Release Notes
Downloads are available on releases.smallstep.com.
Smallstep Agent v0.70.0
EdgeThis version is available on the edge channel and has not yet been promoted to the stable channel.
Stable keys for endpoints
On Windows and Linux, an endpoint's hardware-bound keys are now reused for every certificate order, instead of a new key being created per order. (Attested keys on macOS were already stable and are unchanged.)
Devices enrolled before this release will keep serving their existing credentials and migrate on their own, reclaiming the old per-order key once a replacement certificate is stored.
OS-specific changes
Windows
- On headless, server and kiosk deployments, endpoint credentials are now issued and renewed with no user signed in. When more than one user is signed in, each endpoint is issued once for the device rather than once per signed-in user.
- Fixed a multi-user bug where one user session's renewal would remove another user session's key and certificate.
- An endpoint whose service reload needs a user session is now reported as a warning and retried every minute or at the next sign-in, rather than reported as a failed reload. The certificate is installed either way.
- Introduced a session helper for user-scoped credentials. Prior to 0.70.0, every signed-in user got an agent process of its own that ran via a scheduled task. Starting with 0.70.0, user-scoped endpoint credentials are served by a short-lived session helper that the agent spawns only when there is work to do. The old scheduled task will be removed when the agent is upgraded. Credentials are still issued into the signed-in user's certificate store.
- Fixed a resource leak where the agent kept a connection open for every user who had ever signed in, so memory use grew on hosts with many sign-ins.
Upgrading
On Windows, each endpoint that issues SSH certificates with hardware attestation gets a new key once, the first time the agent runs after the upgrade, and is issued a new certificate for it. Hosts and services that trust your SSH CA need no changes. But if you trust the previous public key directly, such as a raw entry in authorized_keys or known_hosts, replace it with the new one.
Endpoints issuing X.509 certificates don't need re-authorization. Linux devices migrate in place with no key change and need no action. On its first boot online after the upgrade, each Windows device also places one certificate order per hardware-attested X.509 endpoint and reloads the consuming services once; a fleet upgrading together will produce a burst of orders.
Smallstep Agent v0.69.3
New status checks
step-agent status now checks certificate and private keys health during endpoint checks. It will read each issued endpoint certificate from the keychain or file location and directly checking its health. Read errors, expiry, failing key checks, or missing certificates will mark the endpoint as unhealthy or unreadable. It will also test private keys, but keys that require user presence are skipped so that step-agent status can be run non-interactively.
The --skip-key-check flag was added. Use this for non-interactive, polling status checks (eg. checks run by a monitoring system or MDM) to avoid blocking agent key access.
Diagnostics improvements
step-agent doctornow uses the same network path as the agent to check connectivity. If the agent uses a proxy, doctor will too. A refusal from the proxy is reported with its status rather than as a timeout, a passing check names the proxy it went through, and a proxy that cannot carry the agent's traffic is rejected rather than reported as reachable.- TPM data is now reported. The agent now collects the device's TPM's spec version, interface, manufacturer, vendor string, firmware version, supported algorithms and endorsement key fingerprints at startup and during registration. Virtual and software TPMs are also identified as such. To check TPM data locally, run
step-agent tpm.
Endpoint credential files
- Permission changes are now applied to existing credential files on macOS and Linux. Changing an endpoint's
uid,gidormodein its configuration reaches files already on disk, and file ownership and permissions are reconciled on startup.
OS-specific changes
Windows
- Windows machine-wide endpoints are listed only once, rather than once per account.
Linux
- Network endpoints now reload as the network service's user. For example, reloading a Wi-Fi, Ethernet or VPN endpoint will ask NetworkManager for its profile by UUID.
- Fixed an issue that prevented Arch package upgrades from running the post-install steps.
NixOS
- A read-only
agent.yamlconfig file location is now supported, enabling to be declared in the Nix store. The service unit checks that the file exists, so an unregistered host still waits quietly rather than restarting in a loop, and a declared configuration starts the agent. - The agent can be declared with
services.step-agent. - The module gained
enable,packageand freeformsettings.settingsrendersagent.yaml. A settings change restarts the agent onnixos-rebuild switch. Leavingsettingsempty allows for an imperativeregisterflow.
