What’s new in ens0key
Changes through version 1.0.26: local account MFA, API credential inventory, and more reliable certificate operations.
1.0.26
Local MFA and security updates
- Enroll TOTP with Google Authenticator or another compatible app, and save single-use recovery codes. Choose optional enrollment, mandatory MFA for local administrators, or mandatory MFA for all local users.
- Connect Cisco Duo Universal Prompt, map local users to Duo identities, and verify a successful Duo login before activating enforcement. Setup identifies missing mappings before the policy can be applied.
- An explicit exception for the configured host administrator still requires TOTP or a recovery code. Other users subject to mandatory Duo have no automatic outage bypass. SSO and direct LDAP keep their separate policies.
- Account security shows the effective policy and saved Duo mapping. The Users workspace offers grouped actions and mobile cards in English, Croatian and German.
- Updated Go and SSH dependencies ship in both server and agent builds. Upgrade deployed agents as well as the server.
1.0.25
API credential lifecycle: inventory and alerts
- Record API tokens, personal access tokens, API keys and OAuth client secrets with application, environment, issuing identity, accountable owner and consumers.
- Track expiry, rotation and review deadlines; route findings to owners or a fallback recipient. Acknowledge alerts and retain metadata change history.
- Use CSV import/export, priority sorting, filters, pagination, mobile cards and replacement runbooks. Token and secret values remain outside ens0key.
- This release manages metadata and operator follow-up. It does not automatically discover, validate, issue, rotate or revoke provider credentials.
1.0.24
Safer connectors and stronger access controls
- IIS deployment checks the imported leaf certificate, private key and final binding. Ambiguous site/port bindings fail explicitly; selecting individual SNI/IP bindings on the same site and port is outside the current scope.
- Cisco WLC validates platform, certificate type and transfer settings. Connector compatibility is checked against the selected device and use case during the pilot.
- Stronger session invalidation, SSH host-key pinning, command validation, certificate/key matching and SIEM escaping. Renewal distributes keys only to previously successful explicit deployments.
- External CA operations report unsupported revocation instead of marking a certificate revoked locally. Use the issuer portal for unsupported ACME, EJBCA and DigiCert revocation; the internal CA provides CRL and OCSP.
- Appliance upgrade backups detect incomplete dumps and compression failures. Existing hosts need the updated host script separately from an application image upgrade.
1.0.23
Deployment status and operator experience
- Failed retries retain the last successful installation. Agent locations reflect queued/running work and actual results; older deployment records remain unverified until inventory or redeployment confirms them.
- Expiry filters agree with dashboard counts and saved collections retain the selected filters. Responsive layouts, keyboard-accessible dialogs and persistent page URLs improve daily work.
- Pages load on demand and use compressed, cached assets to reduce the initial download.
Plan your upgrade
- Back up the database and retain the master key before upgrading. Migrations are forward-only; restoring an older server across the MFA boundary requires the pre-upgrade backup and a recovery plan.
- When upgrading from before 1.0.24, plan a maintenance window, pause agents and review queued work. The security migration cancels affected jobs; retry them through their dedicated operations after the upgrade.
- MFA starts optional on installations without an existing policy. Test enrollment, recovery and Duo mappings before enforcing it. Protected local accounts cannot use password-only Basic authentication; review CLI and automation dependencies first.
- Validate the upgrade on your target environment before production rollout. Confirm device versions and connector operations in the pilot; Cisco ESA management HTTPS binding is not currently ready for use.