See below for the new features in CA Gateway for Cryptographic Security Platform 1.5.0.

New ​Default Certificate Events Query Page setting (ATEAM-19041)

The Cryptographic Security Platform interface for configuring CA Gateway now includes the Default Certificate Events Query Page​ setting.

POST request body in debug logs (ATEAM-19042)

When selecting the DEBUG logging level, the logs include the HTTP request body for POST requests.

See Logging for how to select the log level.

GlobalSign Atlas CA support (ATEAM-19168)

CA Gateway now supports GlobalSign Atlas certificate authorities through the GlobalSign Certificate Center (GCC).

High-availability support (ATEAM-19298)

CA Gateway now supports high-availability deployments in PKI Hub clusters.

S/Mime support for Sectigo CA (ATEAM-19503)

Integration with Sectigo CA now supports S/MIME certificate enrollment.

OAuth 2.0 support for Sectigo CA (ATEAM-19505)

Integration with Sectigo CA now supports OAuth 2.0 authentication.

New SPIRE UpstreamAuthority plugin anchored to a CSP Certificate Authority (PKIAL-5195)

The new UpstreamAuthority plugin anchors trust in a CSP root Certificate Authority by delegating intermediate CA certificate signing to Entrust CA Gateway. It plays a central role in establishing the trust chain for Agentic AI integrations. SPIRE continues to provide workload attestation and short-lived SVID issuance, enabling zero-trust cryptographic identities. This approach keeps trust rooted in the CSP Certificate Authority and enables mTLS-based agent-to-agent and agent-to-service authentication without static secrets or API keys.

The plugin source code and installation instructions are publicly available at:

https://github.com/EntrustCorporation/cagw-spire-upstreamauthority-plugin