Release Change History

The following changes were made in past DataControl/KeyControl releases. For details about the current DataControl/KeyControl release, see https://www.hytrust.com/docs. For details about previous releases, visit our Customer Portal at https://www.hytrust.com/support.

Changes in Release 5.2

Upgrade Path: For HyTrust KeyControl, upgrade to 5.2 is allowed only from release 5.1.1. For the HyTrust DataControl Policy Agent, upgrade to 5.2 is allowed from release 5.0, 5.1, 5.1.1, and 5.1.2. For details, see KeyControl Upgrades and Policy Agent Upgrades.

Changes in this release:

  • Security administrators can now enforce two-factor authentication for all users. Two-factor authentication is now supported for all -managed user accounts that use local, RADIUS or LDAP authentication, as well as Active Directory users who access KeyControl using their AD login.
  • KeyControl clusters now use certificate-based cluster authentication to join nodes to a cluster and communicate between nodes.
  • You can now use the nShield Connect HSM as a System HSM.
  • You can now encrypt KMIP objects with keys stored in either IBM HPCS, the nShield Connect HSM, or the SafeNet Luna HSM.
  • KeyControl now takes snapshots before you upgrade. You can delete them if you need more space in your system.
  • You can now uninstall on Windows silently.
  • The new secrets vault provides centralized secure storage for managing and controlling access to secrets required to access systems and resources.
  • You can now deploy and run DataControl/KeyControl from the Google Cloud Platform (GCP).

Changes in Release 5.1.2

Upgrade Path: For HyTrust KeyControl, upgrade to 5.1.2 is allowed from release 5.0, 5.1, and 5.1.1. For the HyTrust DataControl Policy Agent, upgrade to 5.1 is allowed from release 5.0, 5.1, and 5.1.1. For details, see KeyControl Upgrades.

Changes in this release:

  • Added support for Safenet Luna client version 10.2.

Changes in Release 5.1

Upgrade Path: For HyTrust KeyControl, upgrade to 5.1 is allowed from release 5.0 and 4.3.2 only. For the HyTrust DataControl Policy Agent, upgrade to 5.1 is allowed from release 5.0 and 4.3.2. For details, see KeyControl Upgrades.

Changes in this release:

  • You can now use DataControl with UEFI secure boot on Linux.
  • You can now connect KeyControl with multiple Safenet Luna HSM servers in a Safenet High Availability (HA) group.
  • You can now use IBM Hyper Protect Crypto Services (HPCS) with DataControl for greater protection of encryption keys.
  • You can now enable passphrase-based startup authentication to protect the master key for all nodes in the same cluster.

  • You can now use external SSL certificates with your KMIP server.
  • You can now use a proxy server for the Vitals Service and Licensing Service.
  • Syslog support over TCP now supports different TLS authentication modes.

  • Online API documentation is now integrated with the DataControl webGUI.
  • You can now use 4096 bit RSA keys for Policy Agent and KMIP certificate creation.
  • You can now use envelope encryption with KeyIDs.
  • You can now move a VM from one CVM set to a different CVM set.

  • SSH access for HSM users is now supported.
  • Improvements to audit log retention have been added.
  • You can now use KeyIDs with either Token-Based Authentication or Certificate-Based Authentication.