See the release notes below for Vault 10.4.1.
Upgrade path
See below for the versions that support upgrading to 10.4.1.
Product | Supported source versions |
|---|---|
Entrust Cryptographic Security Platform Vault | 10.3.1 |
Entrust Policy Agent | 10.3.1 |
Changes in this release
See below for the changes in this Vault release.
- Version 10.4.1 is the first KeyControl release on Oracle Linux. The transition from CentOS to Oracle Linux allows Entrust to improve KeyControl operating system security.
- The main KeyControl components were ported directly to Oracle Linux and will continue to work as they did in earlier releases. The same applies to the KeyControl APIs.
- Entrust KeyControl now runs on the Entrust-hardened version of Oracle Linux.
- You can now use OpenID Connect (OIDC) Authentication with Active Directory in the KeyControl Vault Management appliance.
- You can now use OpenID Connect (OIDC) Authentication without configuring Active Directory in the KeyControl Vault Management appliance.
- AWS multi-Region keys are AWS KMS keys in different AWS Regions that can be used interchangeably. The KeyControl Vault for Cloud Keys now supports using AWS multi-region keys in BYOK.
- The KeyControl Vault for Cloud Keys now supports Azure role-based access control (Azure RBAC) and the access policy model authorization system.
- You can now use secondary approval with the KeyControl Vault for Secrets.
- You can now use Personal Access tokens in your KeyControl Vaults that use OIDC for authentication as a password for API and CLI commands.
- Added support for TLS 1.3 and Extended Master Secret (TLS). TLS 1.3 is the default for all new KeyControl installations.
- You can now set KeyControl to use self-signed certificates for all nodes in a cluster.
- The KeyControl appliance AMI now only supports Instance Metadata Service (IMDS) version 2 for AWS Cloud.