- Fixed security issues in cert auth: OCSP response issuer/serial validation and fail‑open handling for unreachable OCSP servers.
- Improved cert auth OCSP validation (support for responses without NextUpdate and caching) and enterprise core seal rewrap handling.
- Resolved bugs: audit header reload on replication, plugin register CLI error on missing images, login deadlock, identity alias duplication in replication, and UI path/role tab fixes.