New certificate issuer for North American datacenter

This change has been rescheduled to Tuesday February 8th 14:00 UTC to give customers more time to adjust their environments.

A knowledge base article with a full description of the change is available hereThe article contains important information on mandatory changes for users on 10.0 or 10.1 client versions in North America.

This change introduces a new endpoint for validating the certificate status. Please ensure that operating systems hosting the client are able to validate the server certificate status (OCSP/CRL) using port 80. 

Ensure that these certificate revocation lists (CRLs) are accessible from the client machine prior to the planned change on Tuesday February 8th 14:00 UTC  to guarantee continuity of service.

Current CRL: http://crl.godaddy.com/gdig2s1-3235.crl
New CRL: http://crl.sectigo.com/SectigoRSAOrganizationValidationSecureServerCA.crl
Platform CRL: http://crl3.digicert.com/ssca-sha2-g7.crl

Additional registration fields are being made mandatory for tenant registration

The following fields are being made mandatory for tenant registration:

  • Address
  • City
  • ZIP or postal code

If you have automation using the API for tenant registration and tenant updating you should modify your automation to account for these new mandatory fields. 

See the Data Protection on Demand (DPoD) Public API for more information about available endpoints and fields.

Clone between PED Luna HSM and Luna Cloud HSM with Luna HSM Client 10.4.1

Version 10.4.1 of the Luna HSM client is now available for download from the Thales Customer Support Portal.  This client supports hybrid usage of both Luna Cloud HSM services and the Luna HSM product line, as detailed in the Luna Cloud HSM Client User Guide.

Added

  • Luna HSM Client 10.4.1 allows you to initialize a Luna Cloud HSM service using a domain secret imported from a red PED key. This allows you to clone objects between PED-authenticated Luna HSM partitions and Luna Cloud HSM enabling cloud backups and improving availability by adding Luna Cloud HSM to your HA groups. See Initializing a Luna Cloud HSM Service for more information.

Removed API Endpoints

Removed

The PATCH /tenants/{id}/admin/reset and POST /tenants/{id}/admin/resetMfaToken operations have been removed from the DPoD Platform API.

Service provider administrators can no longer reset the password or MFA token of a user inside of a child tenant.  Users can use the self-service resources in the DPoD platform or submit requests to an available administrator. See User Management for more information.

Impact to HTTP White Listing

Under Development

If you are using an IP address in your HTTP Network Connection between your DPoD service and the DPoD platform we recommend you update your configuration to use the fully qualified domain name as described in Network Connectivity.

If your network configuration uses any hard coded IP addresses, be aware that upcoming changes to the DPoD platform will disrupt your connection to the service.

Release 1.16

Added

  • Version 10.2 of the HSM service client is now available for download from Thales Data Protection on Demand. This client supports hybrid usage of both HSMoD services and the Luna HSM product line, as detailed in the HSM on Demand Client User Guide. Refer to the HSM Client 10.2 Customer Release Notes document for more information. See Upgrading your HSMoD Service Client for more information about updating your HSMoD service client. 
  • HSM on Demand service clients now use JWT authentication. 
  • The HSMoD service client is now supported on the following operating systems:
    • RHEL8/CentOS8
    • Windows Server 2019 (standard and core)
  • You can configure additional logs (Application Error Logs and Curl Logs) in the application console. See the HSM on Demand Troubleshooting section for more information. 

Changed

  • The new HSMoD service has updated entries in the REST and XTC sections of the crystoki.ini (Windows) and the Chrystoki.conf (Linux) configuration files. Refer to the Configuration File Summary for a description of the default options and additional settings. 
  • Deleting a client from a JWT authenticated HSMoD service now revokes the client ID and client secret associated with that client. Create a new HSMoD service client for the service to resume access. See Managing HSMoD Services for more information about deleting a service client and revoking the service credentials. 

Removed

  • Older Java versions are no longer supported. See the HSM Client 10.2 Customer Release Notes document for more information.
  • If your application relies on Oracle Java 7 or Java 8, you must update the advanced version provided by Oracle. You require (at minimum) version 7u131 or 82u121. Please refer to the Oracle website for more information.
  • If your application relies on IBM Java 7 or 8, do not update your service client.If you want to update your client software, consider adopting OpenJDK or another supported Java version See Supported Cryptographic APIs.

