github NeySlim/ultimate-ca-manager v2.237-rc1

latest release: v2.237-rc2
pre-release3 hours ago
📜 Recent release history (last 2 versions)

[2.236] - 2026-10-08

Added

  • A new CA can last 1, 2 or 3 years, or any number of days up to 50 years, where the form offered only 5, 10, 15 or 20 years. The API takes validityDays alongside validityYears (#378).
  • The ACME server takes a default certificate profile, applied to orders whose client requests none, which is what most clients do. Those orders were always issued for 90 days whatever the profiles said (#378).
  • Renewing a certificate asks for the validity of the new one, prefilled with the current duration, where it could only repeat the original duration. Issuance policies and the CA's expiry still cap it, and a renewal queued for approval keeps the chosen duration (#378).

Changed

  • Upgrade note: an installation that set REDIS_URL or UCM_REDIS_URL now really uses Redis, so its sessions move there and users sign in again; check that the URL points to a running Redis, as sign-in fails otherwise, or remove the variable.
  • When a Redis URL is set, WebSocket events also go through Redis, in preparation for a high-availability mode; installations sharing a Redis server stay apart by database number.
  • The DEB and RPM packages and the Docker image now include the redis Python package, which a Redis URL needs to take effect.

Fixed

  • An ACME order whose profile was withdrawn before finalize is refused with invalidProfile instead of being issued with the historical defaults.
  • The certificate picker filtered keyless certificates out of each page in the browser, so pages came up short and the count was wrong.
  • Ukrainian counts of 2 or more showed an English label or a wrong form in about twenty places.
  • Signing a CSR under an approval policy, alone or in bulk, now reports a duration shortened by policy to the requester and the approver.
  • An SMTP server on port 465 (implicit TLS) timed out, because the interface could only turn on STARTTLS. Settings › Email now offers None, STARTTLS or SSL/TLS (#377, reported by @lengqing5977).
  • The route applying a certificate to HTTPS accepted a revoked or expired one, which only the picker kept out; it now refuses them.
  • Applying or regenerating the HTTPS certificate failed with a server error when the key file existed without the certificate file, and a renewal rebinding it did not back that key up.
  • Settings › HTTPS did not offer certificates with less than 30 days left, which excluded every short-lived certificate; they are now listed (#378, reported by @lengqing5977).
  • With auto-renewal on, a certificate about as long as the renewal window (27 or 30 days against the default 30) was re-signed on every pass from the day it was issued. Renewal now never starts before the last third of a certificate's lifetime (#378).
  • UCM_REDIS_URL, the variable the Redis guide and the Docker Compose overlay set, was never read, so Redis stayed unused. It is now read along with REDIS_URL.
  • The readiness probe answered 503 when a Redis URL was set without the redis Python package installed; the Redis check is now reported as skipped.
  • The Docker image health check and the example compose files assumed port 8443, so a container with another UCM_HTTPS_PORT was reported unhealthy or unreachable. Both now follow UCM_HTTPS_PORT (#377).

Removed

  • The Maximum validity field of certificate templates: nothing stored it, so it read 3650 again after every save. A maximum is set on an issuance policy, which caps both issuance and renewal (#378).
  • Upgrade note: the Docker variables UCM_SMTP_*, UCM_ACME_*, UCM_CACHE_*, UCM_MTLS_*, UCM_DEFAULT_*, UCM_SESSION_TIMEOUT and UCM_JWT_EXPIRATION had no effect and are gone from the documentation and compose files; these settings live in the web interface (#377, reported by @lengqing5977).
  • The docker-compose.redis.yml overlay: UCM runs as a single instance, where Redis brings nothing. The Redis guide now says what Redis is kept for.
  • WebSocket connections authenticated by an API key in the handshake, and the reauth event that renewed them: no client used them, and the browser connects with its session.
  • The /api/v2/settings/ldap routes, which the interface never called: they returned fixed values, saved settings nothing read, and tested a connection to any server given. LDAP is configured and tested on SSO providers.

[2.235] - 2026-09-26

Fixed

  • Creating a SCEP profile with a static challenge and Intune validation off failed with "requires an app registration"; it now saves (#374, reported by @CrazyManLabs, by @Hemsby).

Full history: CHANGELOG.md


Installation

Docker (Recommended)

# From Docker Hub
docker pull neyslim/ultimate-ca-manager:2.237-rc1

# Or from GitHub Container Registry
docker pull ghcr.io/neyslim/ultimate-ca-manager:2.237-rc1

# Run
docker run -d -p 8443:8443 \
  -e SECRET_KEY=$(openssl rand -hex 32) \
  --name ucm neyslim/ultimate-ca-manager:2.237-rc1

Debian/Ubuntu

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.237-rc1/ucm_2.237.rc1_all.deb
sudo dpkg -i ucm_2.237.rc1_all.deb
sudo apt-get install -f

Fedora/RHEL

wget https://github.com/NeySlim/ultimate-ca-manager/releases/download/v2.237-rc1/ucm-2.237.rc1-1.fc43.noarch.rpm
sudo dnf install ./ucm-2.237.rc1-1.fc43.noarch.rpm

Silent/Automated Install

# Skip firewall prompts for CI/automation
sudo UCM_PORT=8443 UCM_FIREWALL=no dpkg -i ucm_2.237.rc1_all.deb

Default Credentials

  • Username: admin
  • Password: changeme123

Change the password immediately after first login!

Documentation

Don't miss a new ultimate-ca-manager release

NewReleases is sending notifications on new releases.