What’s new?

Welcome to the Sectigo Certificate Manager (SCM) Enterprise release notes. This page highlights the most recent updates across SCM Enterprise and its connected integrations, covering the latest improvements, API updates, and resolved issues.

Orchestration gateway v2.0

This release includes the following updates and improvements:

General updates

Change Reference number

New endpoints added to orchestration gateway:

  • Windows Certificate Store

  • F5 Distributed Cloud (XC)

SCM-13785 / SCM-14250

Proxy support added to external credential stores.

SCM-14258

New ability to configure an orchestration gateway to perform network discovery tasks in SCM.

SCM-14475

Add and edit orchestration gateway keystores and endpoints from the SCM UI.

SCM-14395 / SCM-14396

Implemented support of orchestration gateway cloud discovery.

SCM-14263

Added Cloudflare WAF support.

SCM-14382

Resolved issues

Change Reference number

Citrix install would fail when intermediate certificate already existed under a different certkey name.

SCM-14817

Orchestration gateway would rewrite Tomcat from legacy SSL model to modern model but preserved deprecated SSL attributes.

SCM-14841

Discovery error when using Apache server.

SCM-14732

Failure to update certificate profile when using Citrix Netscaler.

SCM-14761

Node information for orchestration gateway would show incorrect certificate path.

SCM-14823

For earlier releases, see Orchestration gateway release notes.

SCM v26.7

This release of SCM Enterprise includes the following updates and improvements:

General updates

Change Reference number

SCM now supports network discovery tasks using a configured Sectigo Orchestration Gateway (v2.0).

SCM-14475

SCM now supports adding and editing Sectigo Orchestration Gateway (v2.0) keystores and endpoints from the UI.

SCM-14395 / SCM-14396

Improved filtering of Sectigo Orchestration Gateways and SSL/TLS automation endpoints.

SCM-14383 / SCM-14384

New notification for offline Sectigo Orchestration Gateways.

SCM-14386

REST API Enhancements

Change Reference number

Sectigo Orchestration Gateways can be managed via the SCM Admin REST API.

SCM-14461

Resolved issues

Issue Reference number

Updating a certificate’s metadata via API would fail if the certificate’s initial term was no longer allowed in the certificate profile.

SCM-14133

Inventory exceeded notifications might be sent when the usage exactly matched inventory.

SCM-14620

SSL certificate reports created via API did not include the IP address column even when requested.

SCM-13074

Assigning certificates from a bucket to an organization/department might not process all certificates if some certificates had been processed already.

SCM-14434

For earlier releases, see SCM Enterprise release notes.

DNS connector v2.0

This release includes the following updates and improvements:

General updates

Change Reference number

The DNS connector now supports LEGO DNS providers, including all providers available up to LEGO version 4.31. These providers are bundled with the DNS connector and can be used with the lego provider type.

SCM-13509

Resolved issues

Change Reference number

Starting with DNS connector 1.3, created entries for Cloudflare, DNSimple, and OVH would not be deleted after validation was complete.

SCM-14297

For earlier releases, see DNS connector release notes.

MS agent v4.4

This release includes the following updates and improvements:

General updates

Change Reference number

The performance of the Certification Authority snap‑in has been enhanced, resulting in much faster loading and navigation of issued certificates in high‑volume deployments.

SCM-13143

There is improved HTTP proxy compatibility by including the port number in the CONNECT request as well as the Host header.

SCM-12270

Startup no longer converts CA private keys to non‑exportable by default; this can be enabled via the PrivateKeyNonExportable registry setting.

SCM-13903

Resolved issues

Change Reference number

Fixed a regression in MS Agent 4.3 that caused certificate requests to fail for Active Directory Certificate Templates requiring manual SAN entry.

SCM-12534

Improved handling of network loss during initialization, which previously resulted in logging the error "The specified domain either does not exist or could not be contacted."

SCM-12995

Fixed an issue where CA names containing spaces were parsed incorrectly, preventing the CA’s AD Configuration container from being located during discovery.

SCM-13187

Resolved an issue where conflicting error codes caused incorrect permission‑related error messages to appear during enrollment.

SCM-13380

Fixed an issue where startup without SCM connectivity caused the CA console to hide existing certificate templates and delete the assigned template list when attempting to add a new one.

SCM-13922

For earlier releases, see MS agent release notes.

Network agent v5.5

This release includes the following general updates:

Change Reference number

Improved script that collects IIS server information to operate on Windows desktop operating systems that don’t have required IIS features installed.

SCM-12839

Resolved issue of installation of wildcard certificates to Apache servers from a Network Agent installed on Windows that would fail with an error saying “The filename, directory name, or volume label syntax is incorrect”.

SCM-12874

For earlier releases, see Network agent release notes.

Private key agent v2.3

This release includes the following general updates:

Change Reference number

On some systems, the agent would fail when generating CSR and key.

SCM-9723

Improved performance when processing large numbers of key generation requests.

SCM-11056

For earlier releases, see Private key agent release notes.

CA connector v3.5

This release includes the following resolved issues:

Change Reference number

The Sectigo CA Connector 3.4 installer was reporting itself as 3.3.

SCM-13345

Discovery of certificates in DigiCert found no certificates if the account contained a multiple of 20 certificates.

SCM-13287

There was a missing space between review_requests and create_longer_validity_order when describing missing DigiCert API permissions.

SCM-11284

For earlier releases, see CA connector release notes.