AgileSec 3.6 Release Date: July 7, 2026
AgileSec 3.6.1 Release Date: August 3, 2026
We are pleased to announce the general availability of AgileSec 3.6 and AgileSec 3.6.1.
Table of contents
- What's new in AgileSec 3.6
- What's new in AgileSec 3.6.1
- Recommended upgrade path
- Documentation
- Support
What's new in AgileSec 3.6
AgileSec 3.6 is a stabilization and hardening release. It builds on the unified data model introduced in 3.5, focusing on platform security, operational simplicity, and sensor reliability rather than introducing a new data architecture.
Platform and UI:
- Updated UI layout aligned with Keyfactor branding guidelines, with usability refinements throughout the interface
- Improved Remote Sensor history view and Remote Sensor download experience
Performance and scalability
- CBOM exporter now uses asynchronous fetching, increasing export performance
- Policy execution improvements reduce timeouts when policies run against large data sets or under high load
- Sensors and connectors now target a configurable memory limit, preventing unbounded memory growth and improving overall system stability and resource predictability
- Cross-cluster search is now supported for OpenSearch, enabling search across multiple OpenSearch clusters
Security enhancements
- Document-level security for findings data through role-based access control (RBAC)
- Identity provider (IdP) groups are now surfaced as OpenSearch backend roles, improving SAML group mapping
- RSA4096 key support for the Secrets Manager (SM) service
- Hardened password policy, with the following configurable options:
- Minimum password length of 14 characters
- Account lockout for 15 minutes after 5 failed login attempts
- Limits on password reuse
- Required complexity: at least one uppercase character, one number, and one special character
- Hardened HTTP headers (Content Security Policy, CORS, cache control, and server information disclosure)
- Hardened HAProxy configuration
Kubernetes and installation improvements
- AKS and EKS deployments no longer require separate Helm charts. A single unified chart now covers both environments, simplifying Kubernetes-based installations
- Separate systemd services are now available for all platform components
- Additional prerequisite checks added for external server certificates
- New admin password reset utility for post-install recovery
- Stricter file permissions applied to all installer files
- Log rotation enabled on all log files to prevent unbounded growth, with reduced logging verbosity across several components to decrease operational noise
Sensor and module updates
- New connector: GCP KMS. Available for platform, API, and remote scan use
- AWS KMS Connector: Symmetric key metadata is now reported in scan results
- Bitbucket Sensor: Bitbucket Data Center API v1 is now supported; new multi-branch pattern search options provide greater flexibility in repository scanning configurations
- GitHub Sensor: Updated API flow reduces token consumption, significantly decreasing the likelihood of hitting rate limits; improved retry mechanism increases resilience when rate limits are encountered; new multi-branch pattern search options
- GitLab Sensor: New multi-branch pattern search options provide greater flexibility in repository scanning configurations
- Network Sensor, Host Sensor, and Cert Store Sensor: Fully qualified domain names (FQDN) are now reported in scan results for all three sensors
- Tanium EDR: Full Tanium support in 3.6, including Connect jobs, with async mode support for run actions enabling non-blocking execution
Reliability improvements in this release include fixes to Windows host sensor stability, binary scanning of file paths and filenames containing unicode characters, Azure Key Vault certificate metadata retrieval when RBAC is enabled, GitHub and Bitbucket sensor handling of repositories with no commit history or special characters in branch names, network sensor detection accuracy for TLS 1.2 and TLS 1.3 connections, token revocation, scheduled policy execution after a fresh install, SAML role mapping when a SAML assertion contains multiple groups, and correct preservation of alert identifiers during data migration.
What's new in AgileSec 3.6.1
AgileSec 3.6.1 is a maintenance release. It introduces no new features, and focuses entirely on installer reliability, certificate handling, and refreshed bundled components.
- Root CA certificate lifetime fixed. Installer-generated Root CA certificates now honor their configured lifetime (10 years by default) for new installations.
-
Installation no longer fails on hosts with a locked-down
/tmp. Installer temporary files have moved to installer-owned directories, resolving failures on hosts where/tmpis mountednoexecor otherwise restricted. -
More accurate upgrade detection. Upgrades no longer misreport installer-managed
systemdconfiguration lines as customer-made changes, and the installer now tracks packaged component versions correctly so upgrade detection stays accurate. - Bundled components refreshed: OpenSearch 2.19.6, Node.js 22.23.1, Kafka 3.9.1-2, and OpenSearch Dashboards 2.19.5-5, along with updated service images carrying additional security fixes.
Important note for customers already on 3.6.0
The Root CA lifetime fix applies only to new installations performed with the 3.6.1 installer. If you installed AgileSec on 3.6.0 or earlier, your existing Root CA certificate was generated with a one-year expiration and upgrading to 3.6.1 does not retroactively extend it. If you're currently running 3.6.0, contact your Keyfactor Customer Success Manager or open a support ticket to confirm your Root CA's expiration date and plan for renewal before it lapses.
Recommended upgrade path
If you have not yet upgraded to 3.6.0:
Upgrade directly from your current 3.5.x installation to 3.6.1. This gets you all 3.6 features and the latest security and reliability fixes in a single step, rather than upgrading to 3.6.0 first and then to 3.6.1 separately.
If you are already on 3.6.0:
Upgrade to 3.6.1 for the latest security and reliability fixes. See the important note above regarding Root CA certificate expiration before you do.
For a fresh installation:
Use the 3.6.1 installer package directly.
If you are still on AgileSec 3.4.x or earlier:
Upgrade first to AgileSec 3.5.1 to complete the automated data migration, then proceed to 3.6.1. See the AgileSec 3.5 and 3.5.1 released article for migration guidance, or contact your Keyfactor account team for a recommended path if your environment has multi-node or stretch-cluster considerations.
No data is lost at any point in these upgrade paths, and new connectors may be run via Remote Scan without upgrading the full AgileSec platform, provided the correct configuration files are supplied.
Documentation
Full documentation for AgileSec 3.6 and 3.6.1 is available at: https://docs.keyfactor.com/agilesec/latest
Including:
- AgileSec 3.6.1 Release Notes
- AgileSec 3.6 Release Notes
- On-Prem Cross-Cluster Search Setup Guide
- On-Prem Upgrades Guide
- GCP KMS Connector User Guide
- Sensor Deployment Documentation
Support
If you have questions about this release or need assistance with your upgrade, open a ticket at Keyfactor Support or contact your Keyfactor account team.
Add comment
Please sign in to leave a comment.