Fortanix Data Security Manager (DSM) 4.34.2575 release provides an overview of improvements and resolved issues.
WARNING
You are REQUIRED to upgrade Fortanix DSM to version 4.27 or 4.31 before upgrading to version 4.34.2575. If you want to upgrade Fortanix DSM to version 4.34.2575 from a version earlier than 4.27, please contact the Fortanix Support team at your earliest to validate the upgrade path.
Downgrade from 4.34.2575 to any prior version is not supported due to the DCAP migration.
You may observe delay (retries) in bringing up services post upgrade to DSM 4.34.2575 due to a new table creation in the database to support the new Key Expiry Alert feature. For more details, contact Fortanix Support.
For 1-node cluster, the upgrade path must be 4.27 to 4.31 and 4.31 to 4.34.2575.
For 3-node clusters, the upgrade path must be 4.27 to 4.34.2575.
NOTE
The Fortanix DSM cluster upgrade must be done with Fortanix Support on call. Please reach out to Fortanix support if you are planning an upgrade.
The customer's BIOS version must be checked by Fortanix Support before the Fortanix DSM software upgrade. If required, the BIOS version should be upgraded to the latest version and verified by Fortanix Support for a smooth upgrade.
If your Fortanix DSM version is 4.31 or later, then the HSM Gateway version must also be 4.31 or later. Similarly, if the HSM Gateway version is 4.31 or later, then your Fortanix DSM version must be 4.31 or later.
1. Improvements
Improved the query of keys in KMIP Locate (JIRA: PROD-10177).
2. Bug Fixes
Fixed an issue that allowed a user with a restrictive custom role (for example,
UPDATE_ADMIN_APPS) to escalate privileges by updating an administrative application’s (app's) credentials and assigning it a more powerful role (for example, a role with all permissions in the account) (JIRA: PROD-10315).Fixed an issue where if an app belongs to more than 1000 groups, adding a new group to the app fails (JIRA: ES-499).
Fixed Fortanix DSM user interface (UI) performance issues when loading groups and apps if an account has more than 1000 groups and apps (JIRA: ES-500).
3. Quality Improvements
Upgraded the FX2200 Series 2 BIOS version to F16 and CPU microcode to 0xFA (JIRA: DEVOPS-5600).
4. Security Improvements
Updated Intel SGX attestation verification logic to correctly interpret potential future attestation evidence and endorsements from Intel. As of the publication date of these release notes, Intel has not published any evidence or endorsements that would cause security issues with the previous logic (JIRA: RTE-308, RTE-450, RTE-447).
For a complete list of new features, enhancements to existing features, other improvements, bug fixes, and known issues, refer to the full description of the DSM 4.34 release notes.
5. Installation
To install the DSM Runtime Encryption® SGX (on-prem/Azure) and Software (AWS/Azure) packages, Download Here.