Skip to main content

Release Notes

Concise, deployment-focused release notes for the DuoKey Cockpit Solution.

Full functional release notes

For the complete functional notes and download links, contact your DuoKey representative or [email protected].


v1.4​

Released: 6 January 2026

Deployment image​

FieldValue
Imageregistry.duokey.cloud/dke-cockpit/dke-cockpit-host
Tagv1.4.0.20260220.4adff9c8
Digestsha256:816c0ec8f1d1d1f27d7d034a2e8b5728b1364f4f4bb256c478b6c49eca1d7b5d

Pin by digest in production — see Container Images.

Highlights​

  • SQL Server EKM support — Transparent Data Encryption (TDE) integration for client SQL Server databases via the Extensible Key Management provider. The Cockpit's own datastore remains PostgreSQL only (see Configuration).
  • EST server (RFC 7030) — standards-based certificate enrollment and CSR signing; SCEP renamed to EST.
  • Certificate manager — issue CSRs through external PKI issuers.
  • Cryptography — ECDSA secp256k1 (import, CSR, issuance); RSA OAEP SHA-256; AES (CBC/GCM) across the Software Vault, DuoKey MPC KMS and Securosys Primus, incl. via PKCS#11.
  • DuoKey Software Vault — full support throughout, PKCS#11 data objects, private-key export.
  • DKE 365 — more robust Microsoft Graph integration (retry policy).
  • Platform — updated runtime and framework baselines.
  • API — X-Correlation-Id on all calls; optional HTTP for backends behind a customer HTTPS proxy.

Security fixes​

  • Keycloak role mapping and no-email-scope support; IdP login deadlock/race conditions resolved; Azure AD regression fixed.
  • Dependency upgrades across the stack.

Known issues​

  • EST/SCEP backend URL endpoints still use legacy SCEP naming (UI renamed only).
  • Vault selection occurs at the end of the wizard flow (fix planned).

Support​