Skip to content

Release 18.1.6

Choose a tag to compare

@sk-keeper sk-keeper released this 26 Sep 02:46

Commander 18.1.6

This release adds new KeeperPAM proxy and import capabilities, strengthens Service Mode and enterprise permission checks, and includes several reliability fixes.

Highlights

  • Added KeeperRDP and KeeperSSH Proxy support for PAM tunnels, alongside KeeperDB Proxy. pam tunnel start --proxy selects the applicable proxy for the resource; --credential can override the linked credential for RDP/SSH proxy tunnels when the resource permits user-supplied credentials. Proxy-ready messages now appear when the tunnel is connected.

  • Added pam tunnel edit --keeper-proxy on|off|default to configure the applicable proxy for supported resource protocols. Improved tunnel discovery and cleanup across processes, proxy diagnostics, and handling of ephemeral JIT credentials.

  • Added Nested Shared Folder support to CyberArk PAM project imports (--nsf), including imported folders, records, rotation, and PAM configuration. Imports can also match an existing shared folder by UID.

  • Added HashiCorp Vault PAM configuration support through pam config new/edit --environment hashicorp, including Vault URL, token, namespace, mount path, and HashiCorp ID options.

Security and access controls

  • Service Mode now blocks access to its own configuration records and protects integration configuration records, including SailPoint configuration. App-setup commands are restricted to their respective allowlists, and variable expansion can no longer bypass the SailPoint command guard.

  • Delegated administrators cannot grant or revoke sensitive enterprise privileges that they do not hold. PAM gateway creation and removal now enforce the allow_pam_gateway policy, including through legacy commands.

  • Sensitive typed-record values are masked in record-add and record-update debug and Service Mode API logs.

Fixes and improvements

  • Fixed stale-revision errors when editing PAM rotation by refreshing the cache first, and restored the gateway name in pam rotation info.
  • Fixed Service Mode background operation and tunneling on Windows.
  • Fixed truncated application_info and account_info fields in JSON/CSV output from epm approval list.
  • Fixed an incorrect “Supported columns” warning for base fields in enterprise-info.
  • Improved enterprise root-node rename and display-name handling, including root-node visibility.
  • Added an optional path-aware mode for keeper-dag edges so edges on different paths are not inadvertently deactivated.

Full changelog: v18.1.5...18.1.6 (v18.1.5...v18.1.6)