Bugs Found

  • DPS-5531 - If you exit the Suggest An Edit feature, in the DPoD Platform documentation, using the Close button, you can no longer scroll the documentation page. Refresh the page to continue scrolling.
  • DPS-5493 - The Rotation Policies section of the Salesforce Key Broker service do not display. There is no workaround at this time.
  • DPS-5433 - Tenant administrator users cannot reset their password using the Actions column in the User Details table. Change your Tenant Administrator password by clicking Change password in the upper right corner of the DPoD UI. 
  • SH-4987 - When creating a self-signed certificate with cmu selfsigncertificate, additional characters are added to the specified serial number. Use cmu getattribute to list the actual serial number assigned to the certificate.

Bugs Fixed

  • Luna-11616 - LunaCM displays available slots if the client fails to resolve the DPoD service's hostname. Restart LunaCM to re-attempt the connection to the service.
  • Luna-11447 - Resolved a segmentation fault stopping HA members from failing over to an HSMoD service.
  • HOD-957 - The default log level in the client was updated to provide improved details. 

Release 1.10

Features under development

  • FIPS Certification Firmware Candidate - The HSM firmware is undergoing FIPS certification coordination.

Added

  • Added the Virtual Token Library (VTL) to the 1.10 HSMoD service client. 
  • Client patched reducing timeout and failover issues during key and certificate migration.
  • Direct link to SafeNet Data Protection on Demand **Status Page** available in user interface footer.
  • The Company name no longer needs to be unique. Now, multiple enterprise tenants can share a common company name.
  • Service provider monthly reports now include the minimum billable units (MBU) selection from the tenants **Initial Elections** form.

Deprecated

  • Deprecating support for 32-bit operating systems.
  • Ending support for Windows Server 2008 and Windows Server 2008 R2.

Removed

  • You cannot download a new HSMoD service client for a service which existed prior to release 1.5. Recreate the service.

Bugs Fixed

  • DPS-3071 - Deleting an application owner account before deleting any associated platform credentials results in being unable to delete both the platform credentials and any associated subscriber group.
  • DPS-3006 - The HSM on Demand service generic mapping refers to key_vault in reports and the API.

Release 1.9

Features under development

  • FIPS Certification Firmware Candidate - The HSM firmware is undergoing FIPS certification review.

Added

Changed

Deprecated

  • LunaProvider.jar

Removed

  • You cannot download new HSMoD service clients for a service which existed prior to release 1.5. Recreate the service.

Release 1.8

Features under development

  • FIPS Certification Firmware Candidate - The HSM firmware is undergoing FIPS certification review.
  • Conversion from evaluation to subscriber tool for enterprise tenants.

Added

Removed

  • You cannot download new HSMoD service clients for a service which existed prior to release 1.5. Recreate the service.

Bugs Fixed

  • DPS-2159 - When the service provider administrator edits an enterprise tenant, the tenant administrator field displays empty.

Release 1.7

Features under development

  • DPoD enterprise tenant registration page
  • Pipeline improvements

Added

  • Introduced a multi-factor authentication requirement using an authentication application on a mobile device for all users.
  • Added the following HSM on Demand service tiles:
    • HSM on Demand for CyberArk Digital Vault
    • HSM on Demand for Java Code Signer
    • HSM on Demand for Microsoft ADCS
    • HSM on Demand for Authenticode
    • HSM on Demand for Microsoft SQL Server
  • Added the Key Migration Guide to the HSM Client Guides in the Help system. This migration guide now details the process for transferring key material from an Amazon Web Services (AWS) cloud HSM to a DPoD HSM on Demand service.

Changed

  • Updated the following HSM on Demand service tiles:
    • HSM on Demand
    • HSM on Demand for Digital Signing
    • HSM on Demand for PKI Private Key Protection
    • HSMoD for Oracle Database
    • HSM on Demand for Hyperledger

Bugs Fixed

  • DPS-2501 - The UI does not identify an invalid hostname when creating a tenant, resulting in the user having to repeat the tenant creation process.
  • DPS-2159 - When the service provider administrator edits an enterprise tenant, the tenant admin field displays empty.
  • DPS-2487 - Editing the tenant account name does not update the heading on the log in page.
  • DPS-2434 - Deleting a tenant when the tenant account was accessed using the search box fails.