See below for the issues fixed by the 10.6.1 release.

VME Vault Certificate Renewal

Fixed an issue where VME Vault was creating a renewal certificate on every heartbeat even when there is an unadopted certificate.

KMIP and Postgres Service Restart

The KMIP and Postgres services now restart correctly after renewing the self-signed server certificate.

Multi-Node Cluster Upgrade Reliability

Improved the upgrade reliability of the multi-node CSP Vault appliance cluster.

Azure Managed HSM AES Cloud Keys

Added the AES key option while creating Azure cloud keys with a managed HSM key vault.

CA-Chain Certificate Filtering

Added a fix to trim down the CA chain and keep only the relevant certificates, such as intermediate and root CA certificates, that are used to verify the server certificate.

NVMe Root Disk Selection

Added support for selecting NVMe disks as the root disk of the CSP vault appliance.

Database Vault Race Condition

Fixed a race condition in the Database Vault libraries for Microsoft SQL Server and Oracle databases.

Key Cache Invalidation After HSM Connectivity Loss

Added support for automatically invalidating the key cache after a configurable timeout when HSM connectivity is lost.

KMIP Certificate Expiration Alerts

Added advanced email and SNMP alerts for upcoming KMIP certificate expirations.

Audit Configuration Concurrent Access

Fixed an issue that could cause audit configuration file corruption during concurrent access operations.

SMTP Custom CA Certificate Trust

Resolved SMTP certificate trust verification issues by allowing custom CA certificates to be uploaded during SMTP configuration.

OIDC Configuration Concurrency

Fixed an issue that could create duplicate OIDC configuration entries when multiple configuration requests were processed concurrently.

Rotated System Log Compression

Improved log management by automatically compressing rotated system logs to reduce disk space consumption.

kmipcli Explicit Logout

Added an explicit logout option to kmipcli, allowing users to immediately terminate active sessions.

Failed Upgrade Disk Space Visibility

Enhanced the WebGUI to display nodes with insufficient disk space during failed upgrade validation checks.

Database Vault Access Token Validation

Fixed an issue where invalid access tokens or identities were not properly validated when connecting to the Database Vault.

Database Vault TDE Prerequisite Validation

Added prerequisite validation checks to Database Vault TDE installation scripts.

HTTP/2 API Compliance

Modified CSP Vault APIs to conform to HTTP/2 standards.

kmipcli UUID Case Sensitivity

Resolved an issue causing kmipcli to incorrectly enforce case-sensitive UUID matching.

Scheduled Backup Alerting

Improved scheduled backup alerting by suppressing notifications for the first backup failure and generating alerts only for consecutive failures.

KeySafe5 Setting Management

Added support for enabling or disabling the KeySafe5 setting from any cluster node through the HSM details page.

Access Policy Self-Removal

Removed restrictions that prevented users from removing themselves from access policies in Secrets Vault, KMIP Vault, and Tokenization Vault.

Windows Policy Agent UI Name

Modified the Windows policy agent to display "Entrust KeyControl Agent" in the UI.

Tokenization Database Upgrade Recovery

Added a hicli option to rerun Tokenization Database upgrades, providing additional recovery capabilities for upgrade failures.

TUI High CPU Error Handling

Fixed an issue that could cause the TUI to become stuck indefinitely under certain error conditions, resulting in high CPU usage on the Vault appliance node.

Simultaneous Node Reboot Race Condition

Resolved a race condition that could occur when multiple nodes rebooted simultaneously.

Local User Force-Delete Warning

Enhanced user management by displaying a force-delete warning when deleting a local user who is assigned to one or more access policies.

hcl attach Interrupted Operations

Fixed an issue where hcl attach could incorrectly report interrupted encrypt, decrypt, or rekey operations.