2025 Third Quarterly Release - 25.3 Notes

September 2025

Keyfactor is pleased to announce the release of Keyfactor Command 25.3, featuring major new enhancements—including a fully customizable, user-specific dashboard.

Tip:  Keyfactor recommends that you check the Keyfactor GitHub Site (https://keyfactor.github.io/integrations-catalog/) with each release that you install to check if you will need to download the updated orchestrators to work with that version of Keyfactor Command.

Please refer to Keyfactor Command Upgrading for important information about the upgrade process. For a complete list of the items included in this release, see Release Note Details v25.3. For gateway and CA Connector Client release notes, see:

Note:  Professional Services and Customer Success will reach out to you to schedule upgrades.
Highlights
  • New Dashboard

    A new, customizable dashboard has been introduced, allowing each user to configure their own layout and widgets. In the now-legacy dashboard, all users shared the same layout, and customization was limited to hiding the risk header through permissions.

    The new dashboard supports:

    • Adding and positioning widgets as desired

    • Editing widget titles and descriptions

    • Setting critical thresholds to highlight widgets in red

    Related APIClosed An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. endpoints have been added to support populating dashboard widgets (see Analytics).

    Upon upgrading to version 25.3, users will start with a blank dashboard. From there, they can build a custom dashboard or choose to return to the legacy dashboard, which will be removed in a future release. See Dashboard for details.

  • Change Owner for Multiple Certificates

    The Change Owner operation now supports multiple certificates, making it easier to manage ownership across larger sets of certificates.

    • Multi-Select Support: Users can select multiple certificates in the grid and change their owner in a single action.

    • Permission Validation: If the user lacks sufficient permissions for any selected certificates, a warning is displayed. When this warning appears, none of the selected certificates are modified—even those the user would normally have access to.

    • Detailed Feedback: The warning includes the thumbprints of all certificates the user cannot modify.

  • Individually Schedule Expiration Alerts

    Expiration alerts can now be scheduled independently, giving administrators more flexibility in how and when alerts are run.

    • Per-Alert Scheduling: Each expiration alert can be assigned its own schedule.

    • Staggered Execution: Expiration alerts are no longer required to run at the same time.

    • Audited Changes: All modifications to an expiration alert, including schedule changes, are fully audited.

    • Upgrade Behavior: During upgrade, each expiration alert’s schedule is set to the value of the last defined Monitoring Execution Schedule.

Changes & Improvements
Fixes
  • CA threshold monitoring now correctly reports the timeframe for reporting and the certificate issuance count.

  • Disabling the Allow Deprecated API Calls application setting no longer causes an error when loading the Certificate Templates page.

  • Certificate chains can now correctly be built using a CA certificate that contains an empty subject.

  • Requests to the database during Keyfactor Universal Orchestrator system register requests have been reduced to streamline functionality. This will be most noticible when using orchestrators that handle more than 1000 jobs per orchestrator.

Deprecation & Removals
  • The license for the Logi Analytics Platform, used by the Keyfactor Command dashboard and reports, will expire on November 28, 2027 and will not be renewed. Customers who have not upgraded to Keyfactor Command 26.1, when the new reports and dashboards will be available, or later by that date will no longer be able to use the dashboard or reports.
Known Issues
  • Searches for workflow instances using the InitiatingUserName query parser fail with an “invalid column name” error. This will be corrected in a future release.

  • Enrollment from the Windows MMC through the Keyfactor Windows Enrollment Gateway fails and generates the following error in the Keyfactor API log:

    The supplied certificate format was not recognized. Valid formats are , 'DER' or 'PEM'.

    This will be corrected in a future release.

API Endpoint Change Log

Please review the information in the API Change Log for this release carefully if you have implemented any integration using these endpoints: API Change Log v25.3.