Hardware, firmware, software versions in nShield 5

Updated nShield Release Policy

Entrust has updated the nShield software release policy to provide greater clarity around release types and their associated support and update timelines. As part of this update, two categories of software releases have been introduced:

  • Long Term Support (LTS): Designed for customers who prioritize stability and extended support.

  • Standard Term Support (STS): Offers access to the latest features with a shorter support lifecycle.

Each nShield software release will now be designated as either an LTS or STS release.

Additionally, nShield firmware may be released as LTS-C (Long Term Support Certified Firmware). This designation indicates that the firmware is certified and benefits from the same extended support commitments as LTS software releases.

For more information on the software release policy, see the nShield Security World Release Information. Alternatively contact https://nshieldsupport.entrust.com for more information.

The section below contains details of recent nShield 5 releases, however nShield Software Release Information contains details of all the latest software releases.

nShield Security World software

Entrust introduced support for the nShield 5 HSM in the v13.2 Security World release. To make use of the nShield 5 the Security World version needs to be at v13.2 or later.

All subsequent releases of v13.x include support for the nShield 5 and previous generation HSMs (nShield XC and nShield Solo+). All customers are recommended to use v13.6 of Security World client-side software irrespective of the nShield HSM in use. Using the v13.6 (or v13.3+) version makes the adoption of nShield 5 possible whilst still supporting current HSMs. The Security World loaded on the current Solo XC/Solo+ HSMs can be loaded on the nShield 5 HSMs.

The key Security World client-side versions are:

Release Latest version Release Type Release notes Notes

13.2

13.2.2

STS

v13.2

First released version of v13.x Security World, focused on providing support for the new nShield 5 product line
No longer supported. The later v13.6 Security World software should be used.

13.3

13.3.2

STS

v13.3

First v13.x release adding mainline support for nShield 5 HSM and including similar updates to the other nShield HSMs

13.4

13.4.5

STS

v13.4

First release adding support for CodeSafe 5 on the nShield 5.

13.6

13.6.11

LTS

v13.6

Long Term Supported Security World Release supporting all supported nShield HSMs.
Recommended version for use as the Long Term Supported hardened version.

13.7

13.7.3

STS

v13.7

Latest Security World Release adding new features including ML-DSA Post Quantum algorithm support.

nShield 5s firmware

The following are key versions of the nShield 5s firmware.

LTS-C Firmware Releases
The nShield firmware includes a release type known as LTS-C (Long-Term Supported Certified). This designation applies exclusively to firmware versions that have undergone formal certification, ensuring they receive long-term support as part of their associated Security World release. See Long Term Support Certified Firmware (LTS-C) Releases for more information.
Version Latest version Release Type Certification Release notes Notes Solo XC equivalent

13.2

13.2.4

LTS-C

FIPS 140-3
FIPS cert. 4745

v13.2

First version of nShield 5s firmware
FIPS 140-3 certified firmware

12.72.3

13.3

13.3.1

STS

Previous Latest

v13.3

Previous latest version of nShield 5s firmware adding new features but with no certification
Upgrade to v13.5 or v13.7 firmware for new latest firmware is recommended

13.3.1

13.4

13.4.5

LTS-C

FIPS 140-3
FIPS cert. 4765

v13.4

Added support for CodeSafe 5
FIPS 140-3 certified firmware
Recommended version of nShield 5s firmware to use if FIPS certification is required

12.72.3

13.5

13.5.1

LTS-C

Common Criteria
CC cert link

v13.5

Common Criteria certified firmware
Recommended version of nShield 5s firmware to use if Common Criteria certification is required

12.60.15

13.5

13.5.6

LTS

Latest LTS

v13.6

Latest version of nShield 5s LTS firmware released as part of the LTS update with fixes.

13.5.6

13.7

13.7.1

STS

Latest STS

v13.7

Latest version of nShield 5s firmware with ML-DSA Post Quantum algorithm support.

13.7.1

nShield 5c image

The following are key versions of the nShield 5c image.

As with Connect XC releases, each release contains multiple versions of nShield 5c images to provide versions with the different types of nShield 5s firmware.

Version Latest version Release Type Release notes Notes Connect XC equivalent

13.2

13.2.2

STS

v13.2

First version of nShield 5c image
No longer recommended to be used or supported; does not contain any currently certified nShield 5s firmware

12.80.5

13.3

13.3.2

STS

v13.3

Previous latest version of nShield 5s firmware adding new features but does not contain latest certified 5s firmware
Upgrade to v13.6 image for use with latest and certified firmware is recommended

13.3.2

13.4

13.4.5

STS

v13.4

First nShield 5c image adding CodeSafe 5 support for nShield 5
No longer recommended to be used or supported; does not contain any currently certified nShield 5s firmware

13.4.5

13.6

13.6.11

LTS

v13.6

Recommended version of nShield 5c image, which supports all versions of nShield 5s firmware (FIPS, CC and Latest)

13.6.11

13.7

13.7.1

STS

v13.7

nShield 5c image with nShield 5s v13.7 firmware, adding Post Quantum algorithm support

13.7.1