New FeatureBlockchain supportOperationalSecurity
Week of August 3rd, 2026Releases are now numbered
hsm-X.Y.Z (no v prefix). The previous entry, v0.1.46, corresponds to 1.1.0. This entry covers everything delivered since: 1.2.0 through 1.4.2.HSM vendor support updates:- AWS CloudHSM support added, with a deployment runbook. The driver now advertises whether EdDSA is available on the backend.
- Thales Luna V1 (SKS) backend added alongside the existing V0 backend, with on-token HD derivation.
- IBM EP11: on-token HD derivation.
- HD key generation and signing: generate an HD master key, sign at a derivation path, and derive child public keys with the new
derive_public_keyRPC. Supported on Thales Luna (V0 and V1) and IBM EP11. Ed25519 derivation is hardened-only. Not available on the OSO path.
- Persistent key storage: HD master keys can live directly on the HSM partition (located by
CKA_LABEL) instead of as wrapped blobs in the database. Persistent drivers are HD-only, and a new capabilities RPC reports the driver’s storage mode. The legacy sealed mode remains the default.
- HashiCorp Vault secrets retriever added.
- New Vault authentication providers: in-cluster Kubernetes service account and AWS IRSA.
- The HSM PIN can be supplied as a Docker Compose secret file (
USER_PIN_FILE) instead of an environment variable.USER_PINkeeps working; the two are mutually exclusive.
- Pre-signature validation gate: the driver can verify the intent authorizing a signature (payload-hash binding and signing-user proof) before the HSM signs.
- Auto-renewing mTLS server identity for the proxy and secrets retriever, with health exported as OpenTelemetry metrics. The TLS pack can carry only the CA when auto-renew is on.
- Governance-engine signature attestation passed to the OSO plugin.
- Fail-closed input handling: exact signing-scheme matching (no silent ECDSA fallback), plus signature-length and maximum-input-size checks.
destroy_allis gated out of production binaries, production images are distroless, and the Thales driver runs as non-root by default.- Bundled IBM
pkcs11-grep11updated 2.6.11 to 2.6.15, removing 35+ CVEs from the driver image. OpenTelemetry and rustls-webpki updated for upstream advisories.
- Distroless production images for
hsm-driverandhsm-cli, with all vendors bundled. The previous image ships as a-debugvariant for field diagnosis. - Structured logs carrying
trace_idandspan_id, propagated from incomingtraceparentheaders (Datadog-compatible). hsm-clidisaster recovery: HD key generation, signing, and public-key derivation in persistent mode without a running proxy.- arm64 build of
hsm-proxy. - New database migrations must be applied before start, for the driver and, for the first time, the proxy. HD support adds
keys.chain_code; the proxy addsderivation_pathto its signature cache.
New FeatureOperationalSecurity
Week of May 25th, 2026HSM vendor support:
- Securosys Primus CloudHSM support added.
- Database migrations now run automatically on startup (Postgres), with a flag to disable them.
- Response caching added to the HSM proxy.
hsm-cliis now shipped as a separate image.- HPCS (IBM grep11) library updated to 2.6.11.
New FeatureOperational
Week of May 4th, 2026HSM vendor support:
- IBM EP11 support added: multi-card init, secure-key concept, EdDSA and ECDSA generate/sign, pre-generation.
- Thales HSM support added (including Cloud Luna), with a dedicated runbook.
- OpenCryptoki integration reworked, then removed in favor of the higher-level HSM interface.
- SQLite added as a keystore option, with strict tables and a read-only mode.
- HA SQLite mode added.
- Postgres migrations reorganized into a dedicated subfolder.
- Pre-generation of keys supported on startup, with topup capability.
- Pre-generation supported in
pkcs11-executormode.
- Sign by public key supported as an alternative to signing by
key_id. - Signing integrity verification using ed25519.
- Returned and stored public keys are now compressed.
- New
hsm-clifor HSM operations without a proxy connection. - New
benchcommand on the driver CLI. - Async flow: driver can return pending processes to the proxy REST API.
- Multi-platform
hsm-proxyimages (amd64 and s390x). - Version printed at
hsm-driverandhsm-proxystartup.
OperationalBug Fix
Week of January 5th, 2026Operational:
- Documented HSM keystore creation in pregen mode.
- Client cert parsing: customer names containing dots are now accepted.
- Client cert domain handling is now dynamic.
Operational
Week of December 22nd, 2025Operational:
- Client stale timeout is now a configurable parameter on
hsm-proxy. - Proxy can drop driver connections that have gone stale.
- IBM runbook updated with HA SQLite instructions.
Initial Release
Week of December 15th, 2025First release of the DFNS HSM signer tracked in this changelog.