Release Notes On-prem - Patch 1
The AppViewX v2026.2.1.0 (On-prem) release notes describe new features, enhancements, bug fixes, security fixes, known issues, and known limitations in the software.
New Features
There are no new features in this software release.
Enhancements
- Access Control settings for onboarding group ACL enforcement
Centralized Access Control in Platform Settings, providing a single location to manage tenant-level onboarding group ACL enforcement and Dashboard ACL configuration. Existing behavior remains unchanged unless the new settings are enabled.
- PKI path length override for subordinate CA issuance
Added support to override the path length constraint during subordinate CA certificate issuance, enabling successful issuance of externally generated CSRs without a predefined path length.
Bug Fixes
- HAProxy Device Addition Failure
Resolved an issue where the HAProxy device management process failed during the download configuration file phase.
- SCEP Microsoft Intune certificate delivery
Resolved an issue where certificates enrolled through the SCEP Microsoft Intune connector were not delivered to client devices, ensuring successful end-to-end certificate enrollment.
- ACME wildcard certificate enrollment via automated DNS
Resolved an issue that prevented automated DNS validation for wildcard ACME certificate enrollment with Infoblox, enabling successful certificate issuance.
- DNS TXT record cleanup during domain validation
Resolved an issue where unrelated DNS TXT records could be removed during domain control validation, ensuring only the validation-specific record is deleted.
- Scheduled discovery execution for unmanaged devices
Resolved an issue that allowed scheduled discovery to run for devices in Unmanaged status. Discovery execution now verifies device status and prevents execution by failing the affected batch when the device is unmanaged.
- Incorrect mTLS status display in network scan discovery
Resolved an issue where the mTLS status was incorrectly displayed as always enabled during network scan discovery under the Scan Status tab.
- Sectigo multi-organization certificate discovery mapping
Resolved an issue in Sectigo discovery with multiple organizations where the final organization was incorrectly applied to all certificates, leading to mismatches during enrollment.
- Cipher strength classification improvements
Resolved an issue where additional cipher strength data (key type and strength) caused ciphers to be categorized under the Unknown list.
- Duplicate scheduled job execution
Resolved duplicate job executions caused by a Java wait condition at the pod level.
- GlobalSign MSSL subdomain enrollment support
Enhanced GlobalSign MSSL enrollment to support subdomain-based creation, with costing aligned to the CA’s subdomain pricing model.
- Policy Engine certificate auto re-enrollment
Resolved an issue where certificate auto re-enrollment through the Policy Engine was not functioning for the Scheduler role.
- Infrastructure component security upgrades
Upgraded Kubernetes and multiple infrastructure components to address known security vulnerabilities as part of the security patch. These upgrades improve the security, stability, and reliability of both On-Premises and SaaS deployments across supported Kubernetes platforms.
- Infrastructure Upgrade security vulnerability remediation
Addressed SAST and SCA security vulnerabilities identified in the Infrastructure Upgrade module by applying the latest available security patches to underlying operating system.
- HSM Master Key Access
Resolved an issue where access to the HSM Master Key intermittently failed. Updating the HSM restored normal functionality.
- API documentation issues in Infra group host listing and Key
Provision
Resolved documentation issues in the Swagger specification and API documentation for the Infrastructure Group Host Listing API and the Key Provision API. The API documentation was updated to accurately reflect the correct request parameters, response structures, and behavior for both endpoints.
- SSH Key and Certificate provision action improvements
Resolved an issue in the SSH Key and Certificate provision workflow where the Valid From and Valid To date values configured during the Key and Certificate Configuration step were not editable in the Review and Confirm screen. The provision action was updated to display the configured date values as editable fields during the Review and Confirm stage, allowing users to modify them before final confirmation.
- SSH Key Provision workflow error handling improvements
Resolved an issue where a credential fetch failure on a single host would halt provisioning for the entire batch. Failed hosts are now individually flagged, allowing provisioning to continue uninterrupted for all other valid hosts.
Known Issues
- Fetch F5 Master Key Workflow
The Fetch F5 Master Key workflow fails when backup information is unavailable, preventing retrieval and storage of the master key from managed F5 devices.
Limitations
There are no limitations in this software release.
