Skip to main content

1.5.54

Released 3 October 2026

New​

  • Release checksums are signed. Every release now publishes a detached signature of its checksums file, made with the CertAutoPilot release key, so a download can be verified against the published key before it is installed.

  • The reset-password command takes the new password on standard input. user reset-password --password-stdin reads the password from the first line of input instead of the command line, where other local accounts could read it from the process list.

  • IIS placement combines sites, IPs, ports and host headers. A target or a distribution's override can now pick one site, a list of sites or every site (with exclusions), and narrow it by IP addresses, ports and host headers — for example every site on port 443, or two sites on one IP. Targets saved with the earlier modes keep deploying the same bindings and open in the new form.

  • A deployed but not-yet-confirmed distribution is shown as Unverified and re-checked automatically. When every target deployed but the certificate check right after it failed, the distribution reads unverified instead of partial, and five minutes later the check alone runs again — nothing is deployed or restarted twice — ending in success or partial.

  • IIS deploys several servers at once. A new Parallel Windows Hosts setting (Settings → General, default 8) lets an IIS distribution work on that many servers at the same time; sites on the same server still update one after another.

Improved​

  • Windows errors read as a short headline with a checklist. Health-check results, the distribution list and the DNS credential page show an IIS, Exchange or WinRM failure as its error code, one line on what happened and the things to check as a list, instead of one long paragraph; the windows that show them fit small screens.

  • The Helm chart takes extra backend environment variables. Values set under extraEnv (for example a WinRM kill switch) survive helm upgrade, unlike a kubectl set env.

  • The certificate check waits for a service that was just restarted. After an IIS application pool recycle, an Exchange service restart or a post-deploy action, the check waits 30 seconds and then tries six times, ten seconds apart, unless the endpoint sets its own retries — the usual reason an Exchange run with several servers used to end partial.

  • Health checks answer before the proxy gives up and show each target's time. A module health check now finishes within 100 seconds instead of two minutes, gives each Windows target its own time limit, shows how long every target took, and lists a target it had no time left for as not checked instead of failing the whole check.

  • Exchange handles each server within its own time limit. Each server gets its own share of the run; one the run no longer has time for is reported not attempted (time budget) instead of being cut off halfway, a server that could not be reached at all is tried once more, and the job log shows how long each server's deployment and service restart took.

  • Windows deploys make fewer round trips. IIS, Exchange and generic WinRM deploys now run all of a target's commands in one remote shell instead of opening and closing a shell for every command, which shortens deploys over slow links.

  • Exchange dry runs check several targets at once and report per-target times, like IIS and WinRM.

  • An IIS deploy that runs out of time says where. The error names the step that did not finish, how long it ran and which limit ended it.

  • Re-running an IIS deploy that already bound the certificate skips the upload. One quick check replaces the certificate upload and the binding step when every selected binding already carries the certificate.

  • Large fan-outs fit their time limit. IIS and Exchange fan-out batches are made smaller when they would not finish within the execution timeout, and a run without fan-out warns in its log when its targets may not fit.

  • The Exchange server picker, the IIS preview over several sites and the Windows DNS credential test get more time. They now have 90, 100 and 90 seconds instead of timing out after about half a minute.

  • A request that was refused before it ran is recorded under its real action. A signed-in user's request stopped by a role check or a rate limit used to leave a raw POST /api/v1/… line in the audit log, with no resource and coloured like a success. It is now recorded under the route's own action name, with the resource it targeted and why it was refused (denied or rate limited), and it shows in red.

  • Failed requests read as failures wherever the audit log goes. Syslog (RFC 5424, CEF and LEEF), the CSV export and the audit page all treat an entry that ended in an error as a failure, whatever its action name — a rate-limited "Distribution Executed" executed nothing. The JSON export adds the readable action name to entries older releases stored under a raw route; the stored entries themselves are never rewritten.

  • Testing a discovery DNS provider is recorded under its own action name. The audit entry names the provider it tested, like the other credential tests.

