[5.10] DSM - September 23, 2026

Prev Next


Fortanix Data Security Manager (DSM) SaaS 5.10 includes some enhancements and resolved issues.

NOTE

This release is for SaaS only and is not available for on-premises installations. Updates in this release will be part of a future on-premises release.

1. Enhancements

  • Fortanix DSM user interface (UI) now displays the Tenant ID and User ID along with other OCI Vault configuration details in the HSM/KMS tab for the OCI Vault backed groups (JIRA: ROFR-6094).

  • Added session authentication logging for Key Management Interoperability Protocol (KMIP) connections to capture successful and failed authentication attempts for valid applications using username-password, app name, certificate-only, and AWS IAM authentication methods, aligning session authentication logging with KMIP authentication logging (JIRA: PROD-11601).

  • Enhanced the email address change flow in the Fortanix DSM My Profile page to require password verification. Users must now enter their current password in the DSM UI before the new email address is updated, to prevent unauthorized email address changes (JIRA: PM-722). For more information, refer to Updating the Email Address.

2. Bug Fixes

  • Fixed an issue where key export incorrectly displayed a successful status when cryptographic operations were not enabled in the applicable Group Quorum approval policy (JIRA: ROFR-5961).

  • Fixed an issue where the security objects created in DSM CDC groups for Oracle Cloud Infrastructure (OCI) during key rotation displayed the creation date of the parent key instead of the creation date of the corresponding key version in OCI Vault (JIRA: ES-663).

  • Fixed an issue where adding a new Salesforce BYOK integration instance from the DSM Integrations tab installed plugin version 1.0 instead of the current version 1.2 available in the Plugin Library (JIRA: ES-652).

3. Known Issues

  • The DSM Salesforce plugin may fail during the upload operation because the generated SF_KEK name does not match the corresponding Salesforce certificate name, resulting in an INVALID_CROSS_REFERENCE_KEY or "Failed wrapper lookup" error (JIRA: ES-261).

  • If an Azure Log Ingestion – Azure Monitor integration is created with incorrect or incomplete details, the integration may fail after the Azure Log Secret Key has already been created. Deleting the Azure Log Secret Key from the user interface (UI) does not remove this credential, preventing subsequent integration creation (JIRA: ROFR-6127).

    Workaround:

    • Create a DSM Admin App and use its credentials to run the following command:

      GET {{azure_host}}/sys/v1/credentials/ to identify the relevant credential_id
    • Delete the credential using the following command:

      DELETE {{azure_host}}/sys/v1/credentials/{credential_id}
    • Create the Azure Log Ingestion integration again.

  • When users edit a quorum approval policy configured with multiple reviewers, DSM may display the Using second factor security key is required to approve requests check box as unchecked in the Quorum approval policy screen, even though multi-factor authentication (MFA) enforcement continues to work as expected (JIRA: PROD-11444).

  • A Fortanix DSM account, whether normal or system administrator, with the "No Roles Can Login with Password" role selected, may experience issues when attempting to log in using a password. If the users select such an account and enter the SSO credentials, they will be logged out instead of accessing the account (JIRA: ROFR-4998).
    Workaround: The users should log in directly with SSO after the "No Roles Can Login with Password" role is set to access the account.

  • The COPY KEY dialog box does not filter the HSM/External KMS groups as expected when Import key to HSM/External KMS check box is selected, if there are more than 1,000 groups in the account (JIRA: ROFR-5167).

  • Unable to delete a user who was invited to an account with a "Custom account role" that includes an "All Groups Role" along with group membership assigned explicitly in the invite user workflow if the invited user has not accepted the invitation (JIRA: PROD-9409).
    Workaround: To delete the invited user, contact Fortanix Support or perform the following steps:

    • If you have already assigned explicit group memberships, perform the following steps to remove them and delete the user:

      • Change the user's account role to "Account Member".

      • Remove the group memberships one by one using the user interface.

      • Delete the user.

  • Deleting replica keys in groups with Key undo policies is reversible using the undo operation (JIRA: PROD-9925).
    Workaround: Users should avoid deleting keys that are associated with a key-undo policy.

  • Unable to perform Kubernetes CA rotation successfully (JIRA: RODE-62).
    Workaround: To perform CA rotation in DSM 5.2 and higher, contact the Fortanix Support team.

  • When Fortanix DSM contains a large number of objects (for example, ~1000 groups, plugins, apps, and users, and ~11,000 security objects), certain UI pages may load slower than usual (JIRA: PROD-11135).
    Workaround: There is currently no direct workaround. As a mitigation, it is recommended to reduce the number of objects displayed using filters or pagination and use APIs for bulk operations instead of UI navigation in large-scale environments.

Fortanix-logo

4.6

star-ratings

As of August 2025