Skip to content

Releases: metril/certforge

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 16:43
54e271c

0.9.0 (2026-10-10)

⚠ BREAKING CHANGES

  • agent: carry the WebSocket in a signed upgrade and a sealed channel
  • agent: enrol with a token proof and administrator approval
  • api: require signed, sealed requests on every agent route

Features

  • agentca: issue a 24h responder signing certificate renewed by Reload (3ec83d6)
  • agent: carry the WebSocket in a signed upgrade and a sealed channel (83fd4bc)
  • agent: choose the TLS roots by transport mode and drop client-certificate TLS (5b6a02c)
  • agent: enrol with a token proof and administrator approval (5186fa7)
  • agentproto: add HPKE, session AEAD and HTTP message signature primitives (5cc08a7)
  • agents: authenticate by client id and serial, verify agent certificates (603fe98)
  • agent: sign and seal REST over an ephemeral-key session (f579faf)
  • api: require signed, sealed requests on every agent route (6ac6c5e)
  • web: approve or reject agent enrolments (b880e0e)

Bug Fixes

  • agentproto: session-owned seq with replay protection, raw r||s signatures, responder EKU (60c927a)
  • agentproto: sign refusals only after verification and cover Cf-Error (78e2079)
  • agent: rate limit signed REST per client instead of per address; retry 429/503 with backoff (bbe3ef7)
  • agent: retry a busy handshake and a failed reconcile with backoff (61b774d)
  • api: rate limit and session-check secure agent routes, share one nonce cache, cap it, accept listener-name authorities (fbbc684)
  • db: derive enrollment_tokens.lookup_id on insert so pre-upgrade backups restore (d87c8f7)
  • keep the approval dialog open across refetches, poll past token expiry, lock the pending cap, scope request lookup by org (721a8c3)
  • web: name the Clients nav link via aria-label so the badge adds no stray space (b5704d0)
  • web: reword retire CA consequence; reject {#id} anchors in help test (0e40cf7)

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 04:56
a5cf09d

0.8.0 (2026-10-10)

Features

  • challenge: support DNS-over-HTTPS resolvers for propagation checks (8cf0d78)
  • issuance: DNS credential test verifies the TXT record is visible (b577ab2)
  • issuance: hint at DNS interception and negative caching on propagation failure (c803a59)

Bug Fixes

  • challenge: refuse DoH redirects and treat failure rcodes as errors (cc042b7)
  • challenge: wait 20s before querying configured resolvers (c531af7)
  • DNS-01 propagation checks behind DNS-intercepting networks (8b07451)
  • shorten resolver help copy and satisfy lint (4b97209)

v0.7.3

Choose a tag to compare

@github-actions github-actions released this 09 Oct 09:25
a2f085b

0.7.3 (2026-10-09)

Bug Fixes

  • challenge: validate host-composing credential fields for f5xc (3757222)
  • issuance: re-check revoked key inside the success transaction (b85f803)
  • review round 5 (backup compatibility, sweep and revoke races, f5xc host, web tooltips) (eb07b83)
  • web: saved views clear the list's other filters on apply (42f7495)
  • web: tooltips on icon-only close and remove buttons (8f7c170)

v0.7.2

Choose a tag to compare

@github-actions github-actions released this 09 Oct 08:44
7a28bfb

0.7.2 (2026-10-09)

Bug Fixes

  • db: use an SQL comment in StaleServerDeployments so sqlc generates it (21c7f05)
  • deploy,issuance: sweep failed rows every 6h; revoked-key check outside the tx (9383729)
  • deploy: confine vault-kv mount to a single segment for non-global writers (96e5d9f)
  • review round 4 (deploy sweep, revoked key, vault-kv mount, web) (e892fcd)
  • web: keep disabled IconButton one stable aria-disabled element (570da76)
  • web: let optional schema pickers be cleared (a215aae)
  • web: make Combobox non-clearable by default, opt in for optional pickers (9ed696a)
  • web: refresh certificate and attempts after revoking a version (bc7f188)

v0.7.1

Choose a tag to compare

@github-actions github-actions released this 09 Oct 08:11
6223916

0.7.1 (2026-10-09)

Bug Fixes

  • agents: read CA and material through the open transaction and bound OnVersion (c851946)
  • api: require keys:export to re-enrol a client holding key-bearing grants (4dd3f88)
  • backup: include ca_crls in the backup manifest (8d5295d)
  • challenge: keep legacy rfc2136 and oraclecloud field names after lego bump (adcb741)
  • crl: persist signed CRLs and re-sign only on revocation or near expiry (e984191)
  • crl: take a fresh crl_number for every signed CRL (806ac8c)
  • db: make ca_crls foreign key deferrable (3f785bd)
  • deploy: per-row deploy_seq so a re-armed server deployment is not dropped or overwritten by a stale job (866e724)
  • dnscreds: allow only AZURE_AUTH_METHOD=env for non-admins and force it on build (159a460)
  • dnscreds: restrict ambient cloud identity to global settings:write (ab17286)
  • issuance: never reuse a private key shared with a revoked version (44d3c89)
  • issuance: record vault revocation and renewal trigger atomically (0e2959b)
  • issuance: renew a managed certificate immediately when its current version is revoked (dcb9e6d)
  • monitor: scale expiring threshold to short-lived leaf lifetime (3e83e6c)
  • notify: record a delivery as failed when its send never runs on the final attempt (b5b9f8c)
  • review round 3 (Go, security, certificates, web) (a829cbe)
  • web: add IconButton so every icon-only button has a tooltip (d6e2e51)
  • web: Enter on a DataTable row falls back to onRowClick (492e82c)
  • web: keep download sheet open after a generated-password export (e3ea881)
  • web: single tooltip for disabled row Delete; clear download notice on password change (177bb8a)

