Skip to main content

1.5.52

Released 22 September 2026

Improved​

  • A retried issuance no longer shows the previous attempt's error. Once a later attempt gets past the DNS-record step and hands the order to the propagation check, the earlier attempt's red error is cleared instead of sitting next to "issuance pending" until the certificate is issued.

  • Discovery no longer records the server's fallback answer to names it made up. A name the deep-SNI crawler only tried because it appeared in a certificate on the address (the apex of a wildcard, a SAN), that DNS does not point at that address, and that the server answered with a certificate not covering it, is dropped instead of listed — example.com on the IP of app.example.com, answered with *.hosting-provider.net. A name DNS does point at the address, answered that way, is kept and tagged Name mismatch in every endpoint list (name_mismatch in the API, counted per address).

Changed behaviour​

Discovery counts drop on the first scan after upgrading

Rows earlier scans recorded for made-up names are deleted on the next scan, with no endpoint gone alert, so a source's name and certificate counts, its Scan History success count and the Certificates tab shrink. A certificate that was only ever seen through such names — typically a server's default certificate on a hostname source — leaves the inventory with the next cleanup and any open finding on it resolves automatically; nothing on the server changed. A resolver outage during a scan never removes anything: names DNS did not answer for are kept and flagged.