Additional fixes
- Fixed an issue where runs of
step-agent renewandstep-agent doctor --renewdid not process renewal hooks, but remotely-initiated renewals did. These commands will now run the before, after, and on-error hooks associated with the workload. golang.org/x/cryptois updated to v0.56.0, which carries the fixes for GO-2026-6354 and GO-2026-6355 in its SSH package.step-agent tpmno longer downloads endorsement key certificates by default; pass--certificateto fetch them.
Smallstep Agent v0.69.2
This release repairs three ways a Windows device could lose track of its own credentials — a reset that orphaned TPM keys it could not delete, a bootstrap enrollment that deleted the device identity key, and two certificate issuance passes running over each other — and fixes workload hooks that skipped the first issuance at login. The workload hook fix applies on every platform, and the Intune package gains an evergreen download URL.
Reliability
Workload hooks fire on first issuance. A workload's sign_before and sign_after hooks ran on periodic ticks, renewals and configuration updates, but not when its credentials were first issued at login, so anything a workload did to pick up new credentials was skipped exactly once — on the issuance that created them.
Windows
reset no longer orphans TPM keys it cannot delete. Run from an elevated console rather than as the system account, reset removed the records naming the device's TPM keys while the keys themselves survived — and those records were the only handle on them, so a single run could leave every key on a device unreachable. Now reset:
- refuses to start where it cannot finish, and says why: an unelevated run is refused outright, and user-scoped keys it cannot reach — left by an older agent, or by a console elevated as a different account than the logged-in user — are reported with the context needed to reach them (
--dry-runwarns instead;--skip-scope-checkoverrides); - keeps the storage records and directory for every key it could not delete, so a correctly scoped re-run can finish the job, and reports failure rather than success when keys remain;
- deletes each endpoint's certificate together with its key, searching both the machine and the user certificate store and matching by the endpoint the certificate was issued for, so no certificate outlives a key nothing can sign with; the agent's own identity certificate is now removed as well;
- never acts on a key record that belongs to another user profile on the same machine;
- reports one summary grouped by cause instead of many repeated errors.
Enrolling with a bootstrap token no longer destroys the agent's identity key. During a bootstrap enrollment through ACME device attestation, the identity certificate was filed against the short-lived bootstrap key and the real identity key was deleted as superseded. Every later control-plane renewal and re-bootstrap then failed with NTE_BAD_KEYSET, minting and discarding a key every 10–60 seconds for as long as the device stayed awake — while doctor and status still reported it healthy. The usual trigger was the control-plane certificate expiring while the machine slept. A device wedged this way now recovers on its own within about a minute of waking.
Certificate issuance passes no longer overlap. A user login, step-agent renew, or doctor --renew could run at the same time as the agent's periodic pass. Each pass swept the other's keys and wrote its own certificate, so an endpoint could end up with one certificate in the platform store and a different one on disk, or fail issuance outright with NTE_BAD_KEYSET, and nothing repaired it until the next restart or configuration update. Passes now run one at a time, and the log records each pass starting and finishing, with an info-level line whenever one waited more than five seconds for another. The fix applies on every platform.
Also: the user-session reload server now always creates its keys in the user's keyset, so a certificate filed under the current user no longer ends up paired with a machine-scoped key (seen when the logged-in user is the built-in Administrator); and the agent logs a warning naming the endpoint and both scopes when it reuses a key from a different keyset than the one it would now choose.
Intune
Evergreen download URL for the .intunewin package. Every stable promotion now publishes step-agent_<arch>_latest.intunewin beside the MSI pointer, so the package the Intune setup documentation points at tracks the current agent instead of a copy updated by hand.
Additional fixes
resetcould report the state directory deleted while leaving most of it in place, because the removal stopped at the first non-empty subdirectory; it now removes the whole tree apart from the entries it deliberately keeps.golang.org/x/cryptois updated to v0.55.0, which carries the fix for GO-2026-6303 (callbacks ingolang.org/x/crypto/ssh). No agent code changed.
Upgrading
No action required. Two things to know on Windows:
- Run
resetas the system account (for example viapsexec -s) on devices enrolled before machine-scoped keys (< v0.68.0), and otherwise from a console elevated as the logged-in user;resetnow tells you which when it refuses. - Devices that already hold an endpoint key in a different keyset than the agent would now choose are not migrated automatically. The agent logs a warning naming the endpoint; a
resetre-creates the keys consistently.
On every platform, a slow login or manual renewal now delays the agent's periodic renewal for its duration, and simultaneous session logins on multi-session Windows hosts are handled one at a time; the five-second contention line in the log shows when this is happening.
