What's Changed
Added
- ACME client accounts: multiple accounts can share the same CA directory URL — administrative separation for dns-persist-01 and multi-domain setups (#276)
- DNS providers: Tencent Cloud DNSPod (#284, contributed by @wxtewx)
Fixed
- ACME CA account form: the directory URL field is no longer marked required, and an empty URL defaults to Let's Encrypt Production — the helper text and the form now agree (#276)
- ACME account key import now documents the accepted legacy PEM envelopes — SEC1/X9.62 (BEGIN EC PRIVATE KEY) and PKCS#1 (BEGIN RSA PRIVATE KEY) already worked but the UI/helper only mentioned PKCS#8 (#285)
📜 Recent release history (last 2 versions)
[2.209] - 2026-08-14
Added
- SCEP profiles: Microsoft Intune challenge validation — live per-device challenge validation against Intune's
ScepActionsAPI with Entra app registration, forced auto-approve, and success/failure notification before issuance (#228, contributed by @Hemsby) - ACME client accounts: import the private key of an existing account at creation (algorithm derived from the key) (#277)
- ACME client accounts: deactivate an account upstream (RFC 8555 §7.3.6) — permanent and removes the local record (#278)
Fixed
- Certificate, SSH certificate, user certificate, and discovered-certificate lists now search the entire inventory (server-side) instead of only the current page (#280)
[2.208] - 2026-08-12
Added
- WSTEP: per-template pinned subject fields (C/ST/L/O/OU) — CSR/AD-supplied values overridden, CN/SAN stay dynamic (#274, contributed by @Hemsby)
- WSTEP: AD SID security extension (szOID_NTDS_CA_SECURITY_EXT) on Kerberos-bound issuance for KB5014754 strong certificate mapping (#275, contributed by @Hemsby)
Fixed
- Kerberos availability check now requires the gssapi backend, not just importable spnego (which ships transitively) — XCEP no longer advertises/attempts a broken Kerberos binding (#273, contributed by @Hemsby)
Full history: CHANGELOG.md
Installation
Docker (Recommended)
# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.210
# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.210
# Run
docker run -d -p 8443:8443 \
-e SECRET_KEY=$(openssl rand -hex 32) \
--name ucm neyslim/ultimate-ca-manager:2.210Debian/Ubuntu
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.210/ucm_2.210_all.deb
sudo dpkg -i ucm_2.210_all.deb
sudo apt-get install -fFedora/RHEL
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.210/ucm-2.210-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.210-1.fc43.noarch.rpmSilent/Automated Install
# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.210_all.debDefault Credentials
- Username:
admin - Password:
changeme123
Change the password immediately after first login!
Documentation
- Installation Guide
- API Documentation