PrivX 45 Release Notes
45.0
2026-09-30
PrivX 45.0 is a major release with new features. Starting with this release, we provide security and stability fixes for three PrivX major versions: 45.x, 44.x, and 43.x. Older versions are not officially supported.
The following upgrade paths to this release are supported:
- Upgrade with downtime from versions 42.x, 43.x, and 44.x
- Zero-downtime upgrade from version 44.x
The latest PrivX LTS version is 43.2.LTS.1:
PrivX LTS releases follow a separate support lifecycle. For LTS release dates and support periods, see PrivX LTS.
Release Considerations
API Target IPv6 format changed (since v44)
API target endpoints must enclose IPv6 addresses in square brackets. For example, use [3fff::1] instead of 3fff::1.
After upgrading to PrivX 44 or later, update any existing API targets that use unbracketed IPv6 addresses.
HSM ECDSA enabled by default (since v43)
HSM-backed ECDSA support is enabled by default in new deployments of PrivX 43 and later. Upgrading an existing deployment from an earlier PrivX version do not enable ECDSA automatically. For more information, see HSM ECDSA Support.
Upgrade Considerations
Before upgrading, review your PrivX deployment’s typical resource utilization and provision additional resources for the PrivX hosts if needed. For deployments with limited or infrequent RDP or Web connection usage, or sufficient resources to accommodate the increases described below, no additional action is required.
Increased Resource Requirements for RDP and Web Connections
As part of required dependency management, PrivX 45 upgrades Guacamole, FreeRDP, and OpenSSL, which are used for RDP and Web connections. PrivX uses maintained versions of these open-source packages that include recent high-priority security patches. These updates also improve RDP connection quality and the live user experience.
As a result of these required upgrades, audit-trail size, CPU usage, and memory usage are expected to increase for the same connection activity and duration with the default settings.
Using Default Settings
By default, Enable RDPGFX is disabled and Session Recording Quality is set to Full. With these defaults and Session Recording enabled, the expected increases are up to:
- A 10× average increase in audit-trail size.
- A 2× average increase in CPU usage and 50% average increase in memory usage for RDP connections.
- A 50% increase in connection-establishment time for RDP connections.
- For Web connections using the RDP protocol:
- A 7× average increase in CPU usage, with a 7.8× increase in peak usage.
- A 3× average increase in memory usage, with a 2.5× increase in peak usage.
Reducing Audit-Trail Size
If your environment has sufficient available CPU and memory capacity during regular activity, including peak hours, but insufficient storage capacity, you can reduce audit-trail size at the cost of increased CPU and memory usage.
Setting Session Recording Quality to Medium results in:
- A 4× average increase in audit-trail size.
- A 65% average increase in memory usage for RDP connections.
- For Web connections using the RDP protocol:
- A 6× average increase in CPU usage, with a 3× increase in peak usage.
- A 3× average increase in memory usage, with a 3× increase in peak usage.
Setting Session Recording Quality to Low results in audit trails that are 50% larger than in PrivX 44, while CPU and memory usage remain the same as with Medium.
Using VNC for Web Connections
For Web connections, you can use the VNC protocol if the target supports it. Compared with Web connections using RDP in PrivX 44, this results in no increase in CPU usage and an 80% average increase in memory usage, with a 50% increase in peak memory usage.
For instructions on configuring Session Recording, Enable RDPGFX, and Session Recording Quality, see Session Recording.
Deprecation Warnings
privx-agent discontinued (since v44)
Starting with PrivX v44, we no longer release new PrivX Agent versions. Existing PrivX Agent versions will continue to work with PrivX APIs. However, we will no longer provide fixes for breaking changes introduced in this or later PrivX versions.
HAProxy as the preferred Ingress Controller (since v44)
The current preferred Nginx Ingress Controller is being retired. Starting with PrivX v44, HAProxy becomes the preferred Ingress Controller.
In the future, we plan to move PrivX to the Kubernetes Gateway API instead.
Kyber KEX to be deprecated
The Kyber algorithm has been superseded by the NIST-standardized ML-KEM algorithm. For this reason, the KEX suite ecdh-nistp521-kyber1024-sha512@ssh.com may be removed from the default algorithms list in a future PrivX release. Migrate to the mlkem1024nistp384-sha384 KEX suite. PrivX will continue to support ecdh-nistp521-kyber1024-sha512@ssh.com until further notice.
PostgreSQL versions end-of-life
Support for end-of-life PostgreSQL versions will be dropped as follows:
- PostgreSQL 12, 13: End of 2026.
- PostgreSQL 14: Q2 2027.
If you run PrivX with any affected PostgreSQL version, start preparing for a database upgrade.