Smallstep Agent v0.69.1
EdgeThis version is available on the edge channel and has not yet been promoted to the stable channel.
This release closes the ways a device could quietly stop being managed — a Windows laptop that slept, a Linux device that rebooted with no network path but EAP-TLS, an agent whose runner died while its service still reported Running — and adds workloads, Windows event-log reporting for certificate lifecycle, a NixOS module and package channel, and a one-command support bundle.
Workloads
Credentials can be grouped into workloads. A workload names a set of credentials that belong to one service and gives them a single reload that fires once per renewal cycle when any member renews, lifecycle hooks for sign and renew with before, after and on-error steps, and a health probe per credential. Health reports are attributed to the workload, and status lists each workload with its members and their state.
Reliability
SSH endpoints keep their key across renewals. Every SSH renewal ran a full device-attestation order, and on TPM-backed devices each order minted a new hardware key, so an endpoint's SSH key fingerprint changed at every renewal and anything registered against it — an authorized_keys entry, a signing key on a code host — went stale. The agent now resumes the endpoint's existing attested key and re-signs against it; the order runs only for an endpoint with no usable key yet.
Bootstrap keys no longer pile up on TPM-backed devices. A device whose control-plane certificate had expired retried its recovery path indefinitely, and each attempt minted a TPM key that nothing reclaimed, so a stuck device could fill its TPM storage. Prior bootstrap keys are now swept before each attempt.
Control-plane renewal failures are logged. When renewing the agent's own control-plane certificate failed and the token fallback failed too, nothing was logged; a device could sit disconnected for days with the cause absent from every log. The failure is now logged once with its cause.
Windows
Devices no longer stop managing endpoints after sleep. Modern Standby freezes user-session processes while the agent's service keeps running, so the agent treated its frozen user-session reloader as dead, evicted it, and had no way to take it back: status listed only the device identity, every configured endpoint went unmanaged, and the service log repeated a deficit warning once a minute until someone restarted the user task by hand. The agent now:
- evicts a reloader only on proof that its process is gone, never on silence alone, so a frozen reloader resumes managing its endpoints the moment the device wakes;
- restarts a reloader that is awake but not answering, and displaces a user task that is running without being registered, each paced with a cooldown since every re-registration re-issues certificates;
- no longer lets a renewal that falls due during a freeze park the whole certificate loop, and bounds every request it sends to a reloader;
- reports an endpoint as unmanaged once its reloader has actually made it miss a renewal, rather than counting it as healthy indefinitely;
- stores a non-attested endpoint's certificate against the key it actually has, and never lets two overlapping stores delete each other's fresh certificate.
A dead agent no longer reports Running. If the agent's runner exited with an error, the service kept answering status queries and reporting Running indefinitely, so Windows service recovery never restarted it and the device stayed offline while looking healthy. The service now exits with a failure code when the runner dies, and the recovery actions configured at install time restart it. Operator-requested stops still exit cleanly.
Certificate lifecycle events in the Windows event log. The agent now writes structured events under the SmallstepAgent provider in the Application log when an endpoint receives its first certificate (400), cannot be issued one (401), renews (500) or fails to renew (501), when its service picks up the new certificate (600) or does not (601), and when the agent obtains (700) or fails to obtain (701) its own identity certificate. Events are per session on multi-user devices, carry the endpoint, certificate serial and validity as key-value lines, and land in diag bundles without any change. Failures had no event of any kind before.
The machine certificate store is cleaned at startup. Both certificate sweeps ran only after a successful store for the same endpoint, so a device at the lock screen, a disabled endpoint, or a store too polluted to store into never got cleaned. A startup pass now reduces each hardware-attested endpoint in the machine store to one working certificate — expired, unusable and superseded certificates go, and so do endpoint keys no certificate names — with a circuit breaker that refuses to act on an endpoint until at least one of its keys has been shown to open, so an unreachable TPM cannot empty the store.
Stale certificates for non-attested endpoints are swept. Prior certificates for an endpoint's key container were left behind whenever the key changed, so duplicate browser and device certificates accumulated in the user store. After each store, every earlier certificate on that container is removed, whichever key issued it; keys are never touched.
Attested endpoints serve their full certificate chain. The agent placed an attested endpoint's intermediate certificates in the wrong store, so services that build their served chain from the machine store — SQL Server, and anything else behind SChannel — sent only the leaf and clients failed chain verification, even though the PEM file on disk was complete. Intermediates now go to the machine Intermediate Certification Authorities store. Each endpoint heals at its next renewal.