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 05:38
b89940a

0.7.0 (2026-10-04)

Features

  • api: certificate overview summary endpoints per org and across orgs (52c76d0)
  • audit: HMAC-signed head anchor detects tail truncation (e7ecda5)
  • auth: optional setup token, API key maximum lifetime and per-user cap, clear response when setup commits but sign-in fails (869d6ff)
  • backup: audit a failed on-demand backup (236c9ae)
  • cfctl: warn on stderr when the bearer token would go over cleartext http (b00b7c4)
  • db: prune old issuance attempts and hook runs, with supporting indexes (ca680e6)
  • monitor: go unreachable only after two consecutive failed checks (80c9cde)
  • notify: retry deliveries with capped exponential backoff over about five hours (74e789e)
  • notify: signed timestamp and V2 webhook signature alongside the existing one (cdbae80)
  • sites: show how many clients a site delete detaches (196d40e)
  • web: default the audit range to 30 days while searching; keep a populated list on a failed refresh (0d58b99)
  • web: setup token field in the wizard and API key policy in the create sheet (d16105a)

Bug Fixes

  • acme: clamp Retry-After to 24h and guard duration overflow (03cbe06)
  • acme: report a cancelled context when the CA reply races the cancellation (c05d1b4)
  • acme: wrap the underlying error alongside the cancellation (da57f5d)
  • agent: answer ACME challenges while a reconcile is running (5cee4d4)
  • agent: create new parent directories 0755 again, keep the stale temp sweep (966636f)
  • agent: guard agent state shared between heartbeats, renewals and reconciles (b81b1c2)
  • agenthub: bound each OnMessage call well under the idle timeout (7e0d59c)
  • agent: install a grant's files all-or-nothing and tolerate hooks without a command (7282970)
  • agent: let an in-flight reconcile finish when the session drops (f93b1d8)
  • agent: private parent dirs for secret files and sweep stale temp siblings (cfa805a)
  • agent: raise the agent websocket read limit to 8 MiB (8eb536c)
  • agent: reject a non-https agent URL at enrolment and identity load (dd2becf)
  • agents: a failed settings reload serves the stale value for a full TTL (964250c)
  • agents: consume the enrolment token before loading CA material (ff67fc9)
  • api: apply the SSRF URL policy to DNS credential URL fields (8019c94)
  • api: apply the URL policy to an ACME CA directoryUrl (94df9fc)
  • api: block org delete on channels and monitors; audit and warn about clients detached by a site delete (99a6f44)
  • api: cache the readyz database ping and KEK canary for a few seconds (c059205)
  • api: cap agent REST bodies at agentproto.MaxMessage (db4eb24)
  • api: check the CRL issuer serial before unsealing and bound the CRL cache (195b7e8)
  • api: document 400 on the attempts list now that it takes a query parameter (98a3ce8)
  • api: extend the import read deadline only after authentication and authorization (6393b1a)
  • api: extend the read deadline for the certificate import upload (2f54141)
  • api: fixed detail for an unrecorded vault revocation, no database text (d1cc9fd)
  • api: grandfather a vault-kv target's path only while its mount is unchanged too (8363046)
  • api: hide the Vault settings address from principals without settings write (e058ecd)
  • api: leave imported off a failed import preview (12e1a4f)
  • api: make the overview needs_look flag NULL-safe and sort urgent rows before manual-DNS extras (727a4d5)
  • api: raise the agent websocket read limit to 8 MiB (ebaa7a7)
  • api: refuse deleting a certificate that a monitor expects, and show the reason in the bulk delete toast (77a97da)
  • api: report the certificates created before an import failed (540c54e)
  • api: require keys:export for agent grants that deliver a private key (26e9f31)
  • api: require keys:export to make an in-use layout key-bearing (2ff38d1)
  • api: return the signer's safe detail in the CA 502 and log the wrapped error (7c06dc7)
  • api: show the Vault address in key status only to settings writers (410f2aa)
  • api: withhold other users' OIDC details from callers without global users:read (1146299)
  • audit: bind the anchor bootstrap to the chain with an anchor_initialized event (45514a0)
  • auth: audit only the first rate-limited hit per client per window; rate-limit OIDC start and setup (dac3791)
  • auth: cap argon2 parameters read from a stored hash and rehash on login when they differ (442d7f3)
  • authn: require https for OIDC issuers outside loopback (b657dc4)
  • auth: password rehash on login is a compare-and-swap so it cannot undo a concurrent reset (8adb2d4)
  • backup: fsync scheduled archives and their directory, and prune orphaned tmp files (495df11)
  • backup: keep a corrupt chunk during a table load reported as tampering (ae17411)
  • backup: report a restore into a populated database as an audit conflict, not tampering (c95e6fd)
  • backup: spool each table to a private temp file instead of buf...
Read more

