AWS CloudHSM latest Client SDK release - AWS CloudHSM

AWS CloudHSM latest Client SDK release

In March 2021, AWS CloudHSM released Client SDK version 5.0.0, which introduces an all-new Client SDK with different requirements, capabilities, and platform support.

Client SDK 5 is fully supported for production environments, and offers the same components and level of support as Client SDK 3. For more information, see Compare AWS CloudHSM Client SDK component support.

This section includes the latest version of the Client SDK.

Client SDK 5 release: Version 5.16.1

Amazon Linux 2023

Download version 5.16.1 software for Amazon Linux 2023 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 342e81846436708cfc1fb459a7ef1c7b065d8a68b50a5e63653c24918d0338a0)

  • OpenSSL Dynamic Engine (SHA256 checksum 4e83bebcd20201c04629a03b70136df8d225d3056346789054c4e2ce8c9b3cba)

  • JCE provider (SHA256 checksum 014e3c804a56087f8855ed30e480f9c193def0e1132a4769eae3ecd235d76c4f)

  • CloudHSM CLI (SHA256 checksum 854c5c21f9fbef4f53a710340f213c272365c2bb1233106266eca5a5aa547e11)

Download version 5.16.1 software for Amazon Linux 2023 on ARM64 architecture:

  • PKCS #11 library (SHA256 checksum dbe9498d91e1e2e8f80fc870a4a6576b0dc801dc20cb7a82bfded79b3a362ac0)

  • OpenSSL Dynamic Engine (SHA256 checksum 76cff941f36275163db146e05bf5fe64440248643ceb5dfcb3b64103f4f016a7)

  • JCE provider (SHA256 checksum 8c38082797172b5630c74a8fc0c9e2652f0898bd2232b72911fbbaaa0260b5a6)

  • CloudHSM CLI (SHA256 checksum 2a0640e32405a7db138afb2444a542eab11c0a7d9610d5406478c7ac4602a14b)

Amazon Linux 2

Download version 5.16.1 software for Amazon Linux 2 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum cfa59458ec239553c86ac55773bebc69a5dc7cdc08a3927917fd5918e10abe93)

  • OpenSSL Dynamic Engine (SHA256 checksum 49e50bece7d73f3b7dc95eed1df856a6dee40e27f24f40f015c6a4a2e8dee839)

  • JCE provider (SHA256 checksum 85c8853860aa36a6c54e75c94d607a334d64dd34683ba70430ff5be61eedcc56)

  • CloudHSM CLI (SHA256 checksum 0efc3783e8429331aa446e45776fef46c7f9726a4768763ba4881dc2b05e090e)

Download version 5.16.1 software for Amazon Linux 2 on ARM64 architecture:

  • PKCS #11 library (SHA256 checksum dad60a0380ef0ea9c469cae4de10dc47124bbecedafb6956d009734cd49abceb)

  • OpenSSL Dynamic Engine (SHA256 checksum 7ee303421d94544cbe9df03022c48af327833e631d8f1ec59a466673b6e9395d)

  • JCE provider (SHA256 checksum 5ebe8157abb042ee92a7edfbfcb98bf79fc3a9907684565176fd28c387c08e88)

  • CloudHSM CLI (SHA256 checksum 5e76b4a9021a3c92e59fc608c8263af731013835738977f376fb8ad9189add56)

RHEL 9 (9.2+)

Download version 5.16.1 software for RHEL 9 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 696e58f74d89bd8e39f85bddc547f8c94fa2fbca498318a7bb94f22e8be7a668)

  • OpenSSL Dynamic Engine (SHA256 checksum 86197cd8bdd70db91331bb8380ea094352b4087c95a04768d2cefc3bba18dffa)

  • JCE provider (SHA256 checksum 37ccc2df3e8aaddda74dc060f7f5bbe63e4769311f2ccbf313a8ab5d8831f206)

  • CloudHSM CLI (SHA256 checksum 45a6db22db9ae64c239b49ea9281d29d2b4364dd63ee2408f463de17c4da1877)

Download version 5.16.1 software for RHEL 9 on ARM64 architecture:

  • PKCS #11 library (SHA256 checksum fd79fbccf504f53a6e70497135fcea4e20982fca75b628124c7510dcbaddf56c)

