Fortanix Data Security Manager (DSM) 5.8.2976.3589 release provides an overview of new features, improvements, quality enhancements, and resolved issues.
WARNING
If you want to upgrade Fortanix DSM to version 5.8.2976.3589, your current DSM version must be at 5.7 Patch 1* or 5.6 Patch 3*.
Downgrade from 5.8.2976.3589 to 5.7 Patch 1* and 5.6 Patch 3* is supported.
*The minimum required version is specific to your current major.minor version. You must first upgrade to the required patch level within your current version before proceeding to version 5.8.2976.3589.
NOTE
The Fortanix DSM cluster upgrade must be done with Fortanix Support on call. Please reach out to Fortanix Support if you are planning an upgrade.
The customer's BIOS version must be checked by Fortanix Support before the Fortanix DSM software upgrade. If required, the BIOS version should be upgraded to the latest version and verified by Fortanix Support for a smooth upgrade.
If your Fortanix DSM version is 5.7 or later, then the HSM Gateway version must also be 5.7 or later. Similarly, if the HSM Gateway version is 5.7 or later, then your Fortanix DSM version must be 5.7 or later.
1. New Features
Added UI support for Azure Monitor Log Ingestion API logging configurations, enabling DSM audit logs to be ingested into Azure Monitor using the Log Ingestion API as an alternative to the legacy Azure Log Analytics Data Collector API. Users can configure the new integration under Account Settings → Log Management → Custom Log Management Integrations (JIRA: PM-664).
For more information, refer to Logging.
NOTE
The Azure Monitor Log Ingestion API integration is not supported for System Administration → Settings → LOG MANAGEMENT (Sysadmin account). For Sysadmin account logging, continue using the legacy Azure Log Analytics Data Collector API integration. This limitation applies only to the Sysadmin account; all regular DSM accounts can use the Azure Monitor Log Ingestion API integration.
2. Enhancements
Added COPY OCI VAULT EKM KEY ID and COPY OCI VAULT EKM KEY VERSION ID options to the security object COPY ID drop down menu. These options copy the security object “Name” as the OCI Vault EKM Key ID and the security object “UUID” as the OCI Vault EKM Key Version ID (JIRA: PM-701).
.png?sv=2026-02-06&spr=https&st=2026-09-21T02%3A29%3A23Z&se=2026-09-21T02%3A42%3A23Z&sr=c&sp=r&sig=8Bv3QjyfzIwkIMzOZsPJF3fgXuvijyE0ixnDpPO0cGg%3D)
For more information, refer to Oracle Cloud Infrastructure KMS Bring Your Own Key.
3. Other Improvements
Enhanced the performance of DSM cryptographic operations by incorporating cryptographic library performance optimizations (JIRA: PROD-11541).
4. Quality Enhancements
Updated the BIOS for the Fortanix FX3400 appliances to include the latest Intel microcode and associated firmware updates required for IPU 2026.3 compatibility (JIRA: RODE-473).
Updated the BIOS to version 11.13.FP01 for Fortanix FX3400 appliances, resolving an issue where installed memory Dual In-line Memory Module (DIMMs) could be incorrectly detected (JIRA: RODE-474).
5. Bug Fixes
Fixed an issue that prevented certain Nutanix clusters from integrating with DSM 5.7 through KMIP when the Nutanix KMS client included key operations in its requests that are not supported by DSM (JIRA: ES-647).
Fixed an issue where the
sdkmspod could become stuck in theContainerCreatingstate during an upgrade to Fortanix DSM 5.7 (JIRA: ES-637).Fixed an issue where DSM returned an incorrect HTTP error response for cryptographic operations on disabled security objects when using the OCI Vault EKM integration (JIRA: PROD-11536).
6. Security Fixes
Improved email address and domain verification for user sign-up, invitations, and email address updates (JIRA: PROD-11325).
Updated Linux kernel from 6.8.0-124 to 6.8.0-136 to improve system stability and ensure alignment with the latest upstream kernel fixes (JIRA: RODE-583).
Improved the security of LDAP integrations by using Integration Credentials to securely manage LDAP service account credentials. The LDAP integration configuration under Account Settings → AUTHENTICATION → SINGLE SIGN-ON → ADD LDAP INTEGRATION now includes a Fortanix DSM Group field in the Add service account section for configuring Integration Credentials (JIRA: PROD-11428 & ROFR-5990).
.png?sv=2026-02-06&spr=https&st=2026-09-21T02%3A29%3A23Z&se=2026-09-21T02%3A42%3A23Z&sr=c&sp=r&sig=8Bv3QjyfzIwkIMzOZsPJF3fgXuvijyE0ixnDpPO0cGg%3D)
For a complete list of new features, enhancements to existing features, other improvements, bug fixes, and known issues, refer to the full description of the DSM 5.8 release notes.
7. Installation
To install the DSM Runtime Encryption® SGX (on-prem/Azure) and Software (AWS/Azure) packages, Download Here.