Fortanix Data Security Manager (DSM) 5.2.2859.3224 release provides an overview of general improvements.
This release is superseded by the December 15, 2025, release.
Fortanix DSM on-premises now supports the newly released FX3400 appliance.
WARNING
If you want to upgrade Fortanix DSM to version 5.2.2859.3224 from a version earlier than 4.36 patch 5, please contact the Fortanix Support team at your earliest to validate the upgrade path.
Downgrade from 5.2.2859.3224 to any prior version is not supported due to Kubernetes and Kernel upgrades.
NOTE
If you are using a custom sudo user, ensure that the default administrator user is enabled with root privileges before upgrading to Fortanix DSM version 5.2.2859.3224. The administrator user must be able to log in with a password and be part of the sudo group.
During the upgrade, the/etc/sudoersfile is overwritten, which can result in the loss of sudo access for the custom sudo user.In the case of Trusted Computing Base (TCB) recovery, platform registration may fail when an outbound proxy is set up. To resolve this, contact Fortanix Support to assist restarting the registration service.
The Fortanix DSM cluster upgrade must be done with Fortanix Support on call. Please reach out to Fortanix support if you are planning an upgrade.
The customer's BIOS version must be checked by Fortanix Support before the Fortanix DSM software upgrade. If required, the BIOS version should be upgraded to the latest version and verified by Fortanix Support for a smooth upgrade.
If your Fortanix DSM version is 5.0 or later, then the HSM Gateway version must also be 5.0 or later. Similarly, if the HSM Gateway version is 5.0 or later, then your Fortanix DSM version must be 5.0 or later.
1. Improvements
Disallow transforming a non-exportable BIP32 key into an exportable key. Transformed objects now inherit the export restrictions of their parent, ensuring the original export restrictions are preserved (JIRA: PROD-10562).
DCAP attestation for offline (air-gapped) cluster nodes can now be obtained without requiring direct access from the nodes to Intel’s cloud-based attestation service (JIRA: EXTREQ-768).
For more information, refer to Fortanix DSM DCAP Offline attestation guide.
For a complete list of new features, enhancements to existing features, other improvements, bug fixes, and known issues, refer to the full description of the DSM 5.2 release notes.
2. Installation
To install the DSM Runtime Encryption® SGX (on-prem/Azure) and Software (AWS/Azure) packages, Download Here.