Release Notes — v17.2.11 (April 1, 2026)
New Features
- Atlassian Onboarding: Added AD user creation via Gateway with support for username templates.
- Domain Alias Commands — New commands for managing domain aliases.
- KEPM Report Value Command — Added
report valuecommand for KEPM. - PAM Launch "Connect As" — Added "Connect As" options to pam launch, allowing additional records to provide credentials and host:port (#1871).
- PAM Launch Key-Event Input — Added key-event input support in pam launch for session recording (#1900).
- PAM Tunnel Diagnose Enhancements — Extended pam tunnel diagnose with full gateway readiness testing (#1885).
- Share Folder Enhancements — Added path, userId, and expiration date fields to the share folder command (#1893).
Improvements
- Share Report & Security Audit Report — Updates to share-report and security-audit-report commands (#1896).
- Secrets Folder Matching — Folders are now matched by name at any depth, reusing their IDs for secrets lookup.
- PAM Launch SSH Key Lookup — Improved lookup for launch credentials with SSH keys only (#1886).
- Decreased WebRTC Log Verbosity — Reduced log noise from keeper-pam-webrtc-rs during terminal sessions (#1879).
- Updated DAG & Discovery Modules — Updated keeper_dag and discovery_common modules.
Bug Fixes
- PEDM Policy Filters —
policy addcommand now creates all filters. - V2 Record Restriction — New clients are prevented from editing or adding v2 records.
- PAM Launch Fixes — Fixed double newlines on some terminals (Linux, macOS), improved handling of non-terminal protocols (#1870).
- Launch Credential Update — Fixed launch credential not updating on repeated edit of launch-user (#1884).
- PAM Launch Port Override — Fixed connection port override for pamHostname (#1881).
- Security Audit Logic — Fixed needs_security_audit logic.
- Duplicate Warnings — Fixed duplicate warnings in msp-add and en add.
- Two-Factor Duration Display — Fixed enforcement display to show single value instead of cumulative list.
- EPM Bugfixes
- Service Mode JSON — Fixed JSON handling in service mode (#1882).
- Broken Import — Fixed broken import after refactoring (#1888).