.3.1.
Changes in this release:
Entrust KeyControl now runs on the Entrust-hardened version of Oracle Linux.
You can now use OpenID Connect (OIDC) Authentication with Active Directory in the KeyControl Vault Management appliance.
You can now use OpenID Connect (OIDC) Authentication without configuring Active Directory in the KeyControl Vault Management appliance.
AWS multi-Region keys are AWS KMS keys in different AWS Regions that can be used interchangeably. The KeyControl Vault for Cloud Keys now supports using AWS multi-region keys in BYOK.
The KeyControl Vault for Cloud Keys now supports Azure role-based access control (Azure RBAC) and the access policy model authorization system.
You can now use secondary approval with the KeyControl Vault for Secrets.
You can now use Personal Access tokens in your KeyControl Vaults that use OIDC for authentication as a password for API and CLI commands.
Added support for TLS 1.3 and Extended Master Secret (TLS). TLS 1.3 is the default for all new KeyControl installations.
You can now set KeyControl to use self-signed certificates for all nodes in a cluster.
The KeyControl appliance AMI now only supports Instance Metadata Service (IMDS) version 2 for AWS Cloud.
Changes in Release 10.3.1
Version 10.3.1 lays the groundwork for the upgrade to version 10.4.1, the first release of Cryptographic Security Platform Vault on Oracle Linux. The transition from CentOS to Oracle Linux allows Entrust to improve the security of the Cryptographic Security Platform Vault operating system, but it also requires a different migration path than previous Cryptographic Security Platform Vault upgrades.
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.3.1 from version 10.2. For the Entrust Policy Agent, you can upgrade to 10.3.1 from versions 10.2, 10.1.1, and 10.1.
Changes in this release:
You can now use OpenID Connect (OIDC) Authentication without configuring Active Directory in your individual KeyControl vaults.
You can now use Active Directory (AD) or OpenLDAP for authentication in the KeyControl Vault Management appliance.
AD users are supported, but not AD groups.
Two-factor authentication is supported for local users only.
Changes in Release 10.2
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.2 from versions 10.1 and 10.1.1. For the Entrust Policy Agent, you can upgrade to 10.2 from versions 10.1 and 10.1.1.
Changes in this release:
You can now use hardware security modules with the Cryptographic Security Platform Vault for Secrets.
You can now use BYOK with GCP in the Cryptographic Security Platform Vault for Cloud Keys.
You can now use MariaDB with TDE in the Cryptographic Security Platform Vault for Databases.
You can now use the HTTPS proxy server with BYOK for AWS and Azure.
Support for Double Key Encryption for Microsoft 365 in the Cryptographic Security Platform Vault for Cloud Keys.
Two-Factor Authentication is now offered with each Cryptographic Security Platform Vault.
Changes in Release 10.1.1
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.1 from versions 10.0 and 10.1. For the Entrust Policy Agent, you can upgrade to 10.1 from versions 10.0 and 10.1.
Changes in this release:
You can now upgrade KeyControl version 10.0 to KeyControl Vault 10.1.1.
You no longer need to enable (SMTP) in the Appliance Manager UI when adding KeyControl Vaults. This restriction was removed in the 10.1 release.
KeyControl Vault PASM vaults now support Ansible.
Changes in Release 10.1
Upgrade Path: You can only deploy Entrust Cryptographic Security Platform Vault 10.1 as a new installation. Upgrading from previous versions of Entrust Cryptographic Security Platform Vault is not supported.
Changes in this release:
New Entrust Cryptographic Security Platform Vault Architecture. The Entrust Cryptographic Security Platform Vault family of products has been divided into two components:
Cryptographic Security Platform Compliance Manager—This application handles all global requirements for your vaults, such as licensing and authorization.
Entrust Cryptographic Security Platform Vault—All of the Entrust Cryptographic Security Platform Vault applications have been separated and moved into individual vaults.
You manage licensing for all Entrust Cryptographic Security Platform Vaults using Cryptographic Security Platform Compliance Manager.
You can now use Cryptographic Security Platform Vault as an external key manager (EKM) provider for Oracle Server.
You can now use Cryptographic Security Platform Vault as an AWS KMS External Key Store (XKS).
You can now use the new Tokenization Vault and APIs for tokenization, masking, and data encryption.
You can now use Cryptographic Security Platform Vault with Azure-managed HSMs.
You can now configure Syslog Server to use ArcSight Common Event Format (CEF) for logging.
Cryptographic Security Platform Vault now supports Remote Administration Ready Smartcards for nShield HSMs.
Cryptographic Security Platform Vault now includes the Luna HSM library v10.5.1-174
Changes in Release 10.0
Upgrade Path: For Entrust Cryptographic Security Platform Vault, you can upgrade to 10.0 from versions 5.5 and 5.5.1. For the Entrust Policy Agent, you can upgrade to 10.0 from versions 5.3, 5.4, 5.5, and 5.5.1.
Changes in this release:
You can now use Cryptographic Security Platform Vault as an EKM provider for Microsoft SQL.
You can now use Cryptographic Security Platform Vault to manage your SSH keys.
You can now use Bring Your Own Key (BYOK) with Google Cloud Platform.
You can now use Cryptographic Security Platform Vault with nShield HSMs that are enrolled in FIPS 140 Level 3 Security Worlds.