The user-session reloader no longer crashes or double-mints a key. Two requests for the same endpoint's key at once — routine after a service restart — could kill the reloader process outright, which the agent then treated as a dead reloader, or generate two keys for one endpoint and leave it with no certificate. A key is now generated once per endpoint however many requests race for it.
macOS
SCEP certificates can be selected by additional subject components. Key store URIs for the Keychain now accept organizational unit and locality components, so an enrollment certificate issued through MDM can be located by the values the profile set.
doctor no longer hangs in headless runs. The location check waited on CoreLocation without a bound, so doctor and the desktop preflight hung at full CPU when run over SSH or in automation. The wait is now bounded at a few seconds.
Linux
Devices boot and serve PKCS#11 without reaching the control plane. On a device whose only network path is EAP-TLS, the supplicant needs the endpoint's key from the agent's PKCS#11 socket to join the network, and the agent needed the network to start serving. Neither could go first, so a reboot left the device offline indefinitely, and a supplicant that started before the socket existed stayed broken until it was restarted. The agent now:
- takes its PKCS#11 socket from a systemd socket unit, so the socket exists before the supplicant asks, and holds connections until endpoints are initialized so an early client is never answered with an empty token;
- keeps the last configuration the control plane served and boots from it when the control plane cannot be reached, retrying the login in the background;
- serves the certificate already on disk instead of re-signing at every start, so a device with no CA reachable still has its credentials to offer;
- keeps the socket across a
reset, and restarts on upgrade so the new binary takes effect.
First enrollment still needs the network once, and a certificate that expired while the device was off cannot be served.
doctor and the CLI find the packaged software TPM from a root shell. Commands run outside the service's environment probed the wrong path for the swtpm socket, so doctor reported no TPM on a healthy packaged install and register fell through to a non-TPM identity. The packaged socket path is now probed as well, privileged commands prefer it, and the no-TPM failure lists every socket it tried. A non-root user in the step-agent group can now also reach the system swtpm.
doctor no longer breaks later runs by other users. The authorities check wrote root-owned directories under the runtime directory, so after anyone ran doctor as root, a monitoring check running it as the service user failed with permission denied. The check is now read-only; the JSON output key is unchanged.
Packages install where systemd is not PID 1. The post-install script called systemctl daemon-reload unconditionally, so installs in containers, chroots, build roots and WSL without systemd failed or were left half-configured. The call is now guarded the way distribution tooling guards it.
NixOS
A supported NixOS module and package channel. The module is now under source control and mirrored to the Smallstep NUR repository on every merge, and it is wired for the PKCS#11 socket activation above. It gains a services.step-agent.package option for hosts that want the current NUR package rather than what nixpkgs carries, names the agent binary explicitly so a NUR package no longer crash-loops at start, and declares its unfree packages in a form that composes with the host's own configuration. The release tarball the Nix derivations fetch is now published to packages.smallstep.com, on the edge channel at tag time and on stable at promotion, so NixOS installs come from the same channel as every other platform.
Diagnostics
A one-command support bundle. step-agent diag now writes smallstep-agent-diag-<timestamp>.zip instead of streaming text: the diagnostics report, agent logs from every log directory, and on Windows the System, Application, WLAN, Wired AutoConfig and Task Scheduler event logs from the last seven days, Intune Management Extension logs, and recent MSI logs. The report gains a TPM key inventory that records whether each key opens and signs under the collecting identity, and on Windows a service section that shows the configured recovery actions and start triggers, so a service that restarted on its own can be told apart from one that was started. Everything is best-effort: a bundle from a half-dead machine is the point, and each failure becomes a collection note rather than an abort. --text keeps the old output; --no-events skips the off-agent artifacts.
Upgrading
No action required. Things to know:
- On Linux, the package now installs and enables a
step-agent-pkcs11.socketunit and restarts the agent on upgrade. NixOS hosts should take the updated module from the NUR mirror; it depends on the socket unit rather thannetwork-online.target. mcp proxy --gateway-url X --endpoint Ywithout--upstreamis no longer accepted; pass the upstream URL. A configured MCP proxy integration with no upstream URL now fails with a clear error instead of falling back to the gateway's default routing.
Smallstep Agent v0.69.0
EdgeThis version is available on the edge channel and has not yet been promoted to the stable channel.
