github NeySlim/ultimate-ca-manager v2.210-rc1

latest releases: v2.235, v2.235-rc1, v2.234...
pre-releaseone month ago
๐Ÿ“œ Recent release history (last 2 versions)

[2.209] - 2026-08-14

Added

  • SCEP profiles: Microsoft Intune challenge validation โ€” live per-device challenge validation against Intune's ScepActions API with Entra app registration, forced auto-approve, and success/failure notification before issuance (#228, contributed by @Hemsby)
  • ACME client accounts: import the private key of an existing account at creation (algorithm derived from the key) (#277)
  • ACME client accounts: deactivate an account upstream (RFC 8555 ยง7.3.6) โ€” permanent and removes the local record (#278)

Fixed

  • Certificate, SSH certificate, user certificate, and discovered-certificate lists now search the entire inventory (server-side) instead of only the current page (#280)

[2.208] - 2026-08-12

Added

  • WSTEP: per-template pinned subject fields (C/ST/L/O/OU) โ€” CSR/AD-supplied values overridden, CN/SAN stay dynamic (#274, contributed by @Hemsby)
  • WSTEP: AD SID security extension (szOID_NTDS_CA_SECURITY_EXT) on Kerberos-bound issuance for KB5014754 strong certificate mapping (#275, contributed by @Hemsby)

Fixed

  • Kerberos availability check now requires the gssapi backend, not just importable spnego (which ships transitively) โ€” XCEP no longer advertises/attempts a broken Kerberos binding (#273, contributed by @Hemsby)

Full history: CHANGELOG.md


Installation

Docker (Recommended)

# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.210-rc1

# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.210-rc1

# Run
docker run -d -p 8443:8443 \
  -e SECRET_KEY=$(openssl rand -hex 32) \
  --name ucm neyslim/ultimate-ca-manager:2.210-rc1

Debian/Ubuntu

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.210-rc1/ucm_2.210.rc1_all.deb
sudo dpkg -i ucm_2.210.rc1_all.deb
sudo apt-get install -f

Fedora/RHEL

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.210-rc1/ucm-2.210.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.210.rc1-1.fc43.noarch.rpm

Silent/Automated Install

# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.210.rc1_all.deb

Default Credentials

  • Username: admin
  • Password: changeme123

Change the password immediately after first login!

Documentation

Don't miss a new ultimate-ca-manager release

NewReleases is sending notifications on new releases.