Release Notes
What changed in each release, written for the people who run CertAutoPilot. Pick a version to read its full notes.
Versions
| Version | Released | In one line |
|---|---|---|
| 1.5.55 Latest | 4 Oct 2026 | IIS override drawer: “Several sites” keeps its picks again, and the IP / port / host-header pickers list every site a selection covers; a typed site name with spaces stays one site; credential pickers show a saved credential’s name instead of its id |
| 1.5.54 | 3 Oct 2026 | IIS deploys several servers at once and picks bindings by site, IP, port and host header; a deployed-but-unconfirmed distribution is re-checked automatically instead of ending partial; Windows errors read as a checklist; the Free plan allows one distribution target; refused requests appear in the audit log under their real action; an approved AD CS request issues through AD CS; release checksums are signed |
| 1.5.53 | 27 Sep 2026 | Windows deployments say which layer refused them and how to fix it — port, TLS, DNS, credential, Kerberos or a host prerequisite — and the health check now tests whether the host can actually run a deployment; a Cloudflare target can take over, or sit alongside, a certificate uploaded outside CertAutoPilot |
| 1.5.52 | 22 Sep 2026 | Discovery flags names answered with a fallback certificate; a retried issuance no longer shows the previous attempt's error |
| 1.5.51 | 21 Sep 2026 | Security hardening round: deactivated accounts lose their sessions, kubeconfig credentials cannot run programs on the server, private keys over SSH default to 0600, exports are formula-safe and audited, failed logins and token refreshes appear in the audit log, policies apply to approval-gated requests; the Helm chart installs with its defaults |
| 1.5.50 | 16 Sep 2026 | Cloudflare-proxied records discovered at both the edge and the origin; Cloudflare, AWS ACM, PAN-OS and Exchange pickers; failed first issuances are labelled; a review of all seventeen distribution modules fixes idempotency, error classification and save-time validation in each |
| 1.5.49 | 8 Sep 2026 | Pick IIS sites and bindings (and Kubernetes namespaces, Secrets and workloads, Vault mounts and secret paths, Azure Key Vault certificates) from the live target, with a preview of exactly which bindings a deployment would update; zero-config Kerberos (no krb5.conf anywhere, Kerberos on IIS too); Palo Alto PAN-OS firewalls as a distribution target; SSH targets can refuse a changed host key |
| 1.5.48 | 31 Aug 2026 | One-command multi-node install with a built-in MongoDB replica set; multi-profile F5 targets; Discovery tab fix |
| 1.5.47 | 25 Aug 2026 | Revocation monitoring for retained versions; IP grouping, paginated source certificates and safer scans in Discovery |
| 1.5.46 | 23 Aug 2026 | cPanel / WHM becomes the sixteenth distribution target; see where discovery has spotted a managed certificate, with IP-grouped endpoint detail |
| 1.5.45 | 21 Aug 2026 | Discovery auto-recognizes certificates issued here; licensing simplified to two tiers with every feature in both; transient security findings no longer flap; audit-chain verification fixed |
| 1.5.44 | 19 Aug 2026 | Generic webhook notification channel with signed JSON event envelopes; cleaner names throughout the interface |
| 1.5.43 | 17 Aug 2026 | A distribution credential can live in your own secret manager and is read from there on every use |
| 1.5.42 | 15 Aug 2026 | Approval extends to the deployment supply chain; discovery gains schedules and a time budget; private-CA certificates can be revoked |
| 1.5.40 | 12 Aug 2026 | One uniform rollback across every module, with a version picker and per-version revocation |
| 1.5.39 | 9 Aug 2026 | Azure Key Vault becomes the fifteenth distribution target, with its own credential type and built-in troubleshooting |
| 1.5.38 | 7 Aug 2026 | Bring your own certificate — import one issued elsewhere and manage it like any other |
The entry marked Latest is the current release; an entry marked In development is not released yet and its page is still being written. If you are running an older version, read the Changed behaviour section of every page between yours and it before you upgrade.
How to read a release page
Every version page uses the same four sections, in the same order:
| Section | What it covers |
|---|---|
| New | Capabilities that did not exist before — a new target type, a new setting, a new screen. |
| Improved | Something you already used that now works better, faster or more clearly. |
| Changed behaviour | The section to read before upgrading. Something the product used to do one way and now does another: a new default, a stricter check, a different response, an action that is now blocked or newly allowed. |
| Fixed | A problem you could have run into, described by the symptom you would have seen. |
Anything that could interrupt an existing workflow is called out in a highlighted box on the version page itself.
Finding your version
The version you are running is shown at the top left of the web interface, next to the CertAutoPilot logo. An upgrade moves you through every intermediate version, so if you are several releases behind, read the Changed behaviour section of each page between your version and the one you are moving to.
Related
- Roadmap — what is planned but not yet built
- Deployment — how to install and upgrade an installation