| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-11 | 5.1 kB | |
| v1.11.2 source code.tar.gz | 2026-09-11 | 9.0 MB | |
| v1.11.2 source code.zip | 2026-09-11 | 9.6 MB | |
| Totals: 3 Items | 18.6 MB | 0 | |
2026-09-11 - Kanidm 1.11.2- Patch (Security: Moderate)
This update resolves 1 security issue which may cause auth confusion in some very specific client LDAP applications. We have no evidence that this is in active exploitation, and the configuration required is rare.
- Security - Moderate: On a failed LDAP bind the connection state should move to anonymous. Kanidm retained the former bind state instead. This may confuse some LDAP client applications that bind as a service account first, then bind as a user to validate the credentials. It is unlikely this would allow authentication bypass.
2026-08-14 - Kanidm 1.11.1- Patch (Security: Moderate)
KNOWN ISSUE: This version contains an issue where on a fresh install you may receive an error message such as:
WARNING: index PrimaryCredential Equality was not found. YOU MUST REINDEX YOUR DATABASEFollowing the steps for database reindexing will allow you to proceed without further error.
This update resolves 1 security issue which may allow denial of service by an unauthenticated user. We have no evidence that this is in active exploitation.
- Security - Moderate: LDAP BER messages were length checked too late, allowing an attacker to create a large BER message to send to the server which could cause out of memory or DoS. NOTE: Contrary to other similar issues previously, this requires greater attacker resources to conduct which is why it's severity is lowered from HIGH to Moderate.
- Correct an issue with HTTP status codes on OAuth2 responses
- Handle an existing tls session cache dir in radius containers
- Expand what characters are allowed in OAuth2 scopes
- Improve the JS guard around webauthn interactions to prevent spurious console messages
- Resolve an incorrect URN in OAuth2 AccessTokenResponses
- Correct a possible deadlock in test cases
- Resolve replication certificate renewal timeout mishandling
2026-08-02 - Kanidm 1.11.0
This is the latest stable release of the Kanidm Identity Management project. Every release is the combined effort of our community and we appreciate their invaluable contributions, comments, questions, feedback and support.
You should review our support documentation as this may have important effects on your distribution or upgrades in future.
Before upgrading you should review our upgrade documentation
1.11.0 Important Changes
- Passwords now have a max length of 128 UTF-8 characters (512 bytes). This is to prevent a rare class of denial of service during authentication requests.
- rlm_kanidm has been rewritten from python to rust. This greatly improves performance. No configuration changes are required for the container.
1.11.0 Release Highlights
- Security - High: SCIM Filter parsing had an incomplete fix for the previous parsing depth vulnerability. This meant that specially crafted queries were may allow stack exhaustion to occur leading to Denial of Service.
- Refactor early server startup logic to better handle early server shutdowns (#4468)
- Properly use Json types in some responses so that mime types are set correctly (#4480)
- Minor internal attribute syntax tidying (#4439)
- Improve credential update sessions to better indicate when a save is required (#4338)
- Add missing service-account manager attributes for search (#4381)
- Allow custom radius attributes in rlm_kanidm (#4370)
- Add live password feedback in forms (#4348)
- Limit password max length (#4442)
- Fix incorrect processing in bindmount logic that would cause errors when the mount already existed (#4433)
- Add missing attributes for the migration access checks (#4387)
- Add a missing alias for bindmount in unixd tasks (#4398)
- OAuth2 security hardening (#4380)
- Return unique ldap attributes even if requested multiple times (#4364)
- Move schema from the DB to memory (#4315)
- Add support for oidc max-age and prompt=login (#4336)
- Resolve an incorrect handling of commit flags in unixd transactions
- Prevent double deletes in some migration use cases
- Refactor of access control paths to remove some code duplication
- Revert OAuth2 JWT ClientID header which broke some clients (#4334)
- Allow SMTP urls in mail-sender (#4335)
- Remove debug symbols in release builds (#4319)
- Replace rlm_python with rlm_kanidm (#4179)
- Fix copy-paste of TOTP removal prompt (#4314)
- Resolve a mishandling of some webauthn fields being encoded with the wrong base64 padding options (#4312)