--- title: "PKCS#11 Changelog" slug: "pkcs-11-changelog" updated: 2026-08-19T08:28:32Z published: 2026-08-19T08:28:32Z canonical: "support.fortanix.com/pkcs-11-changelog" --- > ## Documentation Index > Fetch the complete documentation index at: https://support.fortanix.com/llms.txt > Use this file to discover all available pages before exploring further. # PKCS#11 Changelog > [!NOTE] > NOTE > > It is recommended to update the PKCS#11 library to the latest available version. ## New Features, Improvements, and Bug Fixes ### [[5.8.2962] - July 09, 2026 (Latest)](/v1/docs/pkcs-11-5-8-2962-latest) - Added Certificate Authentication support for Fortanix PKCS#11 library on Microsoft Windows **(JIRA: PM-678)**. - Provided a workaround for a panic or crash observed in PKCS#11 flow when using OpenSSL provider with PQC algorithms **(JIRA: PM-679)**. - Fixed PKCS#11 library hangs observed during API requests made to DSM when connectivity to DSM was interrupted, improving keepalive duration and timeout handling **(JIRA: ES-687)**. ### [[5.7.2954] - May 25, 2026](/v1/docs/pkcs-11-5-7-2954) - Added support for importing a wrapped key pair into Fortanix DSM using the Fortanix PKCS#11 library (**JIRA: ES-615**). - Upgraded the Fortanix PKCS#11 library from 3.0 to 3.2 and added support for ML-DSA algorithm (**JIRA: EXTREQ-1518**). - Enhanced Fortanix PKCS#11 library error handling to return more specific and appropriate error codes (**JIRA: EXTREQ-1222**). - Enhanced the Fortanix PKCS#11 library with the following (**JIRA: PROD-11233**): - Added sanity checks for `C_SignInit`. - Fixed `no CKF_RW_SESSION` scenario in `C_GetSessionInfo`. - Fixed an issue in the Fortanix PKCS#11 library on Linux where the last intermediate certificate was missed during server certificate chain revocation checks(**JIRA: ES-620**). - Fixed an issue in the Fortanix PKCS#11 library on Windows where the last intermediate certificate was missed during server certificate chain revocation checks (**JIRA: ES-621**). ### [[5.6.2919] - February 26, 2026](/v1/docs/pkcs-11-5-6-2919) - Added the following in the PKCS#11 library (**JIRA: EXTREQ-1222**): - Added support for the `CKA_PUBLIC_KEY_INFO` attribute in the `PKCS#11` library to retrieve the associated public key of the asymmetric keys using C_GetAttributeValue. - Updated `CKA_SIGN` and `CKA_VERIFY` attribute handling for symmetric keys based on `MACGENERATE` and `MACVERIFY` permissions. ### [[5.5.2909] - July 07, 2026](/v1/docs/pkcs-11-5-5-2909) - Fixed an issue where PKCS#11 operations against the Hardware Security Module (HSM) were failing with the `CKR_KEY_FUNCTION_NOT_PERMITTED (104)` error (**JIRA: ES-585**). - Added server certificate revocation checks to the Fortanix PKCS#11 library when connecting to Fortanix DSM (**JIRA: EXTREQ-1377**). - Updated the following in the Fortanix PKCS#11 library (**JIRA: PM-478**): - `CKA_START_DATE` and `CKA_END_DATE` attributes are mapped to the key activation date and deactivation date. These attributes can be retrieved using `C_GetAttributeValue` but cannot be modified using `C_SetAttributeValue`. - The `CKA_CHECK_VALUE` attribute is mapped to the Key Checksum Value (KCV) for symmetric keys and can be retrieved using `C_GetAttributeValue`. - Existing key operations can be removed after