Topicus KeyHub 51 rebuilds the vault record screen around a proper read-only details page, brings hybrid Active Directory and Microsoft Entra ID setups together under a single source provisioning system, and puts the entire web console through a WCAG 2.2 AA accessibility sweep. Group synchronisation with linked systems got considerably faster along the way, and there is a long list of fixes besides.
Important notices
SAML single sign-on and single logout
TKH-4028 Incoming SAML logout messages are now validated in full, including authentication of the sender. That means a service provider has to sign its LogoutRequest. A service provider that sends an unsigned or otherwise invalid logout message will find that single logout no longer works.
TKH-3995 The NameID format Topicus KeyHub sends now follows the subject format configured on the application instead of echoing whatever the service provider asked for. An e-mail address is labelled as an e-mail address, a username or UPN as unspecified, and only the opaque identifier is still labelled persistent. The identity provider metadata advertises every format Topicus KeyHub can produce, so there is nothing left to guess.
Both changes affect how your service providers interact with Topicus KeyHub. After upgrading, please test single sign-on and single logout against each of them.
Vaults and vault records
The vault record screen has been rebuilt, and a cluster of changes around it makes vaults easier to navigate, share and tidy up.
-
TKH-1744Topicus KeyHub keeps track of when a vault record's secret was last read and shows that moment on the record's own page as "Last read", followed by the record's audit log. Opening the details does not itself count as a read, so checking whether a record is still needed never disturbs the answer. The vault overview gained a "Sort on last read" ordering, which gathers the forgotten records at the bottom ready for a clear-out. -
TKH-2390Every shared copy of a vault record shows its own UUID next to the vault it lives in, even when you have no access to that vault, and the copy itself shows the UUID of the record it came from. One click puts either on the clipboard, which saves a good deal of hunting when your infrastructure-as-code addresses records by UUID. -
TKH-3267Group vaults have gained a copy button next to their name that puts a link to that vault on the clipboard. Whoever opens it lands on the vault overview filtered to that single vault, with any search term you had active carried along, so "the records I mean are over here" is now one link instead of a paragraph of directions. Personal vaults have no such button, since nobody else could open the link anyway. -
TKH-3402Clicking a vault record opens a read-only details page rather than dropping you straight into the edit form. Secrets are still revealed and copied from there, and the "Edit" link in the top right corner takes you further when you really do want to change something. Moving, copying and sharing a record have moved to its "Shared with" block. -
TKH-3908The moment a record's secret was last read is available on the record in the API, and record queries can sort on it, with never-read records sorting oldest. The timestamp is written without touching the record itself, so a concurrent edit is never tripped up by someone reading it. -
TKH-3947The "Select a vault..." filter on the vaults page only offered group vaults, so if the same account turned up in several groups as well as in your own vault, there was no way to narrow the list to your own records. Your personal vault now sits at the top of that filter. -
TKH-3997Some follow-up polish after the redesign. In the "Shared with" block, the vault a record is shared with is a real link when you are allowed to open it and grey, inert text when you are not, so you can see at a glance where clicking will get you. In the browser extension, the pencil on a vault record row became a look-up icon, a better match for the read-only page it now opens.

Vault record details
Microsoft Entra ID
The Microsoft Entra ID integration received the largest body of work in this release, covering hybrid directory setups, the first sign-in after activation, and a great deal of reliability work underneath.
-
TKH-3589A source provisioning system can now reference an LDAP directory and an OIDC directory at the same time, which covers the setup where accounts are maintained in an on-premise Active Directory, Entra Connect mirrors them into Entra, and users authenticate at Entra while Topicus KeyHub assigns both Active Directory groups and Entra groups and directory roles. Because one system serves both directories, an existing hybrid configuration can be migrated one account at a time without interrupting provisioning. -
TKH-4007Activation writes the new password to Microsoft Entra ID, which then refuses it for the next few minutes, so the very first sign-in used to end on "your account or password is incorrect". Topicus KeyHub now shows a single-use code for that first sign-in, requested from Entra at the moment the user needs it, and a registration that stops halfway can be picked up again from the activation link instead of leaving the user stranded. Issuing the code requires theUserAuthMethod-TAP.ReadWrite.Allapplication permission and the Temporary Access Pass authentication method enabled in your tenant's authentication methods policy; without those, activation still succeeds and the user signs in with the password they just chose. -
TKH-4008Work on a fresh test tenant turned into a thorough reliability pass over the Entra integration. Writes that were retried went out with an empty body and quietly changed nothing, a delete could miss the object it meant to remove and leave the name reserved, and lookups trusted a directory search index that lags behind reality, so an account that existed could be reported absent and one long gone reported present. Users are now addressed by the object id Entra knows them by wherever Topicus KeyHub has it, and a lookup that falls back to the index is confirmed against the freshest view before it is believed.

Temporary access pass during activation
Provisioning and identity sources
Synchronisation with linked systems is faster, more accurate about who belongs to what, and better behaved when something it depends on is unavailable.
-
TKH-3967Some SCIM services reject filter operators written in uppercase, even though the standard says the case does not matter, and that stopped synchronisation dead at the very first account lookup. A provisioned SCIM system can now be told it "Uses lowercase filter operators", and a new Atlassian preset switches that on for you. -
TKH-3968Topicus KeyHub worked out which groups an account belongs to by filtering a SCIM service's Groups endpoint on its members, which services that only allow filtering groups by name cannot answer at all. Turn off "Supports filtering groups by member" and Topicus KeyHub reads every membership of the service in one pass and works the memberships out itself, provided the service "Returns group members when listing groups". Saving a system with group support but no route to the memberships is now refused rather than failing halfway through a sync. -
TKH-3970An account disabled on a target system was treated as a member of no groups at all, so on connections where deprovisioning disables the account rather than deleting it (Active Directory, Azure tenant and SCIM), expired group memberships were left behind and no later synchronisation cleaned them up. They took effect again the moment the account was re-enabled for any reason. Memberships are now reconciled on whether the account still exists on the system rather than on