Added
- Users can now reset their password for the SafeNet Data Protection on Demand log in page without requiring administrator intervention. In the event of MFA lockout, users are still required to contact their administrator to reset the token.
- HSM on Demand Services running in Non-FIPS mode now support BIP32. There are now two BIP32 mechanisms available:
CKM_BIP32_CHILD_DERIVE
andCKM_BIP32_MASTER_DERIVE
. In addition, ECDSA mechanisms now accept BIP32 key types for the key derivation function. The latest client version (10.0 or above) is required for these mechanisms. Clients downloaded before October 2019 do not support BIP32. - HSM on Demand Services now fully support the 22519 elliptic curve variant.
Bugs Fixed
- SH-4240 - If you initialize the Crypto User, and then login and logout of this role without changing its password, the LunaCM session can no longer log in or log out any users, and returns the error
CKR_USER_ALREADY_LOGGED_IN
. - SH-3804 - A multi-part command fails with the error
CKR_OPERATION_NOT_INITIALIZED
. - KBR-758 - After Tenant creation, the new Tenant is not visible in the Tenants list.