github NeySlim/ultimate-ca-manager v2.208

latest releases: v2.235, v2.235-rc1, v2.234...
one month ago

What's Changed

Added

  • WSTEP: per-template pinned subject fields (C/ST/L/O/OU) — CSR/AD-supplied values overridden, CN/SAN stay dynamic (#274, contributed by @Hemsby)
  • WSTEP: AD SID security extension (szOID_NTDS_CA_SECURITY_EXT) on Kerberos-bound issuance for KB5014754 strong certificate mapping (#275, contributed by @Hemsby)

Fixed

  • Kerberos availability check now requires the gssapi backend, not just importable spnego (which ships transitively) — XCEP no longer advertises/attempts a broken Kerberos binding (#273, contributed by @Hemsby)

📜 Recent release history (last 2 versions)

[2.207] - 2026-08-11

Added

  • Native Windows autoenrollment (MS-XCEP + MS-WSTEP) (#229, contributed by @Hemsby) — UCM now serves the Active Directory Certificate Services enrollment protocols: MS-XCEP policy discovery (/ADPolicyProvider_CEP_* GetPolicies, advertising key usage, EKUs and enrollment URIs to Windows clients) and MS-WSTEP issuance/renewal (/ADCertificateService_CES_* RequestSecurityToken — RequestSecurityTokenResponseCollection). Three authentication bindings, mirroring real ADCS CES endpoints: WS-Security UsernameToken (with HTTP Basic fallback), client-certificate renewal (the RST must be XML-DSig-signed with the private key of a certificate UCM itself issued — byte-for-byte matched against the stored certificate), and Kerberos/SPNEGO over HTTP Negotiate (pyspnego + keytab, optional dependency). A new AD Connector (Settings) lets UCM query Active Directory over LDAP(S) — bind password encrypted at rest — to derive the subject of the deliberately-empty CSRs Windows GPO machine autoenrollment submits (machine: CN=<dNSHostName>; user, opt-in per template: the AD directory DN as subject plus a UPN OtherName SAN, with the AD mail attribute opportunistically added). Templates gain three opt-in flags: autoenroll_enabled (advertise autoEnroll=true in XCEP policy — the Enroll/Autoenroll split real ADCS enforces), ad_derived_subject, and allowed_ad_group for per-template Enroll ACL via AD group membership (nested groups included). Windows-specific interop details were verified against a live AD lab, including the TLS 1.2 cap required by some schannel clients (applied only while WSTEP is enabled), CMC full-PKCS#7 request unwrapping and response building, the Microsoft Certificate Template extension on issued certs (absence breaks CX509Enrollment), UPN SANs, and proof-of-possession enforced on PKCS#7/CMC-wrapped requests.
  • SSH certificate issuance UI — the certificate type selector now auto-syncs to the selected SSH CA (contributed by @gb-123-git).

Security

  • Community audit round-up (contributed by @gb-123-git, #263): path traversal in the update-download helper (unsanitized package_name reached a file path), path verification on backup download/delete (filenames are now resolved and confined to the backup directory), SQL-injection hardening of the PostgreSQL sequence-reset helper (compiler-rendered identifiers and bound names, per-column savepoints), missing ownership checks on ACME-proxy resources — account status enforced at new-order, DNS automation only triggers for the order's owner, challenge-to-order attribution fails closed when the upstream CA omits the Link rel="up" header (legacy orders recorded before ownership tracking intentionally keep read access) — IDOR fixes on user-certificate revoke/delete, SSO provider secrets no longer returned to non-admins requesting include_secrets, CA export password removed from the URL query string (out of access logs), LDAP bind passwords encrypted at rest, and security-sensitive settings (session/lockout/HSTS/public-URL/password-policy keys) now require admin:settings, with the settings UI locking those fields for operators instead of failing the whole card save.
  • WebSocket security overhaul (contributed by @gb-123-git, #263): socket handshakes previously skipped authentication entirely, so any connection received every certificate/CA broadcast, and authenticated clients could subscribe to arbitrary rooms. Connections now authenticate through the Flask session (or an API key scoped to its owner's current permissions, with mandatory periodic re-authentication) and fail closed on error, events are emitted to server-managed permission-scoped rooms only, clients cannot leave mandatory rooms or join privileged ones without the underlying permissions, subscriptions are rate-limited, sessions are periodically re-validated against the auth manager, and API-key authentication in the URL query string is deliberately unsupported.
  • WSTEP certificate-bound renewal requires the exact issued certificate — renewal originally recognized the signing certificate by serial number alone; serial and subject are public, so a forged self-signed lookalike bearing a victim's serial/subject could renew a victim's identity onto an attacker's key. The presented certificate must now match the stored certificate byte-for-byte for the configured CA, and the DB lookup tolerates all serial storage formats (serial_variants(); ARI reuses the same helper).

Fixed

  • Empty-subject CSRs with an IP-only SAN now populate the CN from that IP — the populate-CN-from-SAN fallback only looked at DNS names, so certbot-style CSRs whose single SAN is an IP address produced certificates with a genuinely empty subject (some clients, notably Safari on iOS, reject those) (#271, contributed by @Hemsby).
  • SSH CA download/copy public-key buttons and the missing openssh-client package in the Docker image for KRL generation (contributed by @gb-123-git).
  • Kerberos keytab-validation tests now skip when the optional gssapi extra is not installed (CI environments without the Kerberos libraries), rather than failing.

[2.206] - 2026-08-08

Added

  • Optional purge of replaced ACME-proxy certificates (#240) — new opt-in ACME setting acme.proxy.prune_replaced_certificates (UI toggle under ACME → Let's Encrypt proxy): when a proxy order finalizes, certificates previously imported by proxy orders for the exact same domain set are deleted instead of piling up in the inventory. Revoked certificates are always kept, and certificates not issued through the proxy are never touched. Off by default. (Note: the proxy never stores the client's private key in the first place — keys stay client-side by design of ACME CSRs.)
  • CRL validity window extended to 5 years for offline CAs (#236) — validity_days now accepts 1–1825 (was 1–365) and the CRL/OCSP page offers 90d/180d/1y/3y/5y options, with a warning past one year since relying parties may keep stale revocation data for the full window. Intended for offline root CAs that cannot re-sign CRLs on schedule; online CAs should stay at short validity.

Fixed

  • Duplicate CA/certificate creation on double-submit (#269) — the Create CA modal and Issue Certificate form never disabled their submit button, so a double-click (or Enter+click) during a slow RSA keygen created two identical objects. Both forms now ignore re-entrant submissions and disable the button while one is in flight.

Full history: CHANGELOG.md


Installation

Docker (Recommended)

# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.208

# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.208

# Run
docker run -d -p 8443:8443 \
  -e SECRET_KEY=$(openssl rand -hex 32) \
  --name ucm neyslim/ultimate-ca-manager:2.208

Debian/Ubuntu

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.208/ucm_2.208_all.deb
sudo dpkg -i ucm_2.208_all.deb
sudo apt-get install -f

Fedora/RHEL

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.208/ucm-2.208-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.208-1.fc43.noarch.rpm

Silent/Automated Install

# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.208_all.deb

Default Credentials

  • Username: admin
  • Password: changeme123

Change the password immediately after first login!

Documentation

Don't miss a new ultimate-ca-manager release

NewReleases is sending notifications on new releases.