What’s new?
Welcome to the Sectigo Certificate Manager (SCM) Enterprise release notes. This page highlights the most recent updates across SCM Enterprise and its connected integrations, covering the latest improvements, API updates, and resolved issues.
SCM v26.9
This release of SCM Enterprise includes the following updates and improvements:
General updates
| Change | Reference number |
|---|---|
There is now support for eIDAS QWAC and QWAC PSD2 SSL certificates. |
SCM-14220 |
Improved UI when adding large numbers of nodes during enrollment with orchestration gateway. |
SCM-14839 |
New certificate profile attribute to control if the existing CSR can be reused during renewal. |
SCM-14811 |
CA certificates imported along with the SSL certificate to Azure Key Vault are now explicitly ordered EE to root. |
SCM-15178 |
Improved rendering of certificate serial numbers when the serial number starts with a zero. |
SCM-14868 |
Improved handling of a large number of Azure subscriptions when showing Azure Key Vault enrollment wizard. |
SCM-15160 |
REST API Enhancements
| Change | Reference number |
|---|---|
SSL certificate enrollment REST API now allows auto-renew to be configured. |
SCM-15001 |
Resolved issues
| Issue | Reference number |
|---|---|
Viewing a scheduled report would show the scheduled time in local time instead of the originally selected timezone. |
SCM-14621 |
Assigning an SSL certificate to a department via API would fail to validate that the department had delegated access to the certificate’s domains. |
SCM-15171 |
| For earlier releases, see SCM Enterprise release notes. |
Orchestration gateway v2.0.1
This release includes the following updates and improvements:
General updates
| Change | Reference number |
|---|---|
Restored and improved functionality that allows orchestration gateway to install certificates to discovered nodes that do not already have them. This applies to both HTTP and HTTPS nodes. |
SCM-15115 |
Resolved issues
| Change | Reference number |
|---|---|
A hostname longer than 39 characters would cause discovery to fail in the Imperva integration. |
SCM-15161 |
| For earlier releases, see Orchestration gateway release notes. |
Network agent v5.6
This release includes the following general updates:
| Change | Reference number |
|---|---|
Improved handling of discovery of nodes when one agent is connected to large number of servers. |
SCM-14157 |
Improved handling of CSR generation if network issues interrupted initial request. |
SCM-13717 |
Improved rewriting Tomcat <Connector> to <SSLHostConfig> elements so that all deprecated attributes are dropped. |
SCM-14794 |
Upload of certificates to remove Linux targets from Windows agent would result in error 110. |
SCM-14153 |
When using the Docker-based Network Agent, logs to stdout would stop after the internal log file was rotated. |
SCM-14488 |
Added support for:
|
SCM-14312 |
Added support for F5 Big IP 17.5 and 21. |
SCM-14313 |
Updated third-party components to address the following vulnerabilities:
|
SCM-14662 |
| For earlier releases, see Network agent release notes. |
SCM v26.7
This release of SCM Enterprise includes the following updates and improvements:
General updates
| Change | Reference number |
|---|---|
SCM now supports network discovery tasks using a configured Sectigo Orchestration Gateway (v2.0). |
SCM-14475 |
SCM now supports adding and editing Sectigo Orchestration Gateway (v2.0) keystores and endpoints from the UI. |
SCM-14395 / SCM-14396 |
Improved filtering of Sectigo Orchestration Gateways and SSL/TLS automation endpoints. |
SCM-14383 / SCM-14384 |
New notification for offline Sectigo Orchestration Gateways. |
SCM-14386 |
REST API Enhancements
| Change | Reference number |
|---|---|
Sectigo Orchestration Gateways can be managed via the SCM Admin REST API. |
SCM-14461 |
Resolved issues
| Issue | Reference number |
|---|---|
Updating a certificate’s metadata via API would fail if the certificate’s initial term was no longer allowed in the certificate profile. |
SCM-14133 |
Inventory exceeded notifications might be sent when the usage exactly matched inventory. |
SCM-14620 |
SSL certificate reports created via API did not include the IP address column even when requested. |
SCM-13074 |
Assigning certificates from a bucket to an organization/department might not process all certificates if some certificates had been processed already. |
SCM-14434 |
| For earlier releases, see SCM Enterprise release notes. |
DNS connector v2.0
This release includes the following updates and improvements:
General updates
| Change | Reference number |
|---|---|
The DNS connector now supports LEGO DNS providers, including all providers available up to LEGO version 4.31.
These providers are bundled with the DNS connector and can be used with the |
SCM-13509 |
Resolved issues
| Change | Reference number |
|---|---|
Starting with DNS connector 1.3, created entries for Cloudflare, DNSimple, and OVH would not be deleted after validation was complete. |
SCM-14297 |
| For earlier releases, see DNS connector release notes. |
MS agent v4.4
This release includes the following updates and improvements:
General updates
| Change | Reference number |
|---|---|
The performance of the Certification Authority snap‑in has been enhanced, resulting in much faster loading and navigation of issued certificates in high‑volume deployments. |
SCM-13143 |
There is improved HTTP proxy compatibility by including the port number in the CONNECT request as well as the Host header. |
SCM-12270 |
Startup no longer converts CA private keys to non‑exportable by default; this can be enabled via the PrivateKeyNonExportable registry setting. |
SCM-13903 |
Resolved issues
| Change | Reference number |
|---|---|
Fixed a regression in MS Agent 4.3 that caused certificate requests to fail for Active Directory Certificate Templates requiring manual SAN entry. |
SCM-12534 |
Improved handling of network loss during initialization, which previously resulted in logging the error "The specified domain either does not exist or could not be contacted." |
SCM-12995 |
Fixed an issue where CA names containing spaces were parsed incorrectly, preventing the CA’s AD Configuration container from being located during discovery. |
SCM-13187 |
Resolved an issue where conflicting error codes caused incorrect permission‑related error messages to appear during enrollment. |
SCM-13380 |
Fixed an issue where startup without SCM connectivity caused the CA console to hide existing certificate templates and delete the assigned template list when attempting to add a new one. |
SCM-13922 |
| For earlier releases, see MS agent release notes. |
Network agent v5.5
This release includes the following general updates:
| Change | Reference number |
|---|---|
Improved script that collects IIS server information to operate on Windows desktop operating systems that don’t have required IIS features installed. |
SCM-12839 |
Resolved issue of installation of wildcard certificates to Apache servers from a Network Agent installed on Windows that would fail with an error saying “The filename, directory name, or volume label syntax is incorrect”. |
SCM-12874 |
| For earlier releases, see Network agent release notes. |
Private key agent v2.3
This release includes the following general updates:
| Change | Reference number |
|---|---|
On some systems, the agent would fail when generating CSR and key. |
SCM-9723 |
Improved performance when processing large numbers of key generation requests. |
SCM-11056 |
| For earlier releases, see Private key agent release notes. |
CA connector v3.5
This release includes the following resolved issues:
| Change | Reference number |
|---|---|
The Sectigo CA Connector 3.4 installer was reporting itself as 3.3. |
SCM-13345 |
Discovery of certificates in DigiCert found no certificates if the account contained a multiple of 20 certificates. |
SCM-13287 |
There was a missing space between review_requests and create_longer_validity_order when describing missing DigiCert API permissions. |
SCM-11284 |
| For earlier releases, see CA connector release notes. |