What's New

The following changes have been made in Cryptographic Security Platform Vault Version 10.5.1.

For a list of changes made in earlier releases, see Release Change History.

Important: Beginning with Cryptographic Security Platform Vault 10.1, you must install the Cryptographic Security Platform Compliance Manager when you install Cryptographic Security Platform Vault. The Cryptographic Security Platform Compliance Manager is used to license Cryptographic Security Platform Vaults.

What's New in Cryptographic Security Platform VaultVersion 10.5.1

Feature

Description

Where Documented

Licensing Updates

Licenses are now enforced in the Cryptographic Security Platform Vault. You will see pop-up warnings in the webGUI when there are important issues with your license.

License Page

Post Quantum Support

Expanded support for Post Quantum Encryption and Key Management including support for ML-KEM, ML-DSA and SLH-DSA keys, as well as encapsulation, decapsulation, sign and verify operations using these key types. Also added improved PQ security for KMIP Server with support for PQ-TLS.

Post Quantum Support in the Cryptographic Security Platform Vault for Cryptographic APIs

Post Quantum Support in the Cryptographic Security Platform Vault for KMIP

KeySafe5 Agent

You can now use KeySafe5 to monitor your nShield HSM.

Note: You can view the KeySafe5 GUI through the Cryptographic Security Platform Compliance Manager.

KeySafe5 Agent Requirements

Enabling the KeySafe5 Agent

GCP EKM Support

You can now use the Cryptographic Security Platform Vault for Cloud Keys as an External Key Manager (EKM) provider for GCP.

Using Cryptographic Security Platform Vault as a GCP EKM Provider

Microsoft SQL Server Secret Support

The Cryptographic Security Platform Vault for Secrets now supports Microsoft SQL Server secrets.

Creating a Microsoft SQL Server Secret

EnterpriseDB Postgres Secret Support

The Cryptographic Security Platform Vault for Secrets now supports EnterpriseDB Postgres secrets.

Creating a Postgres or EnterpriseDB Postgres Secret

AWS On-Demand Rotation

The Cryptographic Security Platform Vault for Cloud Keys now supports on-demand key rotation for AWS key versions with BYOK.

On-Demand Key Rotation for AWS AES Keys with BYOK

Batch Encrypt and Decrypt API and CLI commands.

Added the Batch Encrypt, Batch Decrypt, and Batch encrypt-decrypt API and CLI commands.

Cryptographic Security Platform Vault for Cryptographic APIs Crypto CLI

The API commands can be found by selecting ? > API Documentation in the Cryptographic Security Platform Vault for Cryptographic APIs webGUI.