Commander 18.1.6
This release adds new KeeperPAM proxy and import capabilities, strengthens Service Mode and enterprise permission checks, and includes several reliability fixes.
Highlights
-
Added KeeperRDP and KeeperSSH Proxy support for PAM tunnels, alongside KeeperDB Proxy.
pam tunnel start --proxyselects the applicable proxy for the resource;--credentialcan override the linked credential for RDP/SSH proxy tunnels when the resource permits user-supplied credentials. Proxy-ready messages now appear when the tunnel is connected. -
Added
pam tunnel edit --keeper-proxy on|off|defaultto configure the applicable proxy for supported resource protocols. Improved tunnel discovery and cleanup across processes, proxy diagnostics, and handling of ephemeral JIT credentials. -
Added Nested Shared Folder support to CyberArk PAM project imports (
--nsf), including imported folders, records, rotation, and PAM configuration. Imports can also match an existing shared folder by UID. -
Added HashiCorp Vault PAM configuration support through
pam config new/edit --environment hashicorp, including Vault URL, token, namespace, mount path, and HashiCorp ID options.
Security and access controls
-
Service Mode now blocks access to its own configuration records and protects integration configuration records, including SailPoint configuration. App-setup commands are restricted to their respective allowlists, and variable expansion can no longer bypass the SailPoint command guard.
-
Delegated administrators cannot grant or revoke sensitive enterprise privileges that they do not hold. PAM gateway creation and removal now enforce the
allow_pam_gatewaypolicy, including through legacy commands. -
Sensitive typed-record values are masked in record-add and record-update debug and Service Mode API logs.
Fixes and improvements
- Fixed stale-revision errors when editing PAM rotation by refreshing the cache first, and restored the gateway name in
pam rotation info. - Fixed Service Mode background operation and tunneling on Windows.
- Fixed truncated
application_infoandaccount_infofields in JSON/CSV output fromepm approval list. - Fixed an incorrect “Supported columns” warning for base fields in
enterprise-info. - Improved enterprise root-node rename and display-name handling, including root-node visibility.
- Added an optional path-aware mode for keeper-dag edges so edges on different paths are not inadvertently deactivated.
Full changelog: v18.1.5...18.1.6 (v18.1.5...v18.1.6)