2025 Fourth Quarterly Release - 25.4 Notes

November 2025

Keyfactor is pleased to announce the release of Keyfactor Command 25.4, featuring major new enhancements.

Tip:  Keyfactor recommends that you check the Keyfactor GitHub Site (https://keyfactor.github.io/integrations-catalog/) with each release that you install to check if you will need to download the updated orchestrators to work with that version of Keyfactor Command.

Please refer to Keyfactor Command Upgrading for important information about the upgrade process. For a complete list of the items included in this release, see Release Note Details v25.4. For gateway and CA Connector Client release notes, see:

Note:  Professional Services and Customer Success will reach out to you to schedule upgrades.

Highlights

Changes & Improvements

Fixes

Deprecation & Removals

  • The license for the Logi Analytics Platform, used by the Keyfactor Command dashboard and reports, will expire on November 28, 2027 and will not be renewed. Customers who have not upgraded to Keyfactor Command 26.1, when the new reports and dashboards will be available, or later by that date will no longer be able to use the dashboard or reports.

Known Issues

  • Searches for workflow instances using the InitiatingUserName query parser fail with an “invalid column name” error. This will be corrected in a future release.

  • The V1 Reports endpoints (for the legacy (Logi-based) reporting engine) are deprecated and will be removed in November 2027. They remain functional for backwards compatibility only.

  • If the Certificate Owner Role is set to Hidden for a non-default enrollment pattern, and that enrollment pattern specifies a default certificate owner that differs from the default enrollment pattern for the same template, the certificate owner applied after enrollment will incorrectly reflect the default enrollment pattern’s certificate owner rather than the one defined in the selected enrollment pattern. This issue will be corrected in a future release.

  • Selecting certificate stores of different types and attempting to assign them to a single application results in an error stating that “...different categories cannot be approved in a single batch.” A future release will allow assigning multiple certificate store types to an application in one action.

  • The usp_DisassociateCA stored procedure may fail in reference to the dbo.StagingFields table indicating Invalid object name 'dbo.StagingFields'. The workaround to this issue is to edit the stored procedure and comment out the following line (approximately line 63) by adding -- in front if it:

    --DELETE FROM [dbo].[StagingFields] WHERE CertificateAuthorityId = @CAId;

    This issue will be corrected in a future release.

  • There is an issue in the new template naming functionality for EJBCA that can accidentally create duplicate templates with the wrong name under certain circumstances. This will be fixed in a future release.

API Endpoint Change Log

Please review the information in the API Change Log for this release carefully if you have implemented any integration using these endpoints: API Change Log v25.4.