See below for the changes in the 10.6.1 release.

SNMP v3 Support

Added support for SNMP v3, SNMP v2c is no longer supported.

Lenovo SR250/SR630 Appliance Deployment Support

Added support for the deployment of the CSP Vault appliance on Lenovo SR250/SR630 physical server models.

PKCS#11 Vault Support

Implemented a new vault type and a lightweight client to add support for the PKCS#11 Cryptographic Token Interface Base Specification.

Microsoft External Key Manager Support

Added support for Microsoft's External Key Manager protocol.

Fine-Grained Administrative Roles and Permissions

Introduced fine-grained administrative roles and permission controls for CSP Vault appliance management tasks.

GitLab Secrets Vault Integration

Added GitLab integration for Secrets Vault, enabling CI/CD pipelines to securely retrieve and inject application credentials directly from Secrets Vault at runtime.

AWS IAM and STS Secrets Vault Integration

Introduced a dedicated Secrets Vault integration that enables secure storage and rotation of AWS IAM user access keys, as well as on-demand issuance of short-lived AWS STS session tokens and AssumeRole credentials with federated console sign-in.

Azure Entra ID Secrets Vault Integration

Added a dedicated Secrets Vault integration for securely storing and rotating Azure Entra ID (App Registration and Service Principal) credentials, including client secrets and certificates, and for issuing short-lived Azure AD access tokens on demand for Azure management and Microsoft Graph scopes.

Offline Cloud Encryption Key Generation

Added support for generating cloud encryption keys for AWS, Azure, GCP, Salesforce, and OCI offline within CSP Vault, eliminating the need for direct connectivity to the respective cloud providers.

OCI EKM Management Interface Decoupling

Decoupled Oracle Cloud Infrastructure External Key Management (OCI EKM) from the Cloud Key Vault management interface.

Generic Authentication Error Responses

Enhanced security by using generic authentication error responses across vaults to help prevent username enumeration.

ECDSA 384-bit Certificate and Trust Validation Enhancements

Enhanced certificate management and trust validation by adding support for ECDSA 384-bit certificates across internal and external web servers and KMIP servers, optimizing certificate chains to include only the required intermediate certificates, and enabling the use of custom CA certificates for email notification trust verification.

Database Vault TDE and Platform Support Enhancements

Enhanced Database Vault platform support by extending Transparent Data Encryption (TDE) capabilities to Oracle Exadata Cloud@Customer (ExaCC) environments, adding key export and import functionality for seamless TDE key forwarding between database instances, and expanding the officially tested database platform matrix to include PostgreSQL 18.

Vault Administrator Continuity and Alert Recipient Enhancements

Enhanced administrative continuity by allowing organizations to update or replace the primary Vault Administrator account when personnel changes occur, and by enabling email distribution lists (DLs) to be configured as alert recipients across all Vaults and appliances.

CSR Country Code Flexibility

Enhanced CSR generation flexibility by allowing empty or period ('.') values in the Country Code field during Web GUI certificate signing request (CSR) creation, improving compatibility with enterprise CA policies.

Interactive Swagger API Documentation

Replaced the API documentation at /apidoc with an interactive Swagger (OpenAPI 3.1) UI that lets you run APIs directly from the browser.