📜 Recent release history (last 2 versions)
[2.236] - 2026-10-08
Added
- A new CA can last 1, 2 or 3 years, or any number of days up to 50 years, where the form offered only 5, 10, 15 or 20 years. The API takes
validityDaysalongsidevalidityYears(#378). - The ACME server takes a default certificate profile, applied to orders whose client requests none, which is what most clients do. Those orders were always issued for 90 days whatever the profiles said (#378).
- Renewing a certificate asks for the validity of the new one, prefilled with the current duration, where it could only repeat the original duration. Issuance policies and the CA's expiry still cap it, and a renewal queued for approval keeps the chosen duration (#378).
Changed
- Upgrade note: an installation that set
REDIS_URLorUCM_REDIS_URLnow really uses Redis, so its sessions move there and users sign in again; check that the URL points to a running Redis, as sign-in fails otherwise, or remove the variable. - When a Redis URL is set, WebSocket events also go through Redis, in preparation for a high-availability mode; installations sharing a Redis server stay apart by database number.
- The DEB and RPM packages and the Docker image now include the
redisPython package, which a Redis URL needs to take effect.
Fixed
- An ACME order whose profile was withdrawn before finalize is refused with
invalidProfileinstead of being issued with the historical defaults. - The certificate picker filtered keyless certificates out of each page in the browser, so pages came up short and the count was wrong.
- Ukrainian counts of 2 or more showed an English label or a wrong form in about twenty places.
- Signing a CSR under an approval policy, alone or in bulk, now reports a duration shortened by policy to the requester and the approver.
- An SMTP server on port 465 (implicit TLS) timed out, because the interface could only turn on STARTTLS. Settings › Email now offers None, STARTTLS or SSL/TLS (#377, reported by @lengqing5977).
- The route applying a certificate to HTTPS accepted a revoked or expired one, which only the picker kept out; it now refuses them.
- Applying or regenerating the HTTPS certificate failed with a server error when the key file existed without the certificate file, and a renewal rebinding it did not back that key up.
- Settings › HTTPS did not offer certificates with less than 30 days left, which excluded every short-lived certificate; they are now listed (#378, reported by @lengqing5977).
- With auto-renewal on, a certificate about as long as the renewal window (27 or 30 days against the default 30) was re-signed on every pass from the day it was issued. Renewal now never starts before the last third of a certificate's lifetime (#378).
UCM_REDIS_URL, the variable the Redis guide and the Docker Compose overlay set, was never read, so Redis stayed unused. It is now read along withREDIS_URL.- The readiness probe answered 503 when a Redis URL was set without the
redisPython package installed; the Redis check is now reported as skipped. - The Docker image health check and the example compose files assumed port 8443, so a container with another
UCM_HTTPS_PORTwas reported unhealthy or unreachable. Both now followUCM_HTTPS_PORT(#377).
Removed
- The Maximum validity field of certificate templates: nothing stored it, so it read 3650 again after every save. A maximum is set on an issuance policy, which caps both issuance and renewal (#378).
- Upgrade note: the Docker variables
UCM_SMTP_*,UCM_ACME_*,UCM_CACHE_*,UCM_MTLS_*,UCM_DEFAULT_*,UCM_SESSION_TIMEOUTandUCM_JWT_EXPIRATIONhad no effect and are gone from the documentation and compose files; these settings live in the web interface (#377, reported by @lengqing5977). - The
docker-compose.redis.ymloverlay: UCM runs as a single instance, where Redis brings nothing. The Redis guide now says what Redis is kept for. - WebSocket connections authenticated by an API key in the handshake, and the
reauthevent that renewed them: no client used them, and the browser connects with its session. - The
/api/v2/settings/ldaproutes, which the interface never called: they returned fixed values, saved settings nothing read, and tested a connection to any server given. LDAP is configured and tested on SSO providers.
[2.235] - 2026-09-26
Fixed
- Creating a SCEP profile with a static challenge and Intune validation off failed with "requires an app registration"; it now saves (#374, reported by @CrazyManLabs, by @Hemsby).
Full history: CHANGELOG.md
Installation
Docker (Recommended)
# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.237-rc1
# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.237-rc1
# Run
docker run -d -p 8443:8443 \
-e SECRET_KEY=$(openssl rand -hex 32) \
--name ucm neyslim/ultimate-ca-manager:2.237-rc1Debian/Ubuntu
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.237-rc1/ucm_2.237.rc1_all.deb
sudo dpkg -i ucm_2.237.rc1_all.deb
sudo apt-get install -fFedora/RHEL
wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.237-rc1/ucm-2.237.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.237.rc1-1.fc43.noarch.rpmSilent/Automated Install
# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.237.rc1_all.debDefault Credentials
- Username:
admin - Password:
changeme123
Change the password immediately after first login!
Documentation
- Installation Guide
- API Documentation