See the release notes below for Vault 10.4.1.

Upgrade path

See below for the versions that support upgrading to 10.4.1.

Product

Supported source versions

​Entrust Cryptographic Security Platform Vault

10.3.1

Entrust Policy Agent

10.3.1

Changes in this release

See below for the changes in this Vault release.

  • Version 10.4.1 is the first KeyControl release on Oracle Linux. The transition from CentOS to Oracle Linux allows Entrust to improve KeyControl operating system security.
  • The main KeyControl components were ported directly to Oracle Linux and will continue to work as they did in earlier releases. The same applies to the KeyControl APIs.
  • Entrust KeyControl now runs on the Entrust-hardened version of Oracle Linux.
  • You can now use OpenID Connect (OIDC) Authentication with Active Directory in the KeyControl Vault Management appliance.
  • You can now use OpenID Connect (OIDC) Authentication without configuring Active Directory in the KeyControl Vault Management appliance.
  • AWS multi-Region keys are AWS KMS keys in different AWS Regions that can be used interchangeably. The KeyControl Vault for Cloud Keys now supports using AWS multi-region keys in BYOK.
  • The KeyControl Vault for Cloud Keys now supports Azure role-based access control (Azure RBAC) and the access policy model authorization system.
  • You can now use secondary approval with the KeyControl Vault for Secrets.
  • You can now use Personal Access tokens in your KeyControl Vaults that use OIDC for authentication as a password for API and CLI commands.
  • Added support for TLS 1.3 and Extended Master Secret (TLS). TLS 1.3 is the default for all new KeyControl installations.
  • You can now set KeyControl to use self-signed certificates for all nodes in a cluster.
  • The KeyControl appliance AMI now only supports Instance Metadata Service (IMDS) version 2 for AWS Cloud.