  • OpenSSL Dynamic Engine (SHA256 checksum 23fe7407be9c5f8da0ae64e560a9741887bc31936f0b88c8d1490e3c6893a8a8)

  • JCE provider (SHA256 checksum bd1c43e3e28c2f71e78a41342c064ff873fd8e052f89f90227fe00eaa28f089e)

  • CloudHSM CLI (SHA256 checksum 3e877a232303052b8a6b2b869dcf228edbb0da913d3d41393f622831f4455a27)

RHEL 8 (8.3+)

Download version 5.16.1 software for RHEL 8 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum d396c53c229b1eaa7cb30d4fcd17addc9170c7942795d1c82b23a157ec379686)

  • OpenSSL Dynamic Engine (SHA256 checksum c01f2cb66a6c5be839906b25c6a7f7990507b1b8ec3da34c128c1a90838e48df)

  • JCE provider (SHA256 checksum 1745ab78de0712111659e91301f80e771e1b7ebc2ff8c4cc5e37bce591058520)

  • CloudHSM CLI (SHA256 checksum b3ca40ba66062856ef63848c71f6e9dfa0a46a2b18d44c2d96a798fc4a4fb9cf)

Ubuntu 24.04 LTS

Download version 5.16.1 software for Ubuntu 24.04 LTS on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum ade113ee72547cb6a8fe91a4f3ac403f462d0acd0a306f01d16ac90699f9b59c)

  • OpenSSL Dynamic Engine (SHA256 checksum 9e00cb32b16fbb286a853f65c5c5154c3e805ad67820d829a0c5343f12cc9e00)

  • JCE provider (SHA256 checksum 4fab322a138e14372aba394de29f444af640479dd338539be84e0cf659c8993b)

  • CloudHSM CLI (SHA256 checksum f8c1e369885eb77ba4517388dab47c067a617e860fb67a028a1ebde0f96acaef)

Download version 5.16.1 software for Ubuntu 24.04 LTS on ARM64 architecture:

  • PKCS #11 library (SHA256 checksum 5e15a69f8fb1429ed5c10429c91323fe82a63c0fe7bcc2f968820733d1737449)

  • OpenSSL Dynamic Engine (SHA256 checksum f5136ee61bd34b74d59a01d37964b70a0f80ec5981f732b265af1c5466309e6f)

  • JCE provider (SHA256 checksum acf5bebe7009461cdc1e31b95caadcbf80da09ec78d8f69142072da9baf61b79)

  • CloudHSM CLI (SHA256 checksum 511376d2faf9f991f2193d08f80fc1edd53bf06daaa6fd8bd7a3fba0d6563ad1)

Ubuntu 22.04 LTS

Download version 5.16.1 software for Ubuntu 22.04 LTS on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum e1d787f10ee51d94732732811e4d2110f1b8e448e67fd47df8b53a2f7e56e3c8)

  • OpenSSL Dynamic Engine (SHA256 checksum 29a9c41379754ce098a025feadc026f2f75a8638981f5b95ed07007d5b3d8510)

  • JCE provider (SHA256 checksum 390d21e499ba181dc2774c3140433f6e60b49d9de3a892a89038c27e1aff157b)

  • CloudHSM CLI (SHA256 checksum cadadafaa9464f944e5c2446df92fb1777a9e1e5116cab1b359a8aa101cf7ae8)

Download version 5.16.1 software for Ubuntu 22.04 LTS on ARM64 architecture:

  • PKCS #11 library (SHA256 checksum 3b6a3d50b4a55c150f12308ee3914451897bc4cc4c8420accf1d2d706316fcce)

  • OpenSSL Dynamic Engine (SHA256 checksum c366a3c5faf4de32a6dedc4613234ba3d331b0abac3241bed7d25e0109a44f64)

  • JCE provider (SHA256 checksum 705416b47bc62781b5a6dfc78dd02dadb4f18f842b569c3e210b9535813b9e70)

  • CloudHSM CLI (SHA256 checksum 811b501615cf34665b70f103905094ca84ed7c126f72d91b040aacda99dbf22b)

Ubuntu 20.04 LTS

Download version 5.16.1 software for Ubuntu 20.04 LTS on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 6a2c33c78ada33fb435bbf8939b7cde3efe968e9f03250083dc6024b7ebd45b8)

