Loading...

LogonBox SSPR Release Notes

LogonBox SSPR 2.4.14 – Now Available

Windows two-factor authentication

Introduction

LogonBox is pleased to announce the immediate availability of LogonBox SSPR 2.4.14.

This release includes support for Duo’s new CA certificate pinning bundle and the ability to load new server SSL certificates without requiring a server restart. The changelog at the bottom lists all new features and bugs fixed.

Duo root certificate authority bundle replacement

Duo is making changes on February 2nd 2026, that will expire their existing CA certificates and replace them with new ones.
To support this, the LogonBox server has been updated to use the latest Duo client, which supports these changes.

For further information, please see: https://help.duo.com/s/article/9451

Installing a server SSL Certificate no longer requires a server restart

Previously, when you needed to install or renew an SSL certificate for your server, you had to restart the server.
With this release, this is no longer required, and the new certificate becomes live immediately (if you replace the existing one).

All that will be needed is a browser restart to see the new certificate in use.

Upgrade Instructions

You can directly upgrade from the web UI or the operating system.

To upgrade from the web UI, log on to your admin account, navigate to Server Status from the main dashboard, and click Update. If you have Updates, Features & Licensing->Update Prompt turned on, you may also be prompted automatically upon login.

To upgrade from the operating system:

On Windows – download the new installer, run the installer, and follow the prompts.

On a LogonBox VM – from a shell, type in:

apt update
apt upgrade

If you are still running a version before 2.3, you will need to perform some extra steps from the OS, as detailed here:

https://docs.logonbox.com/app/manpage/en/article/6172513

Our support team will upgrade Cloud customers over the coming week.

Changes

Here is a summary of the changes in this release.

Features

  • Updated Duo library to support upcoming changes to Duo certificate authority expiration.
  • Updated phone number library to support the latest mobile number area codes.
  • Server no longer requires a service restart when a new SSL Certificate is updated, only a browser restart.
  • New events created to record Translation create/update/delete actions.
  • New Profile Reset events have been added in the Audit Log for individual authenticators.
  • Added new permission to delegate Profile Resets only, no longer need to grant User Update.

Bugs

  • Removing the Profile Image Support feature no longer breaks the top-right navigation menu’s justification.
  • Removing LogonBox Authenticator, Secure Node, and High Availability features no longer stops Google user directories from syncing.
  • When Password Change permission is removed from a user, the Change Password button is now also removed from the Password Information widget in My Profile.
  • Fixed a 403 error that could occur when admins log in, related to a failing dashboard graph, which is now working again.
  • Delegated admins can now reset individual authenticators for users again.
  • Fixed biometric authentication with the LogonBox Authenticator, which wasn’t working in some use cases.
  • The Authentication Flow view now updates correctly in the UI after a change is made.
  • Linked accounts are now showing the username again when you expand a user on the User Directory page.
  • Daily Profile Statistics are now being sent correctly to System Administrators (only Realm Administrators were receiving emails previously).
To top