New PrivX versions may continue to work with EOL PostgreSQL versions even after support is dropped. However, we do not provide fixes for compatibility issues with these database versions.
SHA-1 deprecated in native RDP connections
TLS SHA1 is disabled by default in Go. This can cause probing for target RDP host certificate to fail when connecting with native RDP client through RDP Bastion. As a workaround, you can add GODEBUG=tlssha1=1 to PrivX microservices' environment variables, enable Use legacy cipher suites for legacy RDP targets, and restart RDP Bastion services. Note that this GODEBUG will be removed by upstream in the near future. TLS SHA1 is unsafe and the proper fix should be to deactivate it in target Windows server(s).
New Features
- [PX-3443] Configure PrivX to warn users about ongoing RDP session for the same target account. Users can cancel the new connection or continue and terminate the existing session.
- [PX-4430] Configure PrivX to prompt users for a connection justification, which can be enabled through:
- [PX-8772] the host-deployment script with the
--enable-justificationflag. - [PX-8767] the
privx-justify-connhost tag.
- [PX-8772] the host-deployment script with the
- [PX-6849] Approve or deny role requests with PrivX Authorizer.
- [PX-7747] Configure separate ICAP scan directories for SSH Proxy and SSH Bastion.
- [PX-8402] HSM configuration: allow PrivX Servers to use local secrets for cryptographic operations, instead of referring to HSM each time.
- [PX-8482] Rotate and check out passwords for web-target accounts using customer-defined scripts executed on a designated rotation server.
- [PX-8577] A cryptographic bill of materials (CBOM) for PrivX is now available on request.
Improvements
- [PX-7865] Upgraded Guacamole and related dependencies to improve RDP and VNC rendering performance. Added dynamic display resizing and improved clipboard handling for VNC connections. The dependency updates also include security fixes. Before upgrading, review Upgrade Considerations.
- [PX-8555] Various improvements to installation and upgrade scripts.
Bug Fixes
- [PX-3086] Fixed an issue where PrivX role rule mapping incorrectly treated wildcard ('') DN filters as separate conditions, which resulted in excessive matches.
- [PX-8354] When all Carrier ports are occupied, trying to start a new connection no longer crashes the Carrier docker service.
- [PX-8594] Client-certificate authentication now works in PrivX deployments on Kubernetes. Note that Kubernetes uses port 8444 for this, not 8443.
- Client-certificate authentication on Kubernetes still breaks after rolling back from v45 unless you manually back up Nginx configurations before upgrading to v45, as described in the documentation in the PrivX Kubernetes Git.
- [PX-8716] The validity period of PrivX Nginx TLS certificates generated by
init_nginx.shhas been reduced from 398 days to 200 days. - [PX-8743] For users with Expire Implicit Roles enabled, their implicit roles are no longer expired after User Purge Delay After Last OIDC Login.
- [PX-8751] Correctly show target FQDN in connection view.
Known Issues
- [PX-1711] RDP fails to connect to the target in maintenance mode; support for the
/adminflag is needed. - [PX-1835] Extender, Carrier, and WebProxy configs are not migrated during upgrade
- [PX-1875] Web proxy login does not work if the login page sends requests to multiple domains.
- [PX-2947] No sound when viewing a recorded RDP MITM connection.
- [PX-3529] The default access-group CA key is always copied to the host when running the deployment script through Extender.
- [PX-3655] RemoteApp cannot be restored after it is minimized.
- [PX-4218] RDP native clients do not work in a Kubernetes environment when running under a non-root account.
- [PX-4352] The UI shows a deleted local user after deletion.
- [PX-4662] Pasting large amounts of text in a Carrier or Proxy host fails (currently limited to 16 kB).
- [PX-4778] RDP Proxy: a file being scanned cannot be overwritten.
- [PX-4809] Empty files are created when ICAP detects malicious uploads with SCP through SSH Bastion.
- [PX-5558] PrivX does not support the password-change-required option for users in the passkey authentication flow.
- [PX-5587] Live playback of WEB connections no longer stays in live mode after the user closes the Carrier browser.
- [PX-8190] Backup and restore scripts do note retain Nginx configuration.
- [PX-8191] Extender V2 (in normal mode) status is Unregistered even after successful registration.
- [PX-8220] Some special layouts do not work as expected in web-target connections.
- [PX-8822] After a password rotation failure, a new rotation request may not start immediately, even after the configuration has been corrected. The request will be processed once the existing retry cycle completes. This behavior will be improved in the next release.
Notable API Changes
- GET /license-manager/api/v1/mobilegw/status return data has changed. If you have automations relying on this endpoint, we strongly suggest verifying and adjusting them against the current API specification.
- POST /auth/api/v1/token/login now requires JWT tokens to include valid
iatclaims. For more information about the required claims, see Prerequisites for JWT Authentication.
