Skip to content

v2.1.2

Latest

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 07 Oct 13:31
76fdd65

October 07, 2026

BREAKING CHANGES:

  • pki: ACME finalization with the default sign-verbatim directory policy now rejects CSRs that contain URI SANs, email SANs, or Other SANs. ACME challenges only verify DNS names and IP addresses; those SAN types are never validated and must not appear in issued certificates. Operators who require the previous behaviour can set default_directory_policy = "sign-verbatim-unsafe" in config/acme, accepting that the resulting certificates may contain unverified identity claims.

SECURITY:

  • core (enterprise): Prevent policy-name canonicalization bypasses in ACL parameter restrictions.
  • core/plugin: Fix plugin catalog entries restored from a raft snapshot, written through sys/raw, or replicated being able to run a binary outside plugin_directory.
  • core/policy: Harden request-time ACL construction to ignore malformed legacy policy references containing path-navigation segments (. or ..) so traversal-style names are never resolved or applied.
  • core: Fixed a bypass of exact-deny ACL policies where case-variant AppRole, AWS, Azure, GCP, Kubernetes, SCEP, or TPM role names, GitHub team or user policy mapping keys, certificate or CRL names, ACL/RGP/EGP policy names, or userpass usernames could evade the deny and be resolved by the backend to the same protected resource. Okta group names, LDAP and RADIUS names on mounts left in their default case-insensitive configuration, and Enterprise SCIM client names (identity/scim/client/<name>, where a case-variant write overwrites the existing client) are not covered by this fix and remain subject to the same bypass; avoid combining a wildcard allow with an exact deny on those mounts and paths.

CHANGES:

  • core/plugin: Plugin catalog entries are now checked against plugin_directory whenever they are used, not only at registration. An entry whose command resolves outside the directory, including through a symlink, is refused with plugin command is outside of configured plugin directory, and mounts that use it are skipped at startup while keeping their data. Such plugins must be registered again with their binary inside plugin_directory.
  • core/policy: Vault now validates policy names with segment-aware checks. Empty names and names containing . or .. path segments are rejected for new policy writes and assignments, while names containing / and \ remain supported. During request-time ACL construction, legacy traversal-style policy references are not applied (treated as invalid and unresolved), which can reduce effective token permissions. Operators should audit and rename affected policies before upgrading.
  • core: ACL and Sentinel EGP rule paths targeting a specific AppRole, AWS, Azure, GCP, Kubernetes, SCEP, or TPM role, GitHub team or user policy mapping key, certificate or CRL name, ACL/RGP/EGP policy name, or userpass username are now matched against the lowercased resource name, since these backends resolve those names case-insensitively. A rule written with a mixed-case resource name (for example auth/approle/role/MyRole) no longer matches requests for that resource and must be rewritten using the lowercase name (auth/approle/role/myrole). The lowercased form is also what Sentinel RGP and EGP policies observe as request.path, so policy rules that compare that value against a mixed-case path (for example request.path is "auth/approle/role/MyRole") must be updated as well. External auth and secret plugins are not affected by this normalization and continue to receive requests with their original casing. Existing deny rules using mixed-case resource names will fail open (become allow-all) after upgrade until rewritten with lowercase names.

IMPROVEMENTS:

  • auth/spiffe (enterprise): Add SPIFFE login cli handler.
  • secrets/pki: Add extra_subject_names_oids field to roles to allow specifying additional OID subject name components.

BUG FIXES:

  • auth/approle: Fix token_bound_cidrs validation when using /128 blocks for role and secret ID
  • ui: Fix regression where the client count billing configuration request omitted the root-namespace header, causing 404s on Monitoring > Client Count when viewed from a child namespace