github NeySlim/ultimate-ca-manager v2.209-rc1

latest releases: v2.235, v2.235-rc1, v2.234...
pre-releaseone month ago
📜 Recent release history (last 2 versions)

[2.208] - 2026-08-12

Added

  • WSTEP: per-template pinned subject fields (C/ST/L/O/OU) — CSR/AD-supplied values overridden, CN/SAN stay dynamic (#274, contributed by @Hemsby)
  • WSTEP: AD SID security extension (szOID_NTDS_CA_SECURITY_EXT) on Kerberos-bound issuance for KB5014754 strong certificate mapping (#275, contributed by @Hemsby)

Fixed

  • Kerberos availability check now requires the gssapi backend, not just importable spnego (which ships transitively) — XCEP no longer advertises/attempts a broken Kerberos binding (#273, contributed by @Hemsby)

[2.207] - 2026-08-11

Added

  • Native Windows autoenrollment (MS-XCEP + MS-WSTEP) (#229, contributed by @Hemsby) — UCM now serves the Active Directory Certificate Services enrollment protocols: MS-XCEP policy discovery (/ADPolicyProvider_CEP_* GetPolicies, advertising key usage, EKUs and enrollment URIs to Windows clients) and MS-WSTEP issuance/renewal (/ADCertificateService_CES_* RequestSecurityToken — RequestSecurityTokenResponseCollection). Three authentication bindings, mirroring real ADCS CES endpoints: WS-Security UsernameToken (with HTTP Basic fallback), client-certificate renewal (the RST must be XML-DSig-signed with the private key of a certificate UCM itself issued — byte-for-byte matched against the stored certificate), and Kerberos/SPNEGO over HTTP Negotiate (pyspnego + keytab, optional dependency). A new AD Connector (Settings) lets UCM query Active Directory over LDAP(S) — bind password encrypted at rest — to derive the subject of the deliberately-empty CSRs Windows GPO machine autoenrollment submits (machine: CN=<dNSHostName>; user, opt-in per template: the AD directory DN as subject plus a UPN OtherName SAN, with the AD mail attribute opportunistically added). Templates gain three opt-in flags: autoenroll_enabled (advertise autoEnroll=true in XCEP policy — the Enroll/Autoenroll split real ADCS enforces), ad_derived_subject, and allowed_ad_group for per-template Enroll ACL via AD group membership (nested groups included). Windows-specific interop details were verified against a live AD lab, including the TLS 1.2 cap required by some schannel clients (applied only while WSTEP is enabled), CMC full-PKCS#7 request unwrapping and response building, the Microsoft Certificate Template extension on issued certs (absence breaks CX509Enrollment), UPN SANs, and proof-of-possession enforced on PKCS#7/CMC-wrapped requests.
  • SSH certificate issuance UI — the certificate type selector now auto-syncs to the selected SSH CA (contributed by @gb-123-git).

Security

  • Community audit round-up (contributed by @gb-123-git, #263): path traversal in the update-download helper (unsanitized package_name reached a file path), path verification on backup download/delete (filenames are now resolved and confined to the backup directory), SQL-injection hardening of the PostgreSQL sequence-reset helper (compiler-rendered identifiers and bound names, per-column savepoints), missing ownership checks on ACME-proxy resources — account status enforced at new-order, DNS automation only triggers for the order's owner, challenge-to-order attribution fails closed when the upstream CA omits the Link rel="up" header (legacy orders recorded before ownership tracking intentionally keep read access) — IDOR fixes on user-certificate revoke/delete, SSO provider secrets no longer returned to non-admins requesting include_secrets, CA export password removed from the URL query string (out of access logs), LDAP bind passwords encrypted at rest, and security-sensitive settings (session/lockout/HSTS/public-URL/password-policy keys) now require admin:settings, with the settings UI locking those fields for operators instead of failing the whole card save.
  • WebSocket security overhaul (contributed by @gb-123-git, #263): socket handshakes previously skipped authentication entirely, so any connection received every certificate/CA broadcast, and authenticated clients could subscribe to arbitrary rooms. Connections now authenticate through the Flask session (or an API key scoped to its owner's current permissions, with mandatory periodic re-authentication) and fail closed on error, events are emitted to server-managed permission-scoped rooms only, clients cannot leave mandatory rooms or join privileged ones without the underlying permissions, subscriptions are rate-limited, sessions are periodically re-validated against the auth manager, and API-key authentication in the URL query string is deliberately unsupported.
  • WSTEP certificate-bound renewal requires the exact issued certificate — renewal originally recognized the signing certificate by serial number alone; serial and subject are public, so a forged self-signed lookalike bearing a victim's serial/subject could renew a victim's identity onto an attacker's key. The presented certificate must now match the stored certificate byte-for-byte for the configured CA, and the DB lookup tolerates all serial storage formats (serial_variants(); ARI reuses the same helper).

Fixed

  • Empty-subject CSRs with an IP-only SAN now populate the CN from that IP — the populate-CN-from-SAN fallback only looked at DNS names, so certbot-style CSRs whose single SAN is an IP address produced certificates with a genuinely empty subject (some clients, notably Safari on iOS, reject those) (#271, contributed by @Hemsby).
  • SSH CA download/copy public-key buttons and the missing openssh-client package in the Docker image for KRL generation (contributed by @gb-123-git).
  • Kerberos keytab-validation tests now skip when the optional gssapi extra is not installed (CI environments without the Kerberos libraries), rather than failing.

Full history: CHANGELOG.md


Installation

Docker (Recommended)

# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.209-rc1

# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.209-rc1

# Run
docker run -d -p 8443:8443 \
  -e SECRET_KEY=$(openssl rand -hex 32) \
  --name ucm neyslim/ultimate-ca-manager:2.209-rc1

Debian/Ubuntu

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.209-rc1/ucm_2.209.rc1_all.deb
sudo dpkg -i ucm_2.209.rc1_all.deb
sudo apt-get install -f

Fedora/RHEL

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.209-rc1/ucm-2.209.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.209.rc1-1.fc43.noarch.rpm

Silent/Automated Install

# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.209.rc1_all.deb

Default Credentials

  • Username: admin
  • Password: changeme123

Change the password immediately after first login!

Documentation

Don't miss a new ultimate-ca-manager release

NewReleases is sending notifications on new releases.