Notable Documentation Changes
Documentation is updated as needed and may change between releases.
| Date | Article | Description |
|---|---|---|
| 2026-09-30 | Site-wide update | New color themes for better distinction of hyperlinks and active article in the TOC. |
| 2026-09-30 | LDAP Errors: Size Limit Exceeded or Time Limit Exceeded | New troubleshooting article for adjusting LDAP administrative limits. |
| 2026-09-30 | Script-Based Certificate Authentication | Article rewritten for better clarity. Documented the --enable-justification option. Updated the privx-justify-conn tag syntax and examples. Added missing host tags privx-web-principals and privx-trust-on-changed-host-keys. |
| 2026-09-30 | Key Storage Locations with HSM | New article describing options for PrivX with HSM to store some keys locally, which can improve PrivX performance. |
| 2026-09-30 | ICAP Servers | New section Configuring ICAP Scan Directories to describe how to configure separate temporary ICAP scan directories for SSH Proxy and SSH Bastion (icap_scan_directory). Updated the SSH file-handling description in the File Transfers Over SSH section to cover configured scan directories (ICAP Scanning → Enabled). New paragraph to document Internal ICAP scanning error reporting and configurable SSH channel termination for SCP and SFTP file transfers through SSH Bastion. General improvements: improved terminology, formatting, and screenshot presentation. |
| 2026-09-30 | Setting Up Hosts | New section Connection Justification to describe how to configure the connection-justification prompt and enable justification for individual host services. New subsection Warning Users About Ongoing RDP Sessions describing how to enable warnings for shared RDP accounts, how PrivX handles the user's response, and the feature limitations. General improvements: standardize UI terminology, navigation paths, formatting, and active instructional wording. |
| 2026-09-30 | Rotating Stored Passwords | New documentation for setting up a dedicated server for rotating passwords. New example for setting up password rotation and password checkout for web-target accounts. |
| 2026-09-30 | Google Cloud Platform as Host Directory | Clarified that PrivX supports service-account credential JSON only for Google Cloud host directories. Clarified that PrivX host tags are stored in VM metadata and are not Google Cloud network tags. General improvements: updated action-oriented headings. |
| 2026-09-24 | Host Directories | Updated sub-article titles under Host Directories to omit articles (a/an). Note the article URLs have also changed. |
| 2026-09-30 | Quick PrivX Setup, Setting Up PrivX Components | Add to the Quick PrivX Setup article information about the reduced validity period of TLS server certificates generated by init_nginx.sh. Add to the Setting Up PrivX Components article a new section Managing TLS Server Certificates with general guidance. |
| 2026-09-30 | Preparing for Setup, Quick PrivX Setup, Setting Up PrivX Components | Articles updated with information to use the latest PostgreSQL version supported by both your OS and your PrivX release. |
| 2026-09-30 | Deployment, Deploying PrivX, Cortex XSOAR | General improvements: restructure deployment and integration documentation, add overview pages, and improve wording and navigation to help users find the instructions they need: The Overview file was renamed to Deployment and is now a parent page. Setting Up PrivX Components was moved under the new parent page Deploying PrivX, which brings together installation, upgrade, and uninstallation instructions. The parent page also includes the deployment overview diagram. Inside Setting Up Components consistent headings were applied, clearer descriptions. Get PrivX Software was renamed to Getting PrivX Software to follow the gerund-based heading style. All pages related to cloud deployment are now under Deploying PrivX in Cloud Environments. Deployment now has a clear structure: release notes, preparing for deployment, getting the software, general deployment on premises, cloud deployment, and then high availability. Integrating PrivX With XSOAR was renamed to Cortex XSOAR and moved under Integrations. |
| 2026-09-24 | Session Recording, PrivX Settings, Connecting with PrivX Web UI | The user-visible effects of the RDP and VNC upgrade: RDPGFX, VNC resizing, and recording-storage. Updated description for the Enable RDPGFX setting in the PrivX Settings article. New section Planning Resources for RDPGFX Connections in Session Recording with information on how to plan resources. In the Connecting with PrivX Web UI article, new information on VNC resizing during an active connection. |
| 2026-09-30 | Post-Quantum Cryptography Readiness | New FAQ article answering questions related to PQC support in PrivX. |
| 2026-09-30 | PrivX Authorizer, Multi-Factor Authentication with PrivX Authorizer, Role Request Approval with PrivX Authorizer | Added the PrivX Authorizer overview, Role Request Approval with PrivX Authorizer, and Enabling Mobile Approval articles, covering app setup, device subscriptions, role request decisions, and workflow configuration. Updated Multi-Factor Authentication with PrivX Authorizer and Requesting and Approving Role Memberships with mobile approval instructions. |