github NeySlim/ultimate-ca-manager v2.236

4 hours ago

What's Changed

Added

  • A new CA can last 1, 2 or 3 years, or any number of days up to 50 years, where the form offered only 5, 10, 15 or 20 years. The API takes validityDays alongside validityYears (#378).
  • The ACME server takes a default certificate profile, applied to orders whose client requests none, which is what most clients do. Those orders were always issued for 90 days whatever the profiles said (#378).
  • Renewing a certificate asks for the validity of the new one, prefilled with the current duration, where it could only repeat the original duration. Issuance policies and the CA's expiry still cap it, and a renewal queued for approval keeps the chosen duration (#378).

Changed

  • Upgrade note: an installation that set REDIS_URL or UCM_REDIS_URL now really uses Redis, so its sessions move there and users sign in again; check that the URL points to a running Redis, as sign-in fails otherwise, or remove the variable.
  • When a Redis URL is set, WebSocket events also go through Redis, in preparation for a high-availability mode; installations sharing a Redis server stay apart by database number.
  • The DEB and RPM packages and the Docker image now include the redis Python package, which a Redis URL needs to take effect.

Fixed

  • An ACME order whose profile was withdrawn before finalize is refused with invalidProfile instead of being issued with the historical defaults.
  • The certificate picker filtered keyless certificates out of each page in the browser, so pages came up short and the count was wrong.
  • Ukrainian counts of 2 or more showed an English label or a wrong form in about twenty places.
  • Signing a CSR under an approval policy, alone or in bulk, now reports a duration shortened by policy to the requester and the approver.
  • An SMTP server on port 465 (implicit TLS) timed out, because the interface could only turn on STARTTLS. Settings › Email now offers None, STARTTLS or SSL/TLS (#377, reported by @lengqing5977).
  • The route applying a certificate to HTTPS accepted a revoked or expired one, which only the picker kept out; it now refuses them.
  • Applying or regenerating the HTTPS certificate failed with a server error when the key file existed without the certificate file, and a renewal rebinding it did not back that key up.
  • Settings › HTTPS did not offer certificates with less than 30 days left, which excluded every short-lived certificate; they are now listed (#378, reported by @lengqing5977).
  • With auto-renewal on, a certificate about as long as the renewal window (27 or 30 days against the default 30) was re-signed on every pass from the day it was issued. Renewal now never starts before the last third of a certificate's lifetime (#378).
  • UCM_REDIS_URL, the variable the Redis guide and the Docker Compose overlay set, was never read, so Redis stayed unused. It is now read along with REDIS_URL.
  • The readiness probe answered 503 when a Redis URL was set without the redis Python package installed; the Redis check is now reported as skipped.
  • The Docker image health check and the example compose files assumed port 8443, so a container with another UCM_HTTPS_PORT was reported unhealthy or unreachable. Both now follow UCM_HTTPS_PORT (#377).

Removed

  • The Maximum validity field of certificate templates: nothing stored it, so it read 3650 again after every save. A maximum is set on an issuance policy, which caps both issuance and renewal (#378).
  • Upgrade note: the Docker variables UCM_SMTP_*, UCM_ACME_*, UCM_CACHE_*, UCM_MTLS_*, UCM_DEFAULT_*, UCM_SESSION_TIMEOUT and UCM_JWT_EXPIRATION had no effect and are gone from the documentation and compose files; these settings live in the web interface (#377, reported by @lengqing5977).
  • The docker-compose.redis.yml overlay: UCM runs as a single instance, where Redis brings nothing. The Redis guide now says what Redis is kept for.
  • WebSocket connections authenticated by an API key in the handshake, and the reauth event that renewed them: no client used them, and the browser connects with its session.
  • The /api/v2/settings/ldap routes, which the interface never called: they returned fixed values, saved settings nothing read, and tested a connection to any server given. LDAP is configured and tested on SSO providers.

📜 Recent release history (last 2 versions)

[2.235] - 2026-09-26

Fixed

  • Creating a SCEP profile with a static challenge and Intune validation off failed with "requires an app registration"; it now saves (#374, reported by @CrazyManLabs, by @Hemsby).

[2.234] - 2026-09-25

Added

  • The certificate list has a sortable Created column, the date the entry was added to UCM (#368).
  • Whatever is created from the interface opens straight away instead of being left to find in a list: an issued, signed or approved certificate, a new CA, a CSR, a trust store entry, an SSH CA or certificate, and the single object of a Smart Import (#368).
  • Settings › Security offers Encrypt remaining keys while private key encryption is enabled and some keys are still stored unencrypted, where the only way from the screen before was to disable encryption and enable it again (#367, by @stefanelul2000).
  • Certificate templates take a subject Email, which Issue Certificate fills in when the template is chosen; like an Email typed in the form, it also becomes a SAN on email and combined certificates (#373, by @seanpdiaz).

Fixed

  • Certificates stored by the ACME client kept their private key unencrypted while private key encryption was enabled. The key is now encrypted like every other, and keys stored before are encrypted with Encrypt remaining keys (#367, by @stefanelul2000).
  • Disabling private key encryption decrypted only CA and certificate keys before removing the master key, which left SSH CA keys, deployment target keys, ACME account and EAB keys, SCEP challenges and LDAP bind passwords unreadable. Every secret under the master key is now decrypted first, with nothing changed if one fails, and the encryption status, Encrypt remaining keys and the startup check for a missing master key cover them all.
  • ACME EAB HMAC keys and ACME account keys stored in settings travelled in a backup as the source installation's ciphertext, which the target cannot read. They are now exported in the clear, protected by the archive, and restored under the master key.
  • Disabling private key encryption while the KEY_ENCRYPTION_KEY environment variable is set decrypted the keys and reported success, then reloaded the variable's key and left encryption on. It is now refused, and Settings › Security no longer offers it when the key comes from that variable.
  • A PostgreSQL installation stopped starting once pip installed SQLAlchemy 2.1, which resolves a postgresql:// URL to the psycopg 3 driver UCM does not ship. A PostgreSQL URL without a driver now uses psycopg2, and SQLAlchemy is held below 2.1.
  • Saving any settings section erased the automatic backup password, which the screen never gets back and sent empty. A blank password now keeps the stored one, Settings › Backup shows whether one is set, and an API client clears it with "clear_backup_password": true (#367, by @stefanelul2000).
  • Importing a template lost its subject fields, key usage and extended key usage, and a round-trip dropped the AD-derived subject, autoenrollment, allowed AD group and pinned subject fields. All of them now survive export and import, and Templates › Import also takes a file holding several templates (#369, #371, by @seanpdiaz).

Full history: CHANGELOG.md


Installation

Docker (Recommended)

# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.236

# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.236

# Run
docker run -d -p 8443:8443 \
  -e SECRET_KEY=$(openssl rand -hex 32) \
  --name ucm neyslim/ultimate-ca-manager:2.236

Debian/Ubuntu

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.236/ucm_2.236_all.deb
sudo dpkg -i ucm_2.236_all.deb
sudo apt-get install -f

Fedora/RHEL

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.236/ucm-2.236-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.236-1.fc43.noarch.rpm

Silent/Automated Install

# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.236_all.deb

Default Credentials

  • Username: admin
  • Password: changeme123

Change the password immediately after first login!

Documentation

Don't miss a new ultimate-ca-manager release

NewReleases is sending notifications on new releases.