August 2026
We are pleased to announce the release of SignServer Hardware Appliance 5.3.2.
With this release, we bring significant security corrections, exposed performance configurations directly to the user interface, and improved overall system stability.
For available deployment types and associated versions, refer to Supported Versions.
Highlights
SignServer Performance Variables in Webconf
Performance environment variables are now exposed and configurable directly within the Webconf, allowing for streamlined tuning of appliance workloads when needed.
Resolved System Instability & Memory Leak in Thales Luna HSM Integration
-
Issue: Hardware Appliances experienced intermittent system instability, including application restarts, CryptoToken disconnections, and performance degradation during heavy cryptographic or administrative operations. This was caused by progressive memory retention within the Thales Luna HSM client library during multi-partition / HA-group operations.
-
Fix: Resolved in close collaboration with Thales through an updated Thales Luna Client version that eliminates the underlying memory leak, ensuring stable, continuous operations and reliable operation of the Keyfactor Hardware Appliance with Luna HSM.
Improvements and Corrections
The following lists other improvements and corrections included in the release.
-
Security & Core Fixes:
Platform & Operational Enhancements:
-
CA Chain Validation: Fixed an issue where the system was unable to validate a trusted CA chain when
"Require Explicit Policy:0"was defined.-
⚠️ DEPRECATION NOTICE: HSM Client Versions
Applicable to:
Customers utilizing outdated external hardware security modules (HSMs).To ensure the highest standards of security, performance, and manufacturer compliance, this release will deprecate outdated, unsupported HSM client libraries from manufacturers from the appliance.
-
What will change?
Outdated HSM client versions will be deprecated from the underlying platform. Active deprecation banners and proactive warnings will now be displayed directly inside the Webconf if an affected or unmaintained module version is detected.
These deprecated versions will be removed in the November Milestone Release. -
Affected Versions:
-
Thales Luna HSM Client - 10.4.0, 10.5.1, TCT 7.13.2
-
TrustWay Proteccio - 3.01.05, 3.06.05
-
Utimaco SecurityServer - 4.45.5.1
-
Entrust nShield Security World - 12.80.4
-
-
Action Required:
Customers currently operating on outdated HSM firmware or older client connections are strongly advised to review their deployment infrastructure and update to the latest supported vendor client versions.
-
-
For a comprehensive overview of actively verified firmware and client layers, please consult the official Supported HSM Versions documentation.
-
Upgrade Information
For information on the required steps to update the SignServer Hardware Appliance, see Settings: Appliance Update.