Additional Fields are now Mandatory for Tenant Registration
The following fields are now mandatory for tenant registration:
- Address
- City
- ZIP Code
- State/Province/Region*
* Mandatory if Country is set to United States, Canada, or Australia
Additional Fields are now Mandatory for Tenant Registration
The following fields are now mandatory for tenant registration:
* Mandatory if Country is set to United States, Canada, or Australia
This change has been rescheduled to Tuesday February 8th 14:00 UTC to give customers more time to adjust their environments.
A knowledge base article with a full description of the change is available here. The article contains important information on mandatory changes for users on 10.0 or 10.1 client versions in North America.
This change introduces a new endpoint for validating the certificate status. Please ensure that operating systems hosting the client are able to validate the server certificate status (OCSP/CRL) using port 80.
Ensure that these certificate revocation lists (CRLs) are accessible from the client machine prior to the planned change on Tuesday February 8th 14:00 UTC to guarantee continuity of service.
Current CRL: http://crl.godaddy.com/gdig2s1-3235.crl
New CRL: http://crl.sectigo.com/SectigoRSAOrganizationValidationSecureServerCA.crl
Platform CRL: http://crl3.digicert.com/ssca-sha2-g7.crl
Version 10.4.1 of the Luna HSM client is now available for download from the Thales Customer Support Portal. This client supports hybrid usage of both Luna Cloud HSM services and the Luna HSM product line, as detailed in the Luna Cloud HSM Client User Guide.
Added
Changed
The following Luna Cloud HSM service names have been changed:
CipherTrust Key Broker for Google Cloud EKM service users can now access their DPoD platform tenant. Users can log in to their tenant hostname URL to access DPoD platform features such as User Management, Tenant Management, and Reporting.
CipherTrust Key Broker for Google Cloud EKM service tenants do not have access to tenant features such as Subscriber Groups or Adding Services.
Removed
The PATCH /tenants/{id}/admin/reset
and POST /tenants/{id}/admin/resetMfaToken
operations have been removed from the DPoD Platform API.
Service provider administrators can no longer reset the password or MFA token of a user inside of a child tenant. Users can use the self-service resources in the DPoD platform or submit requests to an available administrator. See User Management for more information.
Added
Bugs Found
cmu verifyhsm
does not prompt the user to enter a challenge string. Always specify a challenge string using cmu verifyhsm -challenge <string>
.cmu requestcertificate
using the wrong attribute to specify the private key returns an incorrect error message. Use the -privateouid
to specify a private key on a Luna Cloud HSM service.cmu import
to import a DSA key fails. Use an RSA public key instead.cmu selfsigncertificate
with no arguments specified, on Linux, cmu
fails to prompt the user for the relevant object handles/OUIDs. Always specify the object handles/OUIDs using -publichandle
and -privatehandle
or -publicouid
and -privateouid
.ckmdeo
option Get OUID (39)
returns OUIDs with extra zeroes appended. Use option Get Attribute (24)
to view the correct OUID.CKR_OBJECT_HANDLE_INVALID
. We recommend you avoid upgrading your Luna Cloud HSM service client until the issue is resolved. cmu getpkc
to confirm a public key can fail. Execute the ckdemo
Display Object (27)
function to confirm the key pairs origins and security in the HSM. If the CKA_NEVER_EXTRACTABLE
attribute is present it confirms that the private key was created in the HSM and has never been extracted.Bugs Fixed
cmu selfsigncertificate
now match the input serial number.Added
Bugs Found
Bugs Fixed
Changed
Deprecated
Bugs Fixed
Bugs Fixed