Documentation Index

Fetch the complete documentation index at: https://support.fortanix.com/llms.txt

Use this file to discover all available pages before exploring further.

[5.3] - September 25, 2025

Prev Next

Fortanix Data Security Manager (DSM) SaaS 5.3 includes some exciting new features and general improvements.

NOTE

This release is for SaaS only and is not available for on-premises installations. Updates in this release will be part of a future on-premises release.

1. New Features

2. Improvements

  • Improved the account name visibility where the full account names are now displayed on hover, making it easier to identify and select the correct account (JIRA: EXTREQ-1197)

    Screenshot (2321).png

3. Client Improvements

  • Implemented an automatic retry mechanism in Sequoia DSM (JIRA: ES-532).

  • Added support for additional Linux platforms in Sequoia DSM, including RHEL 9 and SUSE 15 (JIRA: PROD-10574).

4. DSM Accelerator New Features

5. API Updates

  • Added support for RSA keys in Google Cloud Platform (GCP) Bring Your Own Key (BYOK), allowing you to specify the key protection_level (for example, Software or HSM) as part of the key's custom_metadata(JIRA: EXTREQ-1255).

    • This enhancement applies to all APIs involving SobjectRequest and SobjectResponse, specifically for Sobjects in Cloud Data Control (CDC) GCP-backed groups that are part of the GCP BYOK setup.

  • Added support for SLIP10 hierarchical deterministic keys through Slip10 sobjects in Fortanix DSM, in addition to existing BIP32 keys. You can now derive SLIP10 keys (master, hardened, and non-hardened) on NistP256 and SecP256K1 curves, and import or export them in SLIP-32 format, as well as sign and verify with them (JIRA: EXTREQ-1463).

    This enhancement affects the following APIs:

    • Derive a new key from an existing key: POST /crypto/v1/derive

    • Transform an existing key into a new one: POST /crypto/v1/transform

    • Sign with a private key: POST /crypto/v1/sign

    • Verify a signature with a public key: POST /crypto/v1/verify

    • Get the details and value of a particular exportable security object: POST /crypto/v1/keys/export

    • Import a security object: PUT /crypto/v1/keys 

6. Known Issues

  • Deriving SLIP10 keys fails if a Cryptographic policy is set at the Fortanix DSM account or group level. Additionally, copying SLIP10 keys is currently not supported (JIRA: PROD-10767).

    Workaround: To derive a SLIP10 key, temporarily delete the account- or group-level Cryptographic policy, perform the key derivation, and then reapply the Cryptographic policy.

  • After upgrading Fortanix DSM to version 5.0, Network Time Protocol (NTP) checks in Sensu may fail even if NTP is correctly synchronized across the cluster (JIRA: RODE-168).

    NOTE

    Use the following command to override the alert:

    check-ntp.rb -u ok -w ${WARN_LEVEL} -c ${CRITICAL_LEVEL}" \
  • The COPY KEY dialog box does not filter the HSM/External KMS groups as expected when Import key to HSM/External KMS check box is selected, if there are more than 1,000 groups in the account (JIRA: ROFR-5167).

  • Unable to delete a user who was invited to an account with a "Custom account role" that includes an "All Groups Role" along with group membership assigned explicitly in the invite user workflow if the invited user has not accepted the invitation (JIRA: PROD-9409).

    Workaround: To delete the invited user, contact Fortanix Support or perform the following steps:

    • If you have already assigned explicit group memberships, perform the following steps to remove them and delete the user:

      • Change the user's account role to "Account Member".

      • Remove the group memberships one by one using the user interface.

      • Delete the user.

  • The sudo get_csrs --rotate command does not support changing the hostname of the service URL. For example, if your service main URL is dsm.fortanix.net, you cannot change this main URL hostname (JIRA: PROD-9542).

  • When you run sudo get_csrs --rotate command to create a new certificate pair for cluster and UI, it does not remove the old certificate pair from the sdkms pod resulting in two certificate pairs which can lead to unexpected results (JIRA: PROD-9570).

  • Deleting replica keys in groups with key history policies only results in a soft-delete of the keys (JIRA: PROD-9925).

    Workaround: Users should avoid deleting keys that are associated with a key-undo policy.

  • The Audit Log page in Fortanix DSM does not display recent “Select Account” events when the log retention period is set to 1 day (JIRA: PROD-10441).

    Workaround: Set the retention period to 2 days or longer under Settings → LOG MANAGEMNET  → Retention period for Audit Logs to ensure recent audit log entries are visible.

  • Unable to perform Kubernetes CA rotation successfully (JIRA: RODE-62).

    Workaround: To perform CA rotation in DSM versions 4.36 and higher, contact the Fortanix Support team.

Fortanix-logo

4.6

star-ratings

As of August 2025