📜 Recent release history (last 2 versions)
[2.196] - 2026-07-18
Added
- ACME loopback upstream opt-in — a new toggle (Let's Encrypt settings /
acme.client.allow_loopback_upstream, default off) allows the ACME client and proxy to reach an upstream CA on a loopback address (a colocated Pebble/step-ca on 127.0.0.1). Cloud-metadata targets remain blocked unconditionally.
Fixed
- Security-key (WebAuthn) login restored — after the per-user credential count was removed from
/auth/methods(username-enumeration hardening), the login page stopped offering the security-key option and auto-attempt. The UI no longer depends on that count: it auto-attempts based on the device's saved method and always offers the security-key button when the browser supports it. - WebAuthn username-enumeration oracle closed —
POST /auth/login/webauthn/startreturned a challenge only for users with a registered key (200) versus a 401 otherwise, and/verifyused distinguishable errors. Both now return identical, well-formed responses for unknown, credential-less, and real users (a deterministic per-username decoy credential), removing the account-existence oracle. - No default
serverAuthEKU on issuing CAs — intermediate CAs created via the API without an explicitextendedKeyUsagewere given aserverAuthEKU, which (via EKU chaining) invalidated clientAuth / emailProtection / OCSPSigning leafs issued beneath them, including delegated OCSP responders. Issuing CAs now have no EKU by default; constrain them explicitly viaextendedKeyUsage. - ACME proxy serves the preferred certificate chain — the per-account preferred chain was computed and stored but the upstream default chain was returned to the client; the selected chain is now the one delivered.
- ACME proxy order ownership binding — new-order and finalize now bind an order to the account resolved from the request
kid, so a different account can no longer finalize someone else's order. The previous binding only took effect for JWK-signed requests, which RFC 8555 new-order/finalize never are. - ACME DNS-01 self-check is advisory — a local resolver that cannot see the challenge TXT record (split-horizon or filtered egress DNS) no longer aborts renewal or proxy issuance before the challenge is submitted; the CA remains the authority. Set the propagation timeout to 0 to skip the pre-check entirely.
- SAN URI validation — the issuance/CSR forms now accept authority-less URIs (
urn:,mailto:,did:), matching what the API already allowed. - Account page PKCS#12 labels — two missing translation keys rendered as raw identifiers on the mTLS certificate export controls.
- Signed CSR history panel — clicking "View certificate" no longer throws a runtime error.
- ACME auto-renewal toggle persistence — the Let's Encrypt auto-renewal switch sent a field the API did not read, so the setting never saved; it now uses
renewal_enabled.
Translations
- Completed the ACME "verbose logs" label and description across all locales.
[2.195] - 2026-07-18
Added
- Named protocol URLs per CA (opt-in) — a CA created with
namedUrlsgets an immutable unique slug derived from its name, used instead of the random id in CDP/AIA URL paths (/cdp/my-issuing-ca.crl); both slug and refid forms always resolve. Easier manual configuration of CRL/OCSP paths in relying products; refid stays the default. Migration 060. (#207) - Full CRL schedule per CA — CRL validity (
nextUpdatewindow) decoupled from the publish cadence, withnext_publishexposed in CRL metadata and the scheduler republishing on the configured interval; configurable CRL signature digest (SHA-256/384/512). NewGET|POST /api/v2/crl/<ca_id>/config, CRL & OCSP page UI, migration 059. (#207) - Readable CRL download filename — CDP downloads suggest
{ca-slug}-{refid8}.crlviaContent-Disposition; URLs are unchanged (they are embedded in issued certificates). (#207) - Clock-skew tolerance on issuance — issued certificates backdate
notBeforeby a fixed 15 minutes so relying parties with slightly slow clocks accept fresh certificates;notAfterstays anchored on the requested validity. (#207) - Port 80 for protocol endpoints — documented the supported ways to serve CDP/OCSP/AIA on port 80 (systemd
CAP_NET_BIND_SERVICE, reverse proxy, Docker port mapping). (#207)
Fixed
- Template digest honored at issuance — certificates issued from the certificate menu were always signed SHA-256 regardless of the template's configured digest; the template link (
template_id) is now persisted on the issued row. (#207) - Template usage counter — the templates list/detail now return a live
usage_countcomputed from issued certificates (the UI previously displayed a field the API never provided). (#207)
Full history: CHANGELOG.md
Installation
Docker (Recommended)
# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.197-rc2
# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.197-rc2
# Run
docker run -d -p 8443:8443 \
-e SECRET_KEY=$(openssl rand -hex 32) \
--name ucm neyslim/ultimate-ca-manager:2.197-rc2Debian/Ubuntu
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.197-rc2/ucm_2.197.rc2_all.deb
sudo dpkg -i ucm_2.197.rc2_all.deb
sudo apt-get install -fFedora/RHEL
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.197-rc2/ucm-2.197.rc2-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.197.rc2-1.fc43.noarch.rpmSilent/Automated Install
# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.197.rc2_all.debDefault Credentials
- Username:
admin - Password:
changeme123
Change the password immediately after first login!
Documentation
- Installation Guide
- API Documentation