--- title: "[5.3] - September 25, 2025" slug: "5-3-september-25-2025" updated: 2026-08-19T06:27:53Z published: 2026-08-19T06:27:53Z canonical: "support.fortanix.com/5-3-september-25-2025" --- > ## Documentation Index > Fetch the complete documentation index at: https://support.fortanix.com/llms.txt > Use this file to discover all available pages before exploring further. # [5.3] - September 25, 2025 Fortanix Data Security Manager (DSM) SaaS 5.3 includes some exciting new features and general improvements. > [!NOTE] > NOTE > > This release is for **SaaS only** and is not available for on-premises installations. Updates in this release will be part of a future on-premises release. ## 1. New Features - Fortanix DSM now supports SLIP10 wallet key derivation using NIST P-256 curves **(JIRA: EXTREQ-1463)**. ![Screenshot (2320).png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/41231882192404) *For more information, refer to the* [*User's Guide: Fortanix Data Security Manager Key Lifecycle Management*](/v1/docs/fortanix-data-security-manager-key-lifecycle-management)*.* - Fortanix DSM now supports managing RSA keys in Google Cloud Platform (GCP) Key Management System (KMS) **(JIRA: EXTREQ-1255)**. - Generate, import, and copy keys (Bring Your Own Key) into GCP KMS. ![GCP-RSA-Generate.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/41231882193428) ![GCP-RSA-Import.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/41231869469076) ![GCP-Rotate.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/41494732983188) - Rotate keys in GCP KMS. ![GCP-Rotate1.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/41494732984852) *For more information, refer to the following guides:* - [*Fortanix Data Security Manager GCP KMS Bring Your Own Key User Guide*](/v1/docs/fortanix-dsm-google-cloud-kms) - [*Fortanix Data Security Manager GCP KMS Cloud Native Key Management User Guide*](/v1/docs/fortanix-dsm-gcp-kms-cnkms-keyring-setup-user-guide) - Fortanix DSM now adds additional authentication failure logs for Key Management Interoperability Protocol (KMIP) to the system log **(JIRA:EXTREQ-972)**. - Added **Learn Mode** toggle in the **FILE DECRYPTION POLICY** tab of Fortanix DSM for Filesystem Encryption Windows and Linux. This feature allows temporary access to guarded paths while capturing detailed audit logs to help administrators refine security policies **(JIRA: FSE-488)**. *For more information, refer to the following guides:* - [*Filesystem Encryption for Linux Using Fortanix Data Security Manager - Policies*](/v1/docs/filesystem-encryption-for-linux-using-fortanix-data-security-manager-policies#90-learn-mode) - [*Filesystem Encryption for Windows as a Service Using Fortanix Data Security Manager - Policies*](/v1/docs/filesystem-encryption-windows-service-fortanix-data-security-manager-policies#80-learn-mode) ## 2. Improvements - Improved the account name visibility where the full account names are now displayed on hover, making it easier to identify and select the correct account **(JIRA: EXTREQ-1197)**. ![Screenshot (2321).png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/41231921760788) ## 3. Client Improvements - Implemented an automatic retry mechanism in Sequoia DSM (**JIRA: ES-532**). - Added support for additional Linux platforms in Sequoia DSM, including RHEL 9 and SUSE 15 (**JIRA: PROD-10574**). ## 4. DSM Accelerator New Features - **DSM Accelerator Webservice SGX** *For more information, refer to the following guides:* - Added support for running Fortanix DSM Accelerator Webservice on Intel® Software Guard Extensions (SGX) (**JIRA: PM-16**). - [*DSM Accelerator Webservice on SGX*](/v1/docs/dsm-accelerator-webservice-on-sgx) - [*DSM Accelerator Webservice on SGX Deployment Guide*](/v1/docs/dsm-accelerator-webservice-deployment-on-sgx) ## 5. API Updates - Added support for RSA keys in Google Cloud Platform (GCP) Bring Your Own Key (BYOK), allowing you to specify the key `protection_level` (for example, `Software` or `HSM`) as part of the key's `custom_metadata`**(JIRA: EXTREQ-1255)**. - This enhancement applies to all APIs involving `SobjectRequest` and `SobjectResponse`, specifically for `Sobjects` in Cloud Data Control (CDC) GCP-backed groups that are part of the GCP BYOK setup. - Added support for SLIP10 hierarchical deterministic keys through `Slip10 sobjects` in Fortanix DSM, in addition to existing BIP32 keys. You can now derive SLIP10 keys (master, hardened, and non-hardened) on NistP256 and SecP256K1 curves, and import or export them in SLIP-32 format, as well as sign and verify with them **(JIRA: EXTREQ-1463)**. This enhancement affects the following APIs: - Derive a new key from an existing key: `POST /crypto/v1/derive` - Transform an existing key into a new one: `POST /crypto/v1/transform` - Sign with a private key: `POST /crypto/v1/sign` - Verify a signature with a public key: `POST /crypto/v1/verify` - Get the details and value of a particular exportable security object: `POST /crypto/v1/keys/export` - Import a security object: `PUT /crypto/v1/keys ` ## 6. Known Issues - Deriving SLIP10 keys fails if a Cryptographic policy is set at the Fortanix DSM account or group level. Additionally, copying SLIP10 keys is currently not supported **(JIRA: PROD-10767)**. **Workaround**: To derive a SLIP10 key, temporarily delete the account- or group-level Cryptographic policy, perform the key derivation, and then reapply the Cryptographic policy. - After upgrading Fortanix DSM to version 5.0, Network Time Protocol (NTP) checks in Sensu may fail even if NTP is correctly synchronized across the cluster **(JIRA: RODE-168)**. > [!NOTE] > NOTE > > Use the following command to override the alert: > > ```plaintext > check-ntp.rb -u ok -w ${WARN_LEVEL} -c ${CRITICAL_LEVEL}" \ > ``` - The **COPY KEY** dialog box does not filter the HSM/External KMS groups as expected when **Import key to HSM/External KMS** check box is selected, if there are more than 1,000 groups in the account **(JIRA: ROFR-5167)**. - Unable to delete a user who was invited to an account with a "Custom account role" that includes an "All Groups Role" along with group membership assigned explicitly in the invite user workflow if the invited user has not accepted the invitation **(JIRA: PROD-9409)**. **Workaround**: To delete the invited user, contact Fortanix Support or perform the following steps: - If you have already assigned explicit group memberships, perform the following steps to remove them and delete the user: - Change the user's account role to "Account Member". - Remove the group memberships one by one using the user interface. - Delete the user. - The `sudo get_csrs --rotate` command does not support changing the hostname of the service URL. For example, if your service main URL is dsm.fortanix.net, you cannot change this main URL hostname **(JIRA: PROD-9542)**. - When you run `sudo get_csrs --rotate` command to create a new certificate pair for cluster and UI, it does not remove the old certificate pair from the sdkms pod resulting in two certificate pairs which can lead to unexpected results **(JIRA: PROD-9570)**. - Deleting replica keys in groups with key history policies only results in a soft-delete of the keys **(JIRA: PROD-9925)**. **Workaround**: Users should avoid deleting keys that are associated with a key-undo policy. - The **Audit Log** page in Fortanix DSM does not display recent “Select Account” events when the log retention period is set to 1 day (**JIRA: PROD-10441**). **Workaround**: Set the retention period to 2 days or longer under **Settings → LOG MANAGEMNET → Retention period for Audit Logs** to ensure recent audit log entries are visible. - Unable to perform Kubernetes CA rotation successfully **(JIRA: RODE-62)**. **Workaround**: To perform CA rotation in DSM versions 4.36 and higher, contact the Fortanix Support team.