Skip to main content

1.5.48

Released 31 Aug 2026

New​

  • One command installs a multi-node cluster with a built-in database replica set. The standalone installer can now install every host from the first one over SSH, forming a three-member replica set with shared credentials minted and distributed automatically. The application stays available through the loss of any single node, and single-node installs are unchanged.

  • One F5 BIG-IP target can manage several client-ssl profiles. The target, and the per-distribution override, now take a list of profile names instead of a single one, and every renewal repoints each of them. Profiles are handled independently — one that does not exist on the device is logged and skipped, and a failure on one never blocks the rest.

  • See your database deployment at a glance. The Cluster page now shows whether the database is a standalone instance or a replica set, with a column marking which machine currently accepts writes. A new command prints the same view in a terminal and exits non-zero when the set has no writable primary.

  • The installer handles brand-new Linux releases. On kernels where the default database version refuses to start it now selects a newer one automatically, and when a distribution is too new to have a matching database repository it falls back to the newest compatible one instead of failing.

  • Enterprise Linux clusters install cleanly. Three-node installs now work on AlmaLinux and RHEL 9.

  • Rotating the encryption key is one command, from one machine. It shows what it is about to change and asks for confirmation, then creates the new key, distributes it to every node so it survives restarts, verifies each node loaded it, switches over and waits for the re-encryption to finish — with existing data readable throughout. Separate commands distribute a key without switching, and retire an old one everywhere once the system confirms nothing still needs it.

Improved​

  • You can now see how much data still depends on each encryption key. The KEK Versions page and the status command gained a Records count beside "Loaded by", which counted only machines holding a key and never answered the question that matters before retiring one. Retiring is now also refused when data is sealed under a version no document advertises, or held in a form rotation cannot move forward, such as an open approval request.

  • Startup now warns when a key version's material is missing. Only the key in active use was checked before, so removing an older key from the secrets file by hand produced a perfectly healthy start while the records that still needed it quietly became unreadable. Every affected version is now named in the startup log.

Changed behaviour​

Upgrade every node before relying on syslog over TLS

The syslog TLS certificates move to a new storage location the moment the first upgraded node starts. A node still on the previous version cannot see them there: it reports no certificates and its own syslog forwarding over TLS fails until it too is upgraded. Nothing is lost and the move needs no action, but audit events that exhaust their retries on such a node during the window are abandoned — so upgrade the nodes close together, or turn syslog forwarding off for the duration.

  • Saving syslog settings is rejected if it would leave half a client certificate pair. The certificate and key are now checked against the state the save would produce rather than the submitted form alone. Replacing just one of the two is therefore allowed while the other stays as stored, and clearing only one of them is refused instead of being accepted and leaving an unusable configuration.

Fixed​

  • Two-factor secrets and the license record are now included in key rotation. Both were skipped silently — rotation reported success without touching them and the retirement check did not see them either, so retiring an old key could leave every enrolled 2FA login failing and an Enterprise install back on the free tier. Rotation now covers them, retirement refuses while any encrypted record is unaccounted for, and a repair command restores records written before this was tracked.

    If you rotated keys before upgrading

    Run the repair command and rotate once more before retiring any old key.

  • Retiring an encryption key can be undone. If data turns out to still need a version you already retired, it can be brought back into service so the data can be moved forward — previously the key material sat on disk unusable and the only way out was editing the database by hand. Records whose recorded key version disagrees with the data they hold are now detected, repaired, and refused for retirement until fixed.

  • A failed two-factor login now says when the cause is server-side. An unreadable stored secret was reported as a wrong code, which sent operators looking at clocks and authenticator apps instead of the encryption key.

  • Re-running the installer no longer restarts the database on the first node. The restart briefly interrupted writes while a new primary was elected, for a re-run that had nothing to change.

  • Saving syslog settings no longer corrupts the stored TLS certificates. Each save encrypted the stored certificates one more time while only one layer was ever removed on use, so after the first save mutual TLS stopped working. Affected material is repaired automatically on the first start after upgrading, and it now lives in its own record that key rotation can see — previously an old key could be retired while it was the only thing that could still read those certificates.

  • Changing an ACME account's external-account credentials now keeps the new account key. Re-registering with the CA produced a new key and registration but never stored them, so the account silently carried on using the superseded key. The renewed registration is now saved with the account.

  • Editing an ACME account is now serialised. Two people editing the same account at once could interleave and lose one of the changes; a second edit now returns "being modified concurrently, please retry" instead.

  • Editing one field of a stored credential can no longer blank the others. When the stored value could not be decrypted, the partial edit was saved as submitted — so changing only, say, an organisation id silently wiped the token that was never re-typed. The update is now refused, with the reason.

  • Deprecated-TLS badges no longer read backwards, and no longer claim an untested endpoint is clean. A red mark next to a version meant the server accepted it, which reads as the opposite; the badges now say "also 1.0" or "no legacy" in words. TLS 1.0/1.1 acceptance is measured once per host and the result is now shared with that host's other endpoints, so two rows of the same host can no longer disagree.

  • The discovery Endpoints table no longer squeezes every column. Host and server name collapsed to a single character because the table reserved less width than its own columns needed. Columns are sized properly, the header stays put while scrolling, and the empty state in "Accepted (weak)" now says "not scanned" instead of a dash that read as "clean".

  • The expand arrow on the certificate Discovery tab no longer sits on its own line. On a grouped endpoint row the arrow wrapped above the address; it now stays on the same line as the endpoint it expands.