1.5.53
Released 27 September 2026
New
-
The health check of an IIS or Windows target now tests whether the host can run a deployment. It reports what is missing — an administrator account, Full Language PowerShell, the IIS management module, a writable temp directory, an accessible certificate store — each with the command that fixes it.
-
Health-check results show warnings, one row per target. Conditions that do not stop a deployment, such as a stopped IIS service or a lowered WinRM message-size limit, are listed under the target instead of being hidden.
-
A Cloudflare target can take over a certificate uploaded outside CertAutoPilot, or be uploaded alongside it. The target, or a single distribution, chooses between updating that certificate in place (no gap), uploading next to it, or stopping as before — once every node is upgraded, since an older node ignores the choice.
-
An IIS target can refuse to bind a certificate to a binding it does not serve. With the new opt-in "Verify binding names" setting, a binding whose host header is not covered by the certificate, or whose current certificate shares no name with the new one, is skipped or refuses the run, and a distribution can switch the check on or off for its own certificate.
-
A refused IIS binding does not roll its neighbours back. A target the binding-name check refused imported and bound nothing, so it no longer counts towards auto-rollback of the distribution's other targets.
-
A Cloudflare upload alongside happens once. Every renewal updates that same certificate, unless the target is later set to take another certificate over.
Improved
-
A failed Windows deployment now names the layer that refused it. The message says whether nothing listens on the port, TLS is set against the wrong WinRM port, the listener's certificate is not trusted, the name does not resolve, or a web site answers instead of WinRM — and what to change.
-
A rejected login now explains itself. The message quotes the authentication methods the Windows host offered and lists the checks in the order that resolves them, including how to read the host's Security log.
-
Kerberos failures are translated. The domain controller's verdict — wrong password, unknown account, wrong realm, clock skew, a missing service principal, an unreachable controller — is reported in plain words with the fix.
-
An account that is only in "Remote Management Users" is now told so. The message names the group and the command that adds the account to the local Administrators group.
-
A distribution-failure notification now says why. The default email, Slack or Teams message carries the first failed target's error; a customised template can add the new failed-detail field.
-
Taking over a Cloudflare certificate that served more names than the new one is flagged. The run and the dry run name the names that would lose it, and the dry run says which certificate will serve each shared name.
-
Health checks of IIS and Windows targets run side by side. Up to five hosts are checked at once, so a larger module no longer runs out of time halfway.
-
A Cloudflare target moved to another zone says what it left behind. The run and the dry run name the certificate in the previous zone, which is no longer updated, so it can be deleted there.
-
An IIS deployment that binds nothing no longer leaves its certificate in the Windows store. The binding is chosen before the import, so a missing or ambiguous binding — or a run where every binding is already current — imports nothing.
Changed behaviour
The health check asks the host more questions than before, so a target that used to come back healthy can now come back unhealthy with a list of what is missing. The deployments that would have failed on those hosts were failing before, just later and with a less useful message.
A first Cloudflare upload is refused when another certificate already serves one of its names. Unless the target, or the distribution, is set to take that certificate over or upload alongside it, the run fails and names the overlapping names; a certificate CertAutoPilot already deploys is still updated, with a warning.
Saving a distribution's overrides is refused while a Cloudflare certificate id sits on its Default row. An id there reached every target of the module, so it must move to the target's own row; until then the saved id keeps working.
-
A refused credential is no longer retried. A rejected password, an account the host will not authorize and a missing host prerequisite now fail at once, so a deployment with a wrong password can no longer lock the account out.
-
An IIS, Windows or Exchange target with an impossible address is refused when saved — a URL or path in the hostname, or TLS switched on against port 5985 (or off against 5986), is rejected with the field to fix. An existing target is only checked when its hostname, port or TLS setting is changed.
-
A port written into the hostname moves into the port field. A new target, or an existing one whose address is edited, stores the port separately; an existing target whose address is left alone keeps it as it was.
-
A Cloudflare certificate id that no longer exists fails instead of being ignored. It is still followed when the takeover's first update gave the certificate a new id, and on targets last deployed before this release.
-
A Cloudflare zone holding more than 500 custom certificates in one state is no longer deployed to unchecked. A first upload, or finding a certificate whose id was lost, is refused because the whole zone cannot be checked for overlapping names; updating a known certificate goes ahead with a warning.
-
Windows PowerShell 2 now fails the health check. It cannot run the file transfer; PowerShell 3 and 4 are reported as a warning.
-
A Windows message-size limit is reported as such. A transfer the host refused for its size looked like a rejected password or a corrupted upload; it now names the limit and the command that restores the default.
-
A credential that stops working in the middle of a Windows deployment is reported as one. An account locked or disabled mid-run, or a domain controller that stopped answering, is an authentication failure — with the message-size limit named as the thing to check if it only ever happens on the upload.
-
Windows deployments after a rolling upgrade. A target saved with a port in its hostname is locked per host from this release on; while workers on the previous release and this one run side by side they do not share that lock, so finish the upgrade before deploying to such a target.
