- CyberArk Rebranding.
- Upgrade to Go 1.24.
- Improve password entropy.
- Replace golang.org/x/crypto/pkcs12 by software.sslmate.com/src/go-pkcs12.
- Add support to pass dns sans values as well when CSR is provided for TPP.
- Fixes panic caused by SanURI in Cloud Zone.
- Add support to provide VCP certificate tags for VCert CLI enroll command.
- Add support to provide VCP certificate tags for VCert CLI renew command.
- Upgrade dependencies.
- Upgrade to Go 1.23.12 to avoid the vulnerability (CVE-2025-4674)
- Add support to revoke certificates in VCP using the CLI and the SDK.
- Release Candidate to support the certificate revocation in VCP.
- Allow to set a GCM Certificate scope without a certificate name.
- Add support to provide GCM Certificate Scope for Provision Cloudkeystore
- Support for Linux ARM 32 bit Binaries
- Add missing support to use --platform flag with the following commands:
- pickup
- renew
- retire
- getpolicy
- setpolicy
- TPP v25.1 support
- Fix for Playbook's backup functionality (#549)
- Fix: fixes VCert logger import
- Fix: bumps libraries
- Enables RSA 3072 bit key size for TPP (VCert SDK)
- Support for VCP Provisioning (final release)
- Support for VCP Provisioning - (Pre-release)
- Enables Certificate Provisioning with Service Account Auth
- Adds ability to provision certificate using keystore and provider name
- NEW FEATURE: Support for VCP Provisioning (api-key support only)
- Fix issues with proxy.golang.org which were introduced in VCert 5.6.3.
General:
- Updates all playbook samples, removing deprecated attributes and making sure they work out-of-the-box
VCert SDK:
- Adds
TokenURLtoendpoint.Authentication - Cloud Connector will stop using the
TokenURLattribute fromendpoint.OAuthProviderand start using the new one (above)
VCert CLI:
- Internal changes to make use fo the new
TokenURLattribute - Renames
getcredcommand flag--idp-jwtback to--external-jwt - Fixes an issue whereby using
getcredcommand to request aTPPaccess token by using username/password threw the deprecation warning message. This should not happen forgetcredcommand - Fixes an issue whereby requesting an access token for
VCPplatform printed the wrong expiration date. Now it properly prints the expiration date
VCert SDK:
- Adds new attribute
config.connection.credentials.tokenURLto playbook file. This attribute should be used to pass theVCPtoken url value - Stops using
config.connection.credentials.idP.tokenURLfor theVCPtoken url value - Enhances the task run. Now, a failed task will not terminate the playbook execution, instead it will run all tasks and errors will be reported at the end of the run.
VCert SDK:
- Removes
TenantIDfromendpoint.Authenticationstruct cloud.Connectorwill useendpoint.Authentication.OAuthProvider.TokenURLinstead of building the URL (using thetenantID) to obtain the access token
VCert CLI:
- Removes
--tenant-idflag forgetcredcommand - Adds
--token-urlflag forgetcredcommand
VCert Playbook:
- Removes
tenantIdattribute fromconfig.connection.credentialsobject - Now uses
config.connection.credentials.idP.tokenURLfor Venafi Control Plane service account authentication
VCert SDK:
- Adds UserAgent header to api requests for TPP, Cloud and Firefly connectors
- Adds functionality to convert a Platform type to a ConnectorType enum
VCert SDK:
- Adds support for service account authentication in Cloud connector
VCert CLI:
- Adds new attributes to
getcredcommand:tenant-idandexternal-jwtfor Venafi Control Plane (VCP) service account authentication
VCert playbook:
- Adds support for service account authentication to VCert playbooks