📜 Recent release history (last 2 versions)
[2.235] - 2026-09-26
Fixed
- Creating a SCEP profile with a static challenge and Intune validation off failed with "requires an app registration"; it now saves (#374, reported by @CrazyManLabs, by @Hemsby).
[2.234] - 2026-09-25
Added
- The certificate list has a sortable Created column, the date the entry was added to UCM (#368).
- Whatever is created from the interface opens straight away instead of being left to find in a list: an issued, signed or approved certificate, a new CA, a CSR, a trust store entry, an SSH CA or certificate, and the single object of a Smart Import (#368).
- Settings › Security offers Encrypt remaining keys while private key encryption is enabled and some keys are still stored unencrypted, where the only way from the screen before was to disable encryption and enable it again (#367, by @stefanelul2000).
- Certificate templates take a subject Email, which Issue Certificate fills in when the template is chosen; like an Email typed in the form, it also becomes a SAN on email and combined certificates (#373, by @seanpdiaz).
Fixed
- Certificates stored by the ACME client kept their private key unencrypted while private key encryption was enabled. The key is now encrypted like every other, and keys stored before are encrypted with Encrypt remaining keys (#367, by @stefanelul2000).
- Disabling private key encryption decrypted only CA and certificate keys before removing the master key, which left SSH CA keys, deployment target keys, ACME account and EAB keys, SCEP challenges and LDAP bind passwords unreadable. Every secret under the master key is now decrypted first, with nothing changed if one fails, and the encryption status, Encrypt remaining keys and the startup check for a missing master key cover them all.
- ACME EAB HMAC keys and ACME account keys stored in settings travelled in a backup as the source installation's ciphertext, which the target cannot read. They are now exported in the clear, protected by the archive, and restored under the master key.
- Disabling private key encryption while the
KEY_ENCRYPTION_KEYenvironment variable is set decrypted the keys and reported success, then reloaded the variable's key and left encryption on. It is now refused, and Settings › Security no longer offers it when the key comes from that variable. - A PostgreSQL installation stopped starting once pip installed SQLAlchemy 2.1, which resolves a
postgresql://URL to the psycopg 3 driver UCM does not ship. A PostgreSQL URL without a driver now uses psycopg2, and SQLAlchemy is held below 2.1. - Saving any settings section erased the automatic backup password, which the screen never gets back and sent empty. A blank password now keeps the stored one, Settings › Backup shows whether one is set, and an API client clears it with
"clear_backup_password": true(#367, by @stefanelul2000). - Importing a template lost its subject fields, key usage and extended key usage, and a round-trip dropped the AD-derived subject, autoenrollment, allowed AD group and pinned subject fields. All of them now survive export and import, and Templates › Import also takes a file holding several templates (#369, #371, by @seanpdiaz).
Full history: CHANGELOG.md
Installation
Docker (Recommended)
# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.236-rc1
# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.236-rc1
# Run
docker run -d -p 8443:8443 \
-e SECRET_KEY=$(openssl rand -hex 32) \
--name ucm neyslim/ultimate-ca-manager:2.236-rc1Debian/Ubuntu
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.236-rc1/ucm_2.236.rc1_all.deb
sudo dpkg -i ucm_2.236.rc1_all.deb
sudo apt-get install -fFedora/RHEL
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.236-rc1/ucm-2.236.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.236.rc1-1.fc43.noarch.rpmSilent/Automated Install
# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.236.rc1_all.debDefault Credentials
- Username:
admin - Password:
changeme123
Change the password immediately after first login!
Documentation
- Installation Guide
- API Documentation