  • Dry runs over several Windows servers finish as fast as the slowest one. IIS and WinRM dry runs now check different servers side by side instead of one after another, and a slow server is reported as timed out on its own row while every other server still returns its plan. Every dry run, whatever the module, is now cut off after 100 seconds (it was two minutes).

  • An IIS or WinRM dry run shows where its time went. Each target lists how long it took and, on hover, each remote step — so a slow server can be told apart from a slow check.

  • An IIS pre-flight makes two round trips instead of five. The binding discovery runs inside the pre-flight itself, the pre-flight script deletes its own temporary file, and temporary files are created already restricted to the connecting account instead of being restricted by a separate step afterwards.

  • The IIS binding preview in a distribution's overrides judges this certificate. Preview affected bindings now marks bindings that already carry the certificate as already current and, with the binding name check on, bindings the certificate does not serve — the same verdicts as Dry Run.

  • A WinRM dry run says when it could not check the destination paths. The paths are still listed, with a note that they carry no create or overwrite verdict.

  • The dry-run summary says what happened. It reads All checks passed or Some checks failed, and a dry run the browser stopped waiting for shows Dry run did not answer in time instead of a generic error.

  • Issuer names read the same on every screen. The 47-day readiness page now says Microsoft AD CS and Imported where it printed MSCA and IMPORTED.

Changed behaviour​

  • The Free plan allows one distribution target. Without a licence, a second target cannot be created (Add Target and Clone are disabled with an explanation); deleting the target frees the slot for a new one. Existing targets keep deploying, and Settings → License shows target usage next to certificate usage.

  • A run whose only problem is the certificate check no longer reports a failure straight away. Its job completes and the Distribution Failed notification is sent by the automatic re-check five minutes later, if the check still fails then.

  • IIS distributions update up to eight servers at the same time by default. Set Parallel Windows Hosts (Settings → General) to 1 to keep updating one server after another.

  • An IIS override's placement mode is now checked. An override that sends a placement mode other than the new filtered selection is refused instead of being silently ignored.

  • A WinRM connection timeout now limits only the connection itself. Once a Windows host has accepted the connection, CertAutoPilot waits at least 60 seconds for each answer, and a timeout message says whether the host could not be reached at all or was reachable but too slow.

  • Re-saving an IIS host-header list takes every binding with a listed header. A target or override saved with the earlier modes opens as a filtered selection and is saved as one; a host-header list then takes every binding carrying a listed header, not only the first one. This differs only when one header is bound on several IPs or ports, and the binding preview shows it before you save.

  • ACME accounts and AD CS connections share one Settings page. Settings → Certificate Authorities has a tab for each; the old ACME Accounts and MSCA Connections addresses redirect to the matching tab, and the edit forms keep their own pages.

  • Revoking an AD CS or imported certificate through the API answers 422. The refusal now carries the code ISSUER_UNSUPPORTED_OPERATION with the issuer and a message, where it used to be a plain 400; the Revoke button was already hidden for these certificates.

  • IIS deploys get more time per server by default. Without an explicit per-host timeout a server now gets five command timeouts plus 30 seconds (330 seconds by default, was 270), so validation and the app-pool recycle still fit after a slow upload.

  • IIS refuses to write a temporary file it cannot restrict. The certificate bundle, its password and staged scripts are created readable only by the connecting account, SYSTEM and Administrators; when that cannot be done — a leftover file it cannot remove, or permissions it cannot set — the transfer fails with IIS_HOST_PREREQ instead of going ahead with the folder's permissions.

  • "Allow Partial Propagation" now checks the record on every DNS-01 path. For RFC 2136, Cloudflare, DigitalOcean, OVH and Plesk — and for every provider with phased propagation turned off — the setting skipped the check entirely instead of accepting one agreeing resolver. It now waits until at least one configured DNS resolver returns the record, as it always did on the phased flow.

  • The IIS binding preview refuses a name check it cannot perform. With the binding name check on and a certificate that carries no DNS name, Preview affected bindings answers IIS_NAME_MISMATCH before contacting the server, as a deploy would.