This release repairs the Windows devices the 0.68.0 key-scope migration left without working network credentials, keeps the Windows user task supervised so endpoints stay managed, and stops the agent presenting an expired certificate to the control plane. It adds on-demand renewal with step-agent renew, machine-readable status, and a packaged osquery extension for macOS.
Certificate renewal
Renew a certificate on demand. step-agent renew <endpoint...> or --all renews agent-managed certificates from the device, so a renewal workflow — a service reload, a Wi-Fi or VPN reconnect, browser mTLS — can be exercised without waiting for the agent's renewal window. It renews sequentially and keeps going past a failure, reports the serial it replaced beside the new one, tells apart an endpoint with no registered reloader from one that does not exist, and reports a renewal whose service reload failed as reload-failed rather than success. --json, --timeout and --ipc are available. Two things this also fixed: an on-demand renewal never reached the control plane, so the dashboard kept showing the superseded certificate until the next scheduled renewal, and doctor --renew validated the certificate it had just replaced.
The control-plane connection uses the renewed certificate. The agent's live connection to the control plane kept presenting the certificate it first logged in with, even after that certificate had been renewed. Once it expired, any transparent reconnect — a VPN idle timeout, a server restart, a laptop waking — was rejected as an expired certificate until repeated failures forced a full reconnect, which showed up as bursts of Unavailable errors in traces. The connection now presents the current certificate on every handshake.
Reliability
The agent no longer crashes when a session logs in during a renewal. A user session registering or leaving while the renewal loop was walking the endpoint tables could hit a fatal concurrent-map error and take the agent down. Access to those tables is now synchronized, and a session that logs out cleanly no longer keeps its endpoints renewing and reporting as managed.
A missing authority no longer crashes the session login. An endpoint that referenced an authority absent from the agent's configuration made the login that registers a user session panic, so that session's endpoints went unmanaged. The agent now reports the missing authority as an error and retries on its normal cycle.
Superseded TPM keys are reclaimed on TPM-backed devices. Every renewal of a hardware-attested endpoint minted a new TPM key and never deleted the old one, so keys accumulated without bound until the TPM ran out of handles. After each successful renewal the previous keys for that endpoint are now removed.
Windows
Devices broken by the 0.68.0 key-scope migration recover. The migration that moved TPM keys to machine scope could delete a device's hardware-attested endpoint keys while leaving their certificates deployed. A certificate whose key is gone still claims to have one, so Windows kept selecting it for Wi-Fi and Ethernet EAP-TLS and the device dropped off the network with no way to heal. The migration now retires the old attestation key by renaming its record and deletes nothing, and a sweep after each issuance removes certificates whose key no longer exists, so a device already in this state repairs itself at its next issuance.
The user task is supervised. All endpoint management on Windows runs through the per-user \Smallstep scheduled task. If that task was removed, disabled, changed, or simply not running, the device silently stopped issuing and renewing certificates. The agent now keeps the task installed, enabled, matching what the installer creates, and running whenever no user session is connected, and repairs it within a minute of noticing. Deployments that deliberately run the task as a fixed account can exempt the principal check with the ReloaderIgnorePrincipalDrift policy.
Endpoint keys are no longer reminted on every restart. An endpoint with no explicit key type — the default for most configurations — had its key deleted and recreated every time the user task restarted, and each new key stranded the previous certificate in the user store. This was the source of the duplicate browser and device certificates accumulating in the store. The key is now reused, and affected devices pick that up with the key they already have.
Recovery from an orphaned attestation key. If the agent's attestation key record survived but its hardware key had been deleted — a TPM clear, a profile reset, an imaging tool — the agent failed to start and crash-looped. It now detects that state, removes the stale record, and creates a new attestation key. Endpoint keys and certificates are untouched.
Doctor's certificate-store check reports what is in the store. doctor reported every attested endpoint's certificate as missing from the certificate store when all of them were present, because it resolved certificates through their private keys from the wrong location. It now enumerates the store directly, also checks endpoints stored through the user session, and reports an unreadable store once with the remedy instead of once per endpoint.
Certificate and key diagnostics reach the logs. Messages from the certificate and key paths were written to a console the service does not have, so nothing about certificate replacement or key reuse appeared in the service or user logs. They now land in the logs with the rest of the agent's output.
Also: cleanup of expired certificates now removes the private key paired with each one, rather than leaving key containers behind.