key creation through PKCS#11 using `C_SetAttributeValue`. ### [[5.4.2891] - October 31, 2025](/v1/docs/pkcs-11-5-4-2891) No Changes ### [[5.3.2861] - September 25, 2025](/v1/docs/pkcs-11-5-3-2861) - PKCS#11 support on RHEL 7 is deprecated starting with Fortanix DSM 5.2 and later versions. ### [[5.2.2852] - August 11, 2025](/v1/docs/pkcs-11-5-2-2852) No Changes ### [[5.1.2830] - July 15, 2025](/v1/docs/pkcs-11-5-1-2830) - Fixed the logic for sending a terminate signal to the session refresh loop associated with the particular HSM slot that was failing occasionally due to a race condition between the signal-issuing thread and the session refresh loop. ### [[5.0.2817] - May 27, 2025](/v1/docs/pkcs-11-5-0-2817) - Fixed performance issues caused by frequent `C_GetAttributeValue` calls in the PKCS#11 wrapper (**JIRA: PROD-9983**). ### [Release 4.37.2554](/v1/docs/pkcs-11-4-37-2554) - Enhanced performance for "Key Generation" and "Key Search" operations using the Fortanix DSM PKCS#11 client (**JIRA: PROD-9801**). ### [Release 4.36.2530](/v1/docs/pkcs-11-4-36-2530) - Added support for Fortanix DSM PKCS#11 client, allowing users to toggle a flag that automatically includes the `EXPORT` permission in every key creation request. This enhancement ensures proper usage of replicated accounts in disaster recovery scenarios (**JIRA: PROD-9217**). ### [Release 4.35.2513](/v1/docs/pkcs-11-4-35-2513) - Added support in the Fortanix DSM PKCS#11 client to immediately close the refresh thread upon session termination (**JIRA: PROD-9428**). ### [Release 4.34.2503](/v1/docs/dsm-accelerator-pkcs-11-4-34-2503) - Fixed an issue in the Fortanix DSM PKCS#11 client where multipart encryption failed when invoking `C_EncryptUpdate` with a `NULL_PTR` in a package buffer file (pBuf) **(JIRA: PROD-9262)**. ### [Release 4.33.2492](/v1/docs/pkcs-11-4-33-2492) No Changes ### [Release 4.32.2476](/v1/docs/pkcs-11-4-32-2476) - Added support in the PKCS#11 client for key or certificate authentication with Fortanix DSM using a password-protected private key file **(JIRA PM-333)**. ### [Release 4.31.2462](/v1/docs/pkcs-11-4-31-2462) No Changes ### [Release 4.30.2447](/v1/docs/pkcs-11-4-30-2447) No Changes ### [Release 4.29.2426](/v1/docs/pkcs-11-4-29-2426) - Added quorum policy approval support for the Fortanix DSM PKCS#11 client (**JIRA: PM-226**). ### [Release 4.28.2410](/v1/docs/pkcs-11-4-28-2410) No Changes ### [Release 4.27.2394](/v1/docs/pkcs-11-4-27-2394) No Changes ### [Release 4.26.2384](/v1/docs/pkcs-11-4-26-2384) No Changes ### [Release 4.25.2353](/v1/docs/pkcs-11-4-25-2353) No Changes ### [Release 4.24.2343](/v1/docs/pkcs-11-4-24-2343) No Changes ### [Release 4.23.2328](/v1/docs/pkcs-11-4-23-2328) No Changes ### [Release 4.22.2307](/v1/docs/pkcs-11-4-22-2307) No Changes ### [Release 4.21.2288](/v1/docs/pkcs-11-4-21-2288) - The DSM PKCS#11 library now integrates with Docker Notary (**JIRA: PROD-6517**). ### [Release 4.20.2276](/v1/docs/pkcs-11-4-20-2276) No Changes ### [Release 4.19.2244](/v1/docs/pkcs-11-4-19-2244) No Changes ### [Release 4.18.2231](/v1/docs/pkcs-11-4-18-2231) No Changes ### [Release 4.17.2214](/v1/docs/pkcs-11-4-17-2214) No Changes ### [Release 4.16.2195](/v1/docs/pkcs-11-4-16-2195) - Fixed an issue where the Sign and Verify tests were failing