Release Notes

SSLNexus 1.0.7

What changed, what it means, and what administrators should know before upgrading.

Release date: 29 September 2026

Overview

SSLNexus 1.0.7 expands first-party certificate deployment coverage and consolidates discovery into a clearer operator workflow while preserving the existing 1.0.x installation, upgrade and certificate-custody model.

New certificate integrations

  • Added first-party Apache Tomcat / Java certificate deployment for Linux targets using the established target-bound deployment workflow.
  • Added Microsoft Exchange certificate lifecycle support using Windows remote management and Exchange-native certificate import/service binding.
  • Added Fortinet FortiGate certificate deployment through its HTTPS API.
  • Added Citrix ADC / NetScaler certificate deployment through NITRO.
  • Added Kubernetes TLS Secret deployment through the Kubernetes API.
  • Added HashiCorp Vault PKI as a native certificate authority connector while retaining Vault KV as a certificate destination.
  • Added a Kemp LoadMaster adapter in Lab status. It is included for controlled qualification and is not represented as a production-qualified integration in this release.

Discovery

  • Added a dedicated Discovery page that separates verified-domain discovery from active network discovery.
  • Domain Discovery now presents managed parent domains through a single dropdown workspace instead of rendering one card per domain.
  • DNS TXT ownership verification is available directly from the Discovery workflow so administrators do not need to return to Organisation to complete verification.
  • Verified-domain discovery can optionally restrict results to a CIDR boundary after name enumeration and DNS resolution. The CIDR is a result filter; it does not turn domain discovery into a subnet scan.
  • Network Discovery exposes the existing active private-CIDR TLS scanner as a distinct workflow.
  • Discovery and Organisation workflow cards now preserve their expanded/collapsed state across page re-renders.

Windows target onboarding

  • Improved the Windows target preparation guide with a complete PowerShell preparation block that can be copied directly from the dashboard.
  • Improved automatic selection of the SSLNexus source address by preferring the Linux kernel route/source decision before falling back to interface enumeration.

Compatibility and security model

  • Existing deployment adapters continue to use the established SSLNexus certificate deployment engine rather than introducing a second automation engine.
  • SSLNexus automation remains scoped to certificate lifecycle operations; the release does not introduce general-purpose server patching or configuration-management automation.
  • Existing customer private-key custody expectations remain unchanged. Integrations that support target-side key generation retain keys within the customer-controlled target/infrastructure boundary.
  • Existing 1.0.x native package upgrade paths are retained.

Release verification

Production publication requires the qualified App1 release gate with exact Go 1.27.1 and GOFIPS140=v1.0.0, the complete Go/security test suite, CycloneDX SBOM generation and verification, finished DEB/RPM package verification, and the established install/upgrade/rollback smoke tests. Only artifacts that pass those checks are to be published.