  • OpenSSL Dynamic Engine (SHA256 checksum 6ee178454e78d88e0ab92cd7c5b056d0c04cd6de192aea731d7ebcbd4c5ed761)

  • JCE provider (SHA256 checksum 1e61ccd8d2b37c64467051d26e8d8bd592465ecef04282d6f4a9491707ba059d)

  • CloudHSM CLI (SHA256 checksum 645693f2ede4fa0d7879eedaa41ae23120d902f24c9a637ba088f277e703cb96)

Windows Server 2025

Download version 5.16.1 software for Windows Server 2025 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 25beadaf28323412c60ed6695d89b6261d34da9cccf08869923b979854aa0329)

  • JCE provider (SHA256 checksum 65f487f22c0786b80d81b387f5f4c8a6c9395c8d31a020c91fc0105829b8ec2c)

  • CloudHSM CLI (SHA256 checksum d4dc9f5efd2b5e2eb07a59fb237f7f8dfd5476c859cdb9f91841354ce88783c4)

  • Key Storage Provider (KSP) (SHA256 checksum 80f70eb3ba22d34e49b5b5da3fa183c86c751bff46229ae16fb83a5fc69a4d0c)

Windows Server 2022

Download version 5.16.1 software for Windows Server 2022 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 25beadaf28323412c60ed6695d89b6261d34da9cccf08869923b979854aa0329)

  • JCE provider (SHA256 checksum 65f487f22c0786b80d81b387f5f4c8a6c9395c8d31a020c91fc0105829b8ec2c)

  • CloudHSM CLI (SHA256 checksum d4dc9f5efd2b5e2eb07a59fb237f7f8dfd5476c859cdb9f91841354ce88783c4)

  • Key Storage Provider (KSP) (SHA256 checksum 80f70eb3ba22d34e49b5b5da3fa183c86c751bff46229ae16fb83a5fc69a4d0c)

Windows Server 2019

Download version 5.16.1 software for Windows Server 2019 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 25beadaf28323412c60ed6695d89b6261d34da9cccf08869923b979854aa0329)

  • JCE provider (SHA256 checksum 65f487f22c0786b80d81b387f5f4c8a6c9395c8d31a020c91fc0105829b8ec2c)

  • CloudHSM CLI (SHA256 checksum d4dc9f5efd2b5e2eb07a59fb237f7f8dfd5476c859cdb9f91841354ce88783c4)

  • Key Storage Provider (KSP) (SHA256 checksum 80f70eb3ba22d34e49b5b5da3fa183c86c751bff46229ae16fb83a5fc69a4d0c)

Windows Server 2016

Download version 5.16.1 software for Windows Server 2016 on x86_64 architecture:

  • PKCS #11 library (SHA256 checksum 25beadaf28323412c60ed6695d89b6261d34da9cccf08869923b979854aa0329)

  • JCE provider (SHA256 checksum 65f487f22c0786b80d81b387f5f4c8a6c9395c8d31a020c91fc0105829b8ec2c)

  • CloudHSM CLI (SHA256 checksum d4dc9f5efd2b5e2eb07a59fb237f7f8dfd5476c859cdb9f91841354ce88783c4)

  • Key Storage Provider (KSP) (SHA256 checksum 80f70eb3ba22d34e49b5b5da3fa183c86c751bff46229ae16fb83a5fc69a4d0c)

Client SDK 5.16.1 adds support for signing and verifying prehashed data in the CloudHSM CLI.

Platform support
  • SDK 5.16.1 is the last release to provide Ubuntu 20.04 LTS platform support. For more information, see the Ubuntu website.

CloudHSM CLI
JCE provider
  • Updated AES/CBC/Pkcs5Padding Encryption mode to automatically generate a random Initialization Vector (IV) when null IV is provided. Previously, null IV would result in an operation failure. Explicit IVs remain mandatory for decrypt operations.

Bug fixes/Improvements
  • Reduced latency for repeated digest update operations in JCE.

  • Updated the `generate key-reference` command to correctly name KSP key reference files based on their Attribute ID values when running on Windows Server. For more information, see Generating KSP key references (Windows).