Release Notes
Concise, deployment-focused release notes for the DuoKey Cockpit Solution.
Full functional release notes
For the complete functional notes and download links, contact your DuoKey representative or [email protected].
v1.4
Released: 6 January 2026
Deployment image
| Field | Value |
|---|---|
| Image | registry.duokey.cloud/dke-cockpit/dke-cockpit-host |
| Tag | v1.4.0.20260220.4adff9c8 |
| Digest | sha256:816c0ec8f1d1d1f27d7d034a2e8b5728b1364f4f4bb256c478b6c49eca1d7b5d |
Pin by digest in production — see Container Images.
Highlights
- SQL Server EKM support — Transparent Data Encryption (TDE) integration for client SQL Server databases via the Extensible Key Management provider. The Cockpit's own datastore remains PostgreSQL only (see Configuration).
- EST server (RFC 7030) — standards-based certificate enrollment and CSR signing; SCEP renamed to EST.
- Certificate manager — issue CSRs through external PKI issuers.
- Cryptography — ECDSA secp256k1 (import, CSR, issuance); RSA OAEP SHA-256; AES (CBC/GCM) across the Software Vault, DuoKey MPC KMS and Securosys Primus, incl. via PKCS#11.
- DuoKey Software Vault — full support throughout, PKCS#11 data objects, private-key export.
- DKE 365 — more robust Microsoft Graph integration (retry policy).
- Platform — updated runtime and framework baselines.
- API —
X-Correlation-Idon all calls; optional HTTP for backends behind a customer HTTPS proxy.
Security fixes
- Keycloak role mapping and no-email-scope support; IdP login deadlock/race conditions resolved; Azure AD regression fixed.
- Dependency upgrades across the stack.
Known issues
- EST/SCEP backend URL endpoints still use legacy SCEP naming (UI renamed only).
- Vault selection occurs at the end of the wizard flow (fix planned).
Support
- Documentation: support.duokey.ch · Support: [email protected]