for the Fortanix DSM 4.13 PKCS#11 client when used with Fortanix DSM 4.11(**JIRA: PROD-6048**). ### Release 4.15 No Release ### Release 4.14 No Release ### [Release 4.13.2147](/v1/docs/pkcs-11-4-13-2173) - Fixed an issue where the backend changes for the PKCS#11 client configuration variable `prevent_duplicate_opaque_objects` were not reflected on the DSM UI (**JIRA: ROFR-3748**). - Fixed an issue in the PKCS#11 client configuration settings where updating a specific feature to `true` converts all features to `true` (**JIRA: ROFR-3614**). ### [Release 4.11.2116](/v1/docs/pkcs-11-4-11-2116) No Changes ### [Release 4.9.2084](/v1/docs/pkcs-11-4-9-2172) No Changes ### [Release 4.8.2070](/v1/docs/pkcs-11-4-8-2070) - Added support for logging X-Request-Id information (**JIRA: PROD-4145**). ### [Release 4.6.2045](/v1/docs/pkcs-11-4-6-2045) - Added support for Oracle TDE heartbeat ciphertext caching (**JIRA: PROD-3660**). ### [Release 4.4.2028](/v1/docs/pkcs-11-4-4-2028) - Internal dependency (tokio/mio) updates ### [Release 4.3.2018](/v1/docs/pkcs-11-4-3-2018) - Added support for AES CMAC in PKCS#11 **(JIRA: PROD-3418)**. - Fixed an error where PKCS#11 library creates threads even if `CKF_LIBRARY_CANT_CREATE_OS_THREADS` is passed (**JIRA: PROD-3818**). ### [Release 4.2.1500](/v1/docs/pkcs-11-4-2-1500) - Improvements to memory management of `C_FindObjects` while using PKCS#11 library **(JIRA: PROD-3354)**. - Introduces `opaque_objects_are_not_certificates = true` setting. - Fixed PKCS#11 library where AES keys were getting created as HMAC when using "`signing_aes_key_as_hmac`" option **(JIRA: PROD-3591)**. - Fixed issues in "`AES-GCM Wrap`" and "`AES-CMAC`" **(JIRA: PROD-3425)**. ### [Release 4.1.1484](/v1/docs/pkcs-11-4-1-1484) No Changes ### [Release 4.0.1467](/v1/docs/pkcs-11-4-0-1467) No Changes ### [Release 3.27.1458](/v1/docs/pkcs-11-3-27-1458) - Added support for encrypted PKCS#8 format (API) **(JIRA: PROD-1953)**. ### [Release 3.25.1443](/v1/docs/pkcs-11-3-25-1443) - Fixed an issue where integrating HSMG with nCipher fails with “pkcs11: 00000000 Error: Module 1 has failed”. ### [Release 3.23.1408](/v1/docs/pkcs-11-3-23-1408) No Changes ### [Release 3.22.1383](/v1/docs/pkcs-11-3-22-1383) No Changes ### [Release 3.21.1376](/v1/docs/pkcs-11-3-21-1376) - The default number of slots is reduced to 32 from 500: Applications use the Fortanix DSM PKCS#11 library to interact with Fortanix DSM for key management and cryptographic operations. The PKCS#11 specification has notions of slots and tokens, which correspond to physical entities in an HSM. Multiple clients or applications connecting to a token on an HSM have equal access to the entire keyspace. However, Fortanix DSM allows access to several applications simultaneously while guaranteeing strong cryptographic separation of key spaces. This is equivalent to every application having access to its own HSM. Fortanix DSM PKCS#11 library implements this by mapping the [application credential](/v1/docs/dsm-authentication) to the user PIN, and by having an arbitrarily large number of slots (numbered from 0), with a single token (numbered 1) already initialized. The number of slots defaults to 32 (numbered 0-31) and can be configured through the environment variable `FORTANIX_PKCS11_NUM_SLOTS.`