📜 Recent release history (last 2 versions)
[2.208] - 2026-08-12
Added
- WSTEP: per-template pinned subject fields (C/ST/L/O/OU) — CSR/AD-supplied values overridden, CN/SAN stay dynamic (#274, contributed by @Hemsby)
- WSTEP: AD SID security extension (szOID_NTDS_CA_SECURITY_EXT) on Kerberos-bound issuance for KB5014754 strong certificate mapping (#275, contributed by @Hemsby)
Fixed
- Kerberos availability check now requires the gssapi backend, not just importable spnego (which ships transitively) — XCEP no longer advertises/attempts a broken Kerberos binding (#273, contributed by @Hemsby)
[2.207] - 2026-08-11
Added
- Native Windows autoenrollment (MS-XCEP + MS-WSTEP) (#229, contributed by @Hemsby) — UCM now serves the Active Directory Certificate Services enrollment protocols: MS-XCEP policy discovery (
/ADPolicyProvider_CEP_*GetPolicies, advertising key usage, EKUs and enrollment URIs to Windows clients) and MS-WSTEP issuance/renewal (/ADCertificateService_CES_*RequestSecurityToken — RequestSecurityTokenResponseCollection). Three authentication bindings, mirroring real ADCS CES endpoints: WS-Security UsernameToken (with HTTP Basic fallback), client-certificate renewal (the RST must be XML-DSig-signed with the private key of a certificate UCM itself issued — byte-for-byte matched against the stored certificate), and Kerberos/SPNEGO over HTTPNegotiate(pyspnego + keytab, optional dependency). A new AD Connector (Settings) lets UCM query Active Directory over LDAP(S) — bind password encrypted at rest — to derive the subject of the deliberately-empty CSRs Windows GPO machine autoenrollment submits (machine:CN=<dNSHostName>; user, opt-in per template: the AD directory DN as subject plus a UPNOtherNameSAN, with the ADmailattribute opportunistically added). Templates gain three opt-in flags:autoenroll_enabled(advertiseautoEnroll=truein XCEP policy — the Enroll/Autoenroll split real ADCS enforces),ad_derived_subject, andallowed_ad_groupfor per-template Enroll ACL via AD group membership (nested groups included). Windows-specific interop details were verified against a live AD lab, including the TLS 1.2 cap required by some schannel clients (applied only while WSTEP is enabled), CMC full-PKCS#7 request unwrapping and response building, the Microsoft Certificate Template extension on issued certs (absence breaksCX509Enrollment), UPN SANs, and proof-of-possession enforced on PKCS#7/CMC-wrapped requests. - SSH certificate issuance UI — the certificate type selector now auto-syncs to the selected SSH CA (contributed by @gb-123-git).
Security
- Community audit round-up (contributed by @gb-123-git, #263): path traversal in the update-download helper (unsanitized
package_namereached a file path), path verification on backup download/delete (filenames are now resolved and confined to the backup directory), SQL-injection hardening of the PostgreSQL sequence-reset helper (compiler-rendered identifiers and bound names, per-column savepoints), missing ownership checks on ACME-proxy resources — account status enforced at new-order, DNS automation only triggers for the order's owner, challenge-to-order attribution fails closed when the upstream CA omits theLink rel="up"header (legacy orders recorded before ownership tracking intentionally keep read access) — IDOR fixes on user-certificate revoke/delete, SSO provider secrets no longer returned to non-admins requestinginclude_secrets, CA export password removed from the URL query string (out of access logs), LDAP bind passwords encrypted at rest, and security-sensitive settings (session/lockout/HSTS/public-URL/password-policy keys) now requireadmin:settings, with the settings UI locking those fields for operators instead of failing the whole card save. - WebSocket security overhaul (contributed by @gb-123-git, #263): socket handshakes previously skipped authentication entirely, so any connection received every certificate/CA broadcast, and authenticated clients could subscribe to arbitrary rooms. Connections now authenticate through the Flask session (or an API key scoped to its owner's current permissions, with mandatory periodic re-authentication) and fail closed on error, events are emitted to server-managed permission-scoped rooms only, clients cannot leave mandatory rooms or join privileged ones without the underlying permissions, subscriptions are rate-limited, sessions are periodically re-validated against the auth manager, and API-key authentication in the URL query string is deliberately unsupported.
- WSTEP certificate-bound renewal requires the exact issued certificate — renewal originally recognized the signing certificate by serial number alone; serial and subject are public, so a forged self-signed lookalike bearing a victim's serial/subject could renew a victim's identity onto an attacker's key. The presented certificate must now match the stored certificate byte-for-byte for the configured CA, and the DB lookup tolerates all serial storage formats (
serial_variants(); ARI reuses the same helper).
Fixed
- Empty-subject CSRs with an IP-only SAN now populate the CN from that IP — the populate-CN-from-SAN fallback only looked at DNS names, so
certbot-style CSRs whose single SAN is an IP address produced certificates with a genuinely empty subject (some clients, notably Safari on iOS, reject those) (#271, contributed by @Hemsby). - SSH CA download/copy public-key buttons and the missing
openssh-clientpackage in the Docker image for KRL generation (contributed by @gb-123-git). - Kerberos keytab-validation tests now skip when the optional
gssapiextra is not installed (CI environments without the Kerberos libraries), rather than failing.
Full history: CHANGELOG.md
Installation
Docker (Recommended)
# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.209-rc1
# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.209-rc1
# Run
docker run -d -p 8443:8443 \
-e SECRET_KEY=$(openssl rand -hex 32) \
--name ucm neyslim/ultimate-ca-manager:2.209-rc1Debian/Ubuntu
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.209-rc1/ucm_2.209.rc1_all.deb
sudo dpkg -i ucm_2.209.rc1_all.deb
sudo apt-get install -fFedora/RHEL
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.209-rc1/ucm-2.209.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.209.rc1-1.fc43.noarch.rpmSilent/Automated Install
# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.209.rc1_all.debDefault Credentials
- Username:
admin - Password:
changeme123
Change the password immediately after first login!
Documentation
- Installation Guide
- API Documentation