  • The Helm chart checks frontend.backendUrl. It must be a plain http(s) address — the chart refuses to render one with quotes, spaces or a query — and its scheme, host and port are what the UI's new content security policy allows the browser to call.

warning
Helm: check frontend.backendUrl before upgrading

A value earlier charts accepted — a query string, quotes, spaces, or a host name with an underscore — now stops helm upgrade with the chart's own message. Set it to a plain https://host[:port][/path] address (or leave it empty) first.

Free plan: one distribution target

An installation without a licence that already has more than one target keeps using all of them, but cannot create another target until enough have been deleted to get below the limit of one, or a licence is installed.

Mixed versions and downgrades

Upgrade every API node before approving requests: an AD CS issuance request approved on a 1.5.53 node is processed as ACME and fails. Before going back to 1.5.53, approve or cancel open AD CS approval requests; a certificate policy saved on 1.5.54 with AD CS connection ids cannot be saved again on 1.5.53 until those ids are removed. Two certificates for the same RFC 2136 name wait for each other only when both run on upgraded nodes. While 1.5.53 nodes still restart, an AD CS approval request can again be cleaned up at its deadline instead of a week later; this stops once every node runs 1.5.54.

A node older than 1.5.54 does not know the new IIS placement. A target saved in the new form stops there with "no site to deploy to", but an override in the new form on a target still in an earlier mode is read only in part or ignored, so that node may update other bindings than the ones selected. Upgrade every node before saving an IIS target or override in the new form, and before going back to 1.5.53 re-save those in one of the earlier modes.

A 1.5.53 scheduler does not know the unverified status and may deploy such a distribution again at its next sweep, or record a different result for one that once ran in fan-out batches; the automatic re-check runs only on upgraded nodes. After going back to 1.5.53, a distribution left unverified keeps that status until it is run again — run it once to settle it.

Allow Partial Propagation and internal-only zones

With "Allow Partial Propagation" on, an RFC 2136, Cloudflare, DigitalOcean, OVH or Plesk issuance (or any issuance with phased propagation turned off) now waits until one of the configured DNS resolvers sees the record. A zone visible only on your internal network needs internal resolvers in DNS Resolvers (or Skip Propagation Pre-check turned on), or issuance times out waiting for propagation.

Existing standalone clusters: add the firewall rule by hand

An upgrade does not change firewall rules. On a cluster of four or more nodes with firewalld or ufw active, allow MongoDB's port (27017) from every cluster node on each database node.

Fixed​

  • NetScaler appliances whose management address offers only older TLS 1.2 ciphers can be reached again. CertAutoPilot now also offers the TLS 1.2 RSA ciphers these appliances use, and the post-deploy certificate check can read virtual servers limited to them; a failed negotiation now says so plainly.

  • Editing a PAN-OS target is saved. Changing a PAN-OS target's host or IP, port, vsys, certificate name, commit setting or timeouts was accepted but not stored, so the next deploy still used the old values.

  • An approved AD CS request now issues through AD CS. An issuance request for a Microsoft AD CS connection that went through the approval workflow was validated and queued as if it were an ACME request; it now runs the same checks and the same job as a direct AD CS issuance, including the AD CS preflight warnings and their confirmation step.

  • A re-issued certificate returns to auto-renewal. Re-issuing a certificate in renewal failed left its renewal attempt counter at the maximum, which silently kept it out of every later renewal sweep.

  • Approving a request can no longer exceed the certificate limit. The limit was checked only when a request was created, so several requests could be approved against the same free slot; execution now re-checks it, and a request refused there moves its certificate to rejected so it can be deleted and requested again.

  • Renewing an AD CS certificate that is waiting for CA-manager approval no longer sends a second request to the CA. The renewal is reported as already in progress until the pending request is approved or denied.

  • Certificate policies accept the ids of ACME accounts and AD CS connections in Allowed issuer IDs. Those ids were refused as "invalid issuer ID", which made the rule impossible to use.