-
DNS resolvers are checked when saved. Settings → General refuses a malformed resolver entry (an empty port, a bracketed IPv6 address without one) and more than 16 entries instead of accepting a value that would break every automated DNS-01 issuance and cleanup; an entry saved before this check must be corrected before General settings can be saved again.
-
An IIS override with a port sweep or host-header list needs at least one entry. Such a row used to save as a single-binding placement when its list was empty; the distribution dialog now refuses to save it until a port or host header is added, or the row is switched back to Single binding, and the placement preview waits for the first entry.
-
IIS binding-name check and international host names. A host header with non-ASCII characters is compared the way Windows itself maps it (for example
straßeasstrasse), so the check agrees with what the binding actually serves.
Fixed
-
The certificate detail page listed at most 20 keys. A certificate that rotates its key on every renewal showed "Keys (20)" next to a longer certificate history; the Keys tab now lists every retained key.
-
A Cloudflare certificate that had just finished activating could slip past the overlap check. For a couple of seconds after activation Cloudflare lists such a certificate only under its explicit "active" filter; that listing is now read too, so a first upload racing that window is refused or warned like any other overlap.
-
A Cloudflare zone id that does not exist was reported as a rejected API token. It is now reported as a zone that was not found.
-
A Cloudflare takeover whose first run lost its record failed on every renewal because the pinned certificate could not be found, although it was in the zone under the new id Cloudflare had given it. That upload is now recognised and updated in place; a pin to an id that never existed still fails.
-
A Cloudflare overlap in the other direction went unreported. When another certificate names a host exactly and CertAutoPilot's certificate covers it only with a wildcard, Cloudflare keeps serving that host from the other certificate; the run now says so (a warning, not a refusal) instead of claiming the host.
-
Switching a new target's type kept a credential of the wrong kind selected (an AWS access key on an Azure Key Vault target), which then failed at save. The credential is cleared when the new type does not accept it.
-
An Exchange certificate found in the store without its private key did not count as observed drift, so an operator-requested service restart was skipped on the redeploy. It now counts, and the restart runs.
-
A wrong password during a deployment was reported as a file-transfer problem and retried. It is now an authentication failure and not retried.
-
Two Windows targets deployed at the same moment could use each other's authentication settings. Each deployment now carries its own.
-
A failure returned by the Windows host sometimes showed an internal message identifier instead of the explanation the host had sent with it.
-
DNS Resolvers set in Settings were ignored when a DNS provider looked up its zone on the default renewal path, on record cleanup (including the leftover records of a deleted certificate) and in the credential test, so a broken server DNS failed renewals with "could not find zone". They are now used there too; an empty list changes nothing.
-
A Windows server whose system path lost the PowerShell folder refused every operation with "'powershell' is not recognized", including the site picker. CertAutoPilot now starts PowerShell by its full path.
-
A Windows command that printed nothing for about 20 seconds lost its output. A slow ActionSet, import or restart could report success without its result, or fail; it now waits for the command, including on Windows installed in another language.
-
An untrusted WinRM listener certificate was retried as a network error. IIS and Windows targets now report it as an authentication failure and do not retry it, since only trusting the certificate, addressing the host by its name or skipping verification fixes it.
-
The health check of slow hosts timed out in the browser after 30 seconds, hiding each target's result. The browser now waits up to about two minutes, as long as the check itself may take.
-
An application-pool recycle or old-certificate cleanup whose result could not be read counted as a success. The deployment now carries a warning that the outcome is unknown.
-
Two targets pointing at the same Windows server could deploy at the same time when one had the port written into its hostname. They now share one lock; upgrade every node before deploying to such a target.
-
On a Windows server running in another language, some refusals were not recognised. They are now identified from Windows' own language-independent codes.
-
A domain controller that could not be reached was treated as a rejected login on Exchange targets and never retried. It is now retried; a refusal from the controller stays permanent.
-
A Cloudflare certificate that was still being provisioned was invisible, so a quick re-run could upload a second copy. It is now found, and one Cloudflare is about to delete is no longer reused.
-
The hint for a Cloudflare zone that cannot take another certificate only mentioned the plan. It now also covers a zone whose allowance is used up.
-
A Cloudflare upload whose result was not recorded was refused on the next run as if another certificate owned the names. The next run now recognises its own certificate.
-
An IIS site that does not exist was reported as a missing binding when the target updates several bindings. The deployment now says the site is missing.
-
A distribution-failure notification could name a target that had succeeded on retry. It now reports each target's final outcome.
-
An SSH deployment to a host that stopped answering was never retried. The target now fails as a connection problem and is retried; a job an operator cancels is no longer retried.
-
The Exchange health check and dry run listed Edge Transport servers. They are now left out, like the deployment itself does, so the dry run no longer warns that they will be skipped.
-
A DER download was recorded in the audit log as carrying no private key. It is now marked as including one, like the PEM, PFX and JKS formats.
-
Approving several requests in quick succession sent one notification. Every approval, rejection and execution now sends its own.