Linux
Packages install on Enterprise Linux 10 and Arch pulls the PKCS#11 engine. The rpm required a package that Enterprise Linux 10 no longer ships, so installs failed with nothing providing it; it now accepts either the engine or the provider, whichever the distribution carries. The Arch package declared no OpenSSL PKCS#11 engine at all and now depends on libp11. Both are needed for Wi-Fi EAP-TLS to reach the agent's keys.
doctor exercises the software TPM. The runtime requirements check probed only a hardware TPM, so a host running the packaged software TPM failed the check the agent itself passes at runtime, and --tpm-device was ignored. The check and the desktop preflight now use the same hardware-then-software fallback as enrollment, honor the flag, and report which TPM they used.
osquery / Fleet
The osquery extension is packaged for macOS. A macOS package installs the extension and registers it with Orbit, and an uninstall script that Fleet can distribute removes it. The agent now exports its attestation key's public half to its state directory, and the extension reads it from there on every query, so a wrong location at startup no longer sticks until a restart. The smallstep_enrollment table gains an agent_ak_fingerprint column so a Fleet report can be matched to a device synced earlier, and the extension's errors name step-agent in Orbit's logs.
Status
Machine-readable status with the permanent identifier. status now prints the device's permanent identifier on its own line, so it is available before attestation has completed, and status --json returns the same information as JSON.
Additional fixes
go-pkcs12andpgxare updated to versions without their known vulnerabilities.
Upgrading
No action required. Windows devices affected by the 0.68.0 migration heal at their next certificate issuance, and endpoints with no explicit key type keep the key they have rather than rotating once more.
Smallstep Agent v0.68.0
This release focuses on reliability, keeping device certificates renewed, delivered, and trusted, especially on Windows and on networks with always-on VPNs, along with expanded osquery/Fleet support and Wi-Fi/Ethernet (802.1X) improvements.
Reliability
Self-healing certificate management on Windows. The agent is now far more resilient to restarts and interrupted user sessions. Previously, after a restart the agent could stop renewing and reloading endpoint certificates without recovering. Now it:
- automatically re-registers and re-initializes managed endpoints after a restart, with no user action;
- retries failed service reloads within about a minute instead of waiting for the next renewal cycle, so renewed certificates actually reach the services that use them;
- detects and clears stale reload connections left behind by ended sessions or upgrades;
- raises a clear warning and reports a degraded status when endpoints are configured but aren't being managed, instead of showing a false "healthy";
- recovers when Windows delivers managed configuration later than expected during startup.
Stays connected behind VPNs and firewalls. On networks with always-on VPNs or middleboxes, idle connections to the control plane could be dropped silently and stall renewals. The agent now uses connection keepalives, request deadlines, automatic reconnection, and bounded request timeouts, so it detects these stalls and recovers on its own.
Recovers after sleep/wake. Laptops resuming from sleep before the network is ready could fail to set up certificates until the next sleep/wake. The agent now retries setup automatically on its normal cycle.
Windows
Machine-scoped TPM keys. Fixes Windows agents that could fail to create TPM-backed keys while running as a system service, and adds support for machine-scoped TPM keys so attestation and certificate storage work correctly in that context.
Hardware-attested Wi-Fi. Windows Wi-Fi profiles that use hardware-attested machine certificates now authenticate correctly.
Also: corrected garbled CLI output in Windows consoles (e.g. PowerShell), more reliable handling of multiple hardware-attested certificates during renewal, and a more robust service stop/remove path during upgrades and reset.
Linux
More reliable Wi-Fi and Ethernet (802.1X). NetworkManager and wired (EAPoL) 802.1X now use PKCS#11 to access TPM-backed keys, and renewed certificates are reliably reloaded into the network stack so new credentials take effect immediately. Enrollment also no longer fails on key stores that don't support machine-scoped keys.
osquery / Fleet
Packaged osquery extension. The osquery extension is now distributed as native packages for Linux (deb, rpm, Arch) and as an MSI for Windows.
Additional fixes
- Fixed a crash in the certificate renewer.
resetnow runs every cleanup step and reports all errors instead of stopping at the first failure.- Fixed key-store URI handling on macOS.
Upgrading
No action required. Windows devices automatically migrate to machine-scoped TPM keys during upgrade, re-enrolling each device under the same hardware identity.
Last updated on September 23, 2026
Introducing
Device Identity
Ensure that only company-owned devices can access your enterprise's most sensitive resources.