  • A domain with non-ASCII characters matches its zone whichever spelling is used. A name given in punycode is now recognised as belonging to a zone registered under its Unicode name, and the other way round.

  • A search term containing a NUL character no longer fails every paginated list with a server error.

  • Error details in notification e-mails keep their line breaks. A multi-line error, such as a Windows checklist, used to arrive as one run-on line.

  • The standalone backup no longer puts the database password on the command line. On a single-node install it was visible to other local accounts in the process list while the backup ran; it now goes through a file only the backup can read, as it already did on clusters.

  • Linking a certificate to a module it is already linked to answers with a clear message. It used to be refused with a raw database error; it now says the link already exists and asks you to edit that distribution instead.

  • An AD CS request that reaches its approval deadline is always resolved. The workflow record could be deleted by the database at the very moment its last check was due, leaving the certificate "waiting for CA-manager approval" for good; it is now kept a week past the deadline, and the last check at the deadline asks the CA once more, so an approval granted at the last minute is stored instead of expiring.

  • A DNS-01 issuance, or an AD CS request that waited for CA-manager approval, completes when interrupted right after its certificate was stored. The challenge records used to stay in DNS, with no audit entry or notification and a bulk renewal counting it as failed; the next run now finishes those steps. No issuance stores the same certificate version twice any more.

  • An AD CS request approved at its deadline no longer loops when its certificate cannot be stored. The request now ends as expired instead of being picked up again and again.

  • Retrying an approved request after a queue error works. A certificate could be left pending with no job and every retry refused; it now goes back to awaiting approval, or the retry starts the missing job. A retry is refused when the certificate has already run an issuance, so an approval is never carried out twice.

  • Requests whose handler crashed, or whose client disconnected, are audited. Both used to leave no audit entry for a change that had been made.

  • The audit log no longer shows the name of another project's resource. A refused request addressing a resource of a different project displayed that resource's name in the requesting project's log.

  • The dry-run result stays responsive with many large plans. Plans page at 20 rows, targets after the first ten expand on demand, and targets the dry run had no time left to check are listed in a warning at the top.

  • A dry run no longer fails in the browser after 30 seconds. The page gave up on a dry run after 30 seconds while the server kept checking for up to two minutes, so a dry run over several or slow Windows servers intermittently showed a timeout instead of its result. The page now waits for the server's answer, and the same applies to the machine-wide IIS binding preview.

  • An IIS dry-run error is one readable line. A refused placement used to show the temporary script's path and PowerShell's position markers; it now shows the error code and its message, as the binding preview does. A target that answered but failed its check is shown as Check failed (IIS used to call it Unreachable) and counts as failed in the summary, in every module.

  • An IIS dry run over every site lists up to 500 bindings, like the preview. It stopped at 200 while the preview showed up to 500, so the two lists disagreed on large servers; a final row now says how many more bindings exist.

  • The override drawer says when the preview and Dry Run are looking at different things. The binding preview follows unsaved edits while Dry Run uses the saved overrides; the drawer now shows Unsaved changes while they differ.

  • Two certificates for the same name no longer break each other's RFC 2136 validation. Adding a challenge record over RFC 2136 replaces every record at that name, so certificates such as example.com and *.example.com renewing at the same time could delete each other's record mid-validation. The second one now waits until the first has finished.

  • Standalone clusters of four or more nodes can reach the database behind a host firewall. With firewalld or ufw active, the installer opened MongoDB's port only between the three database nodes, so the application on the fourth node and beyond could not connect. It now opens it to every cluster node.

  • The web UI is served with the full set of security headers. The pages and scripts of the UI now carry the HTTPS-enforcement, anti-framing, anti-sniffing and referrer headers, a content security policy and a permissions policy, and the web server no longer announces its version.

Existing standalone installs keep their web server settings

An upgrade never touches the web server configuration, and re-running the installer keeps a working one, placing the new version next to it. To pick up the header fix on an install made before 1.5.54, copy the security-header lines from that new version into yours, or remove yours and re-run the installer. Docker, Helm and the CertAutoPilot OS appliance apply it on upgrade by themselves.