๐ Recent release history (last 2 versions)
[2.186] - 2026-07-06
Fixed
- ACME proxy
/directoryon fresh install โ the legacy/acme/proxy/directoryand/new-nonceendpoints returned a 500 (No external ACME CA account configured for the proxy) on a brand-new instance before any external CA account was added, because the proxy service resolved the upstreamAcmeClientAccounteagerly in its constructor. Resolution is now lazy: only the upstream directory URL (config-derived, defaults to Let's Encrypt staging) is needed for/directoryand/new-nonce, and the account row is looked up on the first key-bearing operation (new-account,new-order, signing), preserving the helpful configuration error for actual signing paths. This had broken the release smoke gate on a fresh Docker container. - ACME manual verify DNS wait and authorization poll cadence โ the synchronous manual-verify endpoint ran the DNS self-check up to the full configured
dns_propagation_timeout(max 3600 s), risking client/proxy timeouts; it is now capped at 30 s (background auto-poll still honors the full timeout). The auto-poll loop also queried per-domain authorization status on every iteration, doubling CA traffic; it is now checked everymax(poll_interval ร 5, 15)s, with the order-status poll still catching terminalinvalidstates each interval. - Contact-less upstream account registration โ
AcmeClientService.register_accountnow acceptsemail=Noneand omits thecontactfield (RFC 8555 makes it optional; Let's Encrypt accepts contact-less registrations), so the proxy no longer blocks issuance when the only available email has a non-public TLD (.lan/.local). - ACME preflight staging order cleanup on failure โ an ephemeral staging order created during a
fullpreflight is now removed from the database even when a later stage of the preflight raises, instead of leaking an orphan row. - Key-reuse renewal fallback โ
key_source=reusenow falls back to the originalsource_certificate_idwhen the order's owncertificate_idis missing (e.g. an order whose import failed), so the key-reuse chain survives across renewals.
[2.185] - 2026-07-06
Added
- ACME proxy multi-CA with per-account slug endpoints โ the ACME proxy upstream is now selected per external CA account (
AcmeClientAccount), so several CAs (Let's Encrypt staging, production, ZeroSSL, โฆ) can be exposed in parallel. Each account can opt in to the proxy with a unique slug, served at/acme/proxy/<slug>/directoryalongside the legacy/acme/proxy/directory(backward compatible). Reserved slugs (directory,new-order,acct,challenge, โฆ) prevent collisions with existing routes. Migrations050(acme.proxy.acme_account_id) and051(proxy_enabled,proxy_slug) backfill the account already linked in proxy settings. The UI surfaces a toggle and slug field on external CA accounts and lists all enabled endpoints with a Certbot example (#170). - Typed SAN validation for certificate issuance โ the Issue Certificate form (
POST /api/v2/certificates) now validates SAN entries per type (DNS, IP, Email, URI, UPN) on both backend and frontend, with cross-type errors (e.g. an FQDN entered in the IP field is rejected with a hint to use DNS) and ECDSA curve mapping (256/384/521 โprime256v1/secp384r1/secp521r1). The CN auto-SAN no longer adds an email CN as a DNS SAN on server certs; email SAN is added only for Email/Combined types. New RSA 3072 size and P-384/P-521 curve options appear in the Issue Certificate selector (#169). - CI: block bot Co-authored-by trailers โ a new
no-bot-attribution.ymlworkflow rejects PRs whose commits carryCo-authored-bytrailers from known AI agent identities (Cursor, Copilot, Claude, โฆ), so commits attributed to bots can no longer reachdev.
Fixed
- ACME DNS-01 propagation diagnostics and
dns_propagation_timeout=0โ the DNS-01 self-check succeeds as soon as the authoritative (or configured) resolver confirms the TXT record, but the per-public-resolver diagnostic log was emitted even on success and a flaky resolver (e.g. SERVFAIL from Quad9) was indistinguishable from a real propagation gap. Each failing public resolver is now logged at DEBUG with its exception type (NXDOMAIN/Timeout/ConnectionError/ โฆ) and the public-propagation line is explicitly marked(diagnostic, does not block issuance).dns_propagation_timeout=0now skips the pre-check entirely on both the auto-poll background path and the manual Verify path (was a single-pass probe), matching the "submit immediately" help text (#171). - TXT RDATA multi-string concatenation โ long ACME authorization tokens published as a single TXT RR carrying several
<character-string>elements (RFC 1035 ยง3.3.14; Quad9 splits them across quoted strings) are now joined before matching against the expected value. A correctly published record no longer renders asvalue_mismatch/pendingon such a resolver (#171). - Migration 050 NotNullViolation on PostgreSQL โ the proxy account backfill inserted legacy credentials into
acme_client_accountswithoutcreated_at/updated_at; on instances where those columns areNOT NULLwithout a serverDEFAULT, the raw INSERT failed at boot (null value in column "created_at"). The migration now provides both timestamps explicitly on the SQLite and PostgreSQL paths. - Flaky OCSP/CDP auto-URL tests โ CA OCSP/CDP/AIA auto-URL generation relied on
hostname -fvia_get_fqdn(), which on CI runners can return a short hostname without a domain and resolve toNone, flaking the update-CA tests. The shared test app fixture now pinsFQDN = 'ucm.test'so URL generation is deterministic.
Full history: CHANGELOG.md
Installation
Docker (Recommended)
# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.187-rc1
# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.187-rc1
# Run
docker run -d -p 8443:8443 \
-e SECRET_KEY=$(openssl rand -hex 32) \
--name ucm neyslim/ultimate-ca-manager:2.187-rc1Debian/Ubuntu
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.187-rc1/ucm_2.187.rc1_all.deb
sudo dpkg -i ucm_2.187.rc1_all.deb
sudo apt-get install -fFedora/RHEL
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.187-rc1/ucm-2.187.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.187.rc1-1.fc43.noarch.rpmSilent/Automated Install
# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.187.rc1_all.debDefault Credentials
- Username:
admin - Password:
changeme123
Change the password immediately after first login!
Documentation
- Installation Guide
- API Documentation