Combined Key Management release notes for upgrades from Zurich to Australia

  • Release version: Australia
  • Updated August 11, 2026
  • 4 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Key Management release notes for upgrades from Zurich to Australia

    This consolidated release note page helps ServiceNow customers prepare for upgrading Key Management from Zurich to Australia. It highlights new features, important upgrade information, changes, and activation details to ensure a smooth transition and improved cryptographic capabilities.

    Show full answer Show less

    Important Information for Upgrading

    • Australia release discontinues the use of the deprecated GlideEncrypter API based on 3DES encryption in new instances, aligning with NIST 800-131A Rev 2 recommendations.
    • Upgraded Australia instances still support GlideEncrypter, but it now uses AES256-GCM encryption through the Key Management Framework (KMF).
    • All base system scripts have been updated to use alternative encryption methods to prepare for future deprecation of GlideEncrypter/3DES.

    Key Features Introduced in Australia

    • SHA512 Support: GlideDigest now supports creation and verification of message digests using the SHA512 cryptographic hash function, enhancing security.
    • Offline Key Exchange: Administrators can share cryptographic module keys offline between on-premise instances to facilitate cloning and migration.
    • JWT Signing and Verification: JSON Web Token (JWT) signing and verification are integrated as KMFCryptoOperation class operations for streamlined cryptographic processes.
    • Centralized Crypto Management Console: A new console scans and displays all certificates on an instance, streamlining certificate lifecycle management.
    • Clone and Restore Support: Added support for cloning and restoring on-premise instances, including migration between commercial and on-premise instances.
    • Certificate Revocation List (CRL) Validation: Support for CRL validation has been added as an alternative to OCSP, with automatic fallback, improving certificate revocation checks.

    Changes

    • Streamlined workflow for creating cryptographic modules to improve speed and ease of use.
    • Enhancements to the SecurityUtils API to better prevent cross-site scripting (XSS) attacks by sanitizing and escaping inputs.

    Activation and Licensing

    • The Platform Encryption subscription bundle includes Field Encryption Enterprise and Cloud Encryption.
    • Field Encryption Enterprise offers unlimited usage and is activated via the com.glide.now.platform.encryption plugin.
    • Customers should review subscription details to ensure proper activation of encryption features.

    Additional Notes

    No updates were made in Zurich or to localization, browser requirements, accessibility, or feature removals/deprecations for Key Management in this upgrade cycle.

    Practical Benefits for ServiceNow Customers

    • Upgrading to Australia enhances cryptographic security by adopting AES256-GCM encryption and SHA512 hashing.
    • New tools and workflows simplify certificate and key management tasks, improving operational efficiency.
    • Offline key sharing supports complex on-premise instance management scenarios like cloning and migration.
    • Improved security APIs help protect against common web vulnerabilities.

    Consolidated page of all release notes for Key Management from Zurich to Australia.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Key Management release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Zurich to Australia.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Key Management to Australia

    Before you upgrade to Australia, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    • In pre-Zurich releases, the GlideEncrypter API used the three-key Triple Data Encryption Standard (3DES) encryption standard, which NIST 800-131A Rev 2 has recommended against using after 2023. The following changes are taking place in the Australia release in preparation for a full deprecation of GlideEncrypter/3DES in the future:
      • New Australia instances can’t use GlideEncrypter. All base system scripts have been changed to use alternative encryption processes.
      • if you’re upgrading your Australia instances, you can still GlideEncrypter, which has been updated to use AES256-GCM encryption via the Key Management Framework.
      • Learn more about 3DES deprecation in KB1704481.

    New features

    Between your current release family and Australia, new features were introduced for Key Management.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    Added SHA512 support for message digests
    GlideDigest has been updated to allow creation and verification of message digests using the SHA512 cryptographic hash function.
    Offline key exchange to share module keys between instances
    Admins can share module keys between instances offline to facilitate instance clones between on-premise instances using KMF.
    Sign and verify JSON web tokens (JWT) through KMFCryptoOperation
    The signing and verification processes for JWTs are now integrated as operation types in the existing KMFCryptoOperation class.
    Centralized Crypto Management console
    Use the new Crypto Management Console to streamline and track the certificate management lifecycle. The new console scans your instance for certificates and displays their details in a central location,
    Clone and restore support for on-premise instances
    Support for cloning and restoring on-premise instances. Support has also been added from migrating a commercial instance to on-premise instances, and vice-versa.
    Certificate Revocation List (CRL) validation support
    ServiceNow now supports Certificate Revocation List (CRL) validation for certificate revocation checks as an alternative to Online Certificate Status Protocol (OCSP), with automatic fallback when OCSP is unavailable.

    Changes

    Between your current release family and Australia, some changes were made to existing Key Management features.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    Updated workflow for creating cryptographic modules
    Use the streamlined workflow designed for faster, easier creation of cryptographic modules.
    SecurityUtils Enhancements
    The SecurityUtils API has been enhanced to help prevent cross-site scripting attacks, including methods to sanitize and escape input.

    Removed

    Between your current release family and Australia, some Key Management features or functionality were removed.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Deprecations

    Between your current release family and Australia, some Key Management features or functionality were deprecated.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Activation information

    Review information on how to activate Key Management.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    The Platform Encryption subscription bundle is a group commercial entitlement that includes Field Encryption Enterprise and Cloud Encryption.

    Field Encryption Enterprise is the unlimited license of Field Encryption. The Enterprise plugin is available with the activation of the com.glide.now.platform.encryption plugin. For details, see Encryption and Key Management subscription bundle.

    Additional requirements

    If any additional requirements were introduced or changed for Key Management we have noted them here.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Key Management we have noted them here.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Key Management, such as specific requirements or compliance levels.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Localization information

    If there are specific localization considerations for Key Management we have noted them here.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Key Management we have noted them here.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    • GlideDigest has been updated to allow creation and verification of message digests using the SHA512 cryptographic hash function
    • Admins can share module keys between instances offline to facilitate instance clones between on-premise instances using KMF.
    • The signing and verification processes for JWTs are now integrated as operation types in the existing KMFCryptoOperation class.

    See Key Management Framework for more information.