Skip to main content

Release Notes

What changed in each release, written for the people who run CertAutoPilot. Pick a version to read its full notes.

Versions​

VersionReleasedIn one line
1.5.55
Latest
4 Oct 2026IIS override drawer: “Several sites” keeps its picks again, and the IP / port / host-header pickers list every site a selection covers; a typed site name with spaces stays one site; credential pickers show a saved credential’s name instead of its id
1.5.543 Oct 2026IIS deploys several servers at once and picks bindings by site, IP, port and host header; a deployed-but-unconfirmed distribution is re-checked automatically instead of ending partial; Windows errors read as a checklist; the Free plan allows one distribution target; refused requests appear in the audit log under their real action; an approved AD CS request issues through AD CS; release checksums are signed
1.5.5327 Sep 2026Windows deployments say which layer refused them and how to fix it — port, TLS, DNS, credential, Kerberos or a host prerequisite — and the health check now tests whether the host can actually run a deployment; a Cloudflare target can take over, or sit alongside, a certificate uploaded outside CertAutoPilot
1.5.5222 Sep 2026Discovery flags names answered with a fallback certificate; a retried issuance no longer shows the previous attempt's error
1.5.5121 Sep 2026Security hardening round: deactivated accounts lose their sessions, kubeconfig credentials cannot run programs on the server, private keys over SSH default to 0600, exports are formula-safe and audited, failed logins and token refreshes appear in the audit log, policies apply to approval-gated requests; the Helm chart installs with its defaults
1.5.5016 Sep 2026Cloudflare-proxied records discovered at both the edge and the origin; Cloudflare, AWS ACM, PAN-OS and Exchange pickers; failed first issuances are labelled; a review of all seventeen distribution modules fixes idempotency, error classification and save-time validation in each
1.5.498 Sep 2026Pick IIS sites and bindings (and Kubernetes namespaces, Secrets and workloads, Vault mounts and secret paths, Azure Key Vault certificates) from the live target, with a preview of exactly which bindings a deployment would update; zero-config Kerberos (no krb5.conf anywhere, Kerberos on IIS too); Palo Alto PAN-OS firewalls as a distribution target; SSH targets can refuse a changed host key
1.5.4831 Aug 2026One-command multi-node install with a built-in MongoDB replica set; multi-profile F5 targets; Discovery tab fix
1.5.4725 Aug 2026Revocation monitoring for retained versions; IP grouping, paginated source certificates and safer scans in Discovery
1.5.4623 Aug 2026cPanel / WHM becomes the sixteenth distribution target; see where discovery has spotted a managed certificate, with IP-grouped endpoint detail
1.5.4521 Aug 2026Discovery auto-recognizes certificates issued here; licensing simplified to two tiers with every feature in both; transient security findings no longer flap; audit-chain verification fixed
1.5.4419 Aug 2026Generic webhook notification channel with signed JSON event envelopes; cleaner names throughout the interface
1.5.4317 Aug 2026A distribution credential can live in your own secret manager and is read from there on every use
1.5.4215 Aug 2026Approval extends to the deployment supply chain; discovery gains schedules and a time budget; private-CA certificates can be revoked
1.5.4012 Aug 2026One uniform rollback across every module, with a version picker and per-version revocation
1.5.399 Aug 2026Azure Key Vault becomes the fifteenth distribution target, with its own credential type and built-in troubleshooting
1.5.387 Aug 2026Bring your own certificate — import one issued elsewhere and manage it like any other

The entry marked Latest is the current release; an entry marked In development is not released yet and its page is still being written. If you are running an older version, read the Changed behaviour section of every page between yours and it before you upgrade.

How to read a release page​

Every version page uses the same four sections, in the same order:

SectionWhat it covers
NewCapabilities that did not exist before — a new target type, a new setting, a new screen.
ImprovedSomething you already used that now works better, faster or more clearly.
Changed behaviourThe section to read before upgrading. Something the product used to do one way and now does another: a new default, a stricter check, a different response, an action that is now blocked or newly allowed.
FixedA problem you could have run into, described by the symptom you would have seen.

Anything that could interrupt an existing workflow is called out in a highlighted box on the version page itself.

Finding your version​

The version you are running is shown at the top left of the web interface, next to the CertAutoPilot logo. An upgrade moves you through every intermediate version, so if you are several releases behind, read the Changed behaviour section of each page between your version and the one you are moving to.

  • Roadmap — what is planned but not yet built
  • Deployment — how to install and upgrade an installation