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 13:14
1bd93cf

0.6.0 (2026-10-02)

Features

  • run backups without the key copy confirmation and show key status only when needed (47d9348)

Bug Fixes

  • web: do not suggest removing the old key before re-encryption has finished (ad2e977)
  • web: events table overflow, shorter labels, and plain encryption key wording (99566a4)
  • web: keep backup actions inside the status card (7facc90)
  • web: keep the events table within its container with long channel names (86784d5)
  • web: rename the Backup and keys settings section to Backups (4f967a4)
  • web: say encryption key and re-encrypt instead of KEK and rewrap (2c7b3b3)
  • web: shorten the events severity filter to All, Warning+ and Critical (055514c)

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 05:54
edc926b

0.5.0 (2026-10-02)

Features

  • web: collapse flow lanes and groups (c5316ac)
  • web: darken the dark theme and add sidebar and raised surfaces (407f8d9)
  • web: darker theme, contained sections, and reworked Events, Flow and defaults (559f339)
  • web: filter the flow map by name and problems (ad3a07c)
  • web: frame sections in cards on a darker canvas (89e0e0c)
  • web: make Global the base layer of issuance defaults (592434a)
  • web: move list filters into a labelled toolbar under the tabs (0df1ba7)
  • web: pick the defaults scope with a segmented control and an organization picker (e6912e1)
  • web: rebuild the events page as a filterable table (74762de)

Bug Fixes

  • web: associate filter labels with their controls and allow clearing on mobile (5f30b25)
  • web: keep flow filtering fast and collapsed groups keyboard reachable (61db069)
  • web: keep the events table from scrolling sideways at medium widths (abd8dc3)
  • web: never pin shipped defaults on save and correct unknown organization links (d25b331)
  • web: show an unset propagation wait as the DNS provider's own timeout (9020189)
  • web: show unset defaults as a short state with a tooltip (19f0223)
  • web: stop the ACME accounts table scrolling sideways (6bfb393)

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 03:11
e16361c

0.4.0 (2026-10-02)

Features

  • api: add GET /orgs/{orgId}/flow contract (1d45609)
  • api: build the org flow map from existing stores (12fcbf4)
  • api: say something true in Flow node statuses (71b896d)
  • api: serve the built-in issuance defaults from the effective endpoint (9da7923)
  • web: add control border, field and selected tokens (b1c75d5)
  • web: add Flow system-map page with path highlighting (32c5f39)
  • web: add PageHeader tabs and filters, PrimaryCell and FormSection (e79ef8a)
  • web: clarify server defaults with a level chain and Global-first tab (abe5d65)
  • web: confirm before navigating away from a dirty form sheet (bd6c0bb)
  • web: declutter alerts pages and move filters to the tab line (30112d6)
  • web: declutter certificates and clients lists (190faa0)
  • web: declutter delivery lists; shorten merged help copy and fix type errors (71c7336)
  • web: declutter issuers pages and move the CA filter to the tab line (67a96c1)
  • web: give inputs, buttons, tabs and segments visible boundaries (fea8969)
  • web: group inheritable issuance fields into sections with Reset section (59e6d33)
  • web: guard form side panels against accidental close (4deffe1)
  • web: move optional sheet fields under a closed Advanced section (0a61baa)
  • web: regroup Overview into status row, needs attention and insights tabs (06e962f)
  • web: UI clarity pass and Flow system map (454df82)

Bug Fixes

  • api: keep pending deliveries and full issuer usage in Flow statuses (64e19a5)
  • api: per-certificate delivery edges and channel coverage flag on flow map (6bb7ffb)
  • web: do not show built-in defaults as unset while they are unknown (eeb7462)
  • web: draw default Flow connectors in the control-border colour so they read in the light theme (d07b461)
  • web: flow edge status follows the selected path; trace channels from delivery and client starts (e99d49f)
  • web: give ListInput the standard field background, hover and focus border (13e5733)
  • web: keep segmented option labels on one line and wrap the control onto extra rows (22bbdf3)
  • web: keep the page-title help icon out of the heading's accessible name (ec93d78)
  • web: restore Enabled switch, column help tooltips and full layout paths lost in the declutter (96aa3b6)
  • web: show one source badge per default field and move the chain into its popover (ad8e98e)
  • web: stop the channel type chip overflowing its column (133de0e)
  • web: stop untouched target and layout edits raising a discard prompt (d96d623)

Performance Improvements

  • api: count issuer use for the flow map with a narrow query (a0546db)

v0.3.1

Choose a tag to compare

@github-actions github-actions released this 01 Oct 23:12
821721d

0.3.1 (2026-10-01)

Bug Fixes

  • issuance: store and serve an empty attempt timeline as [] not null (352b580)
  • issuance: store and serve an empty attempt timeline as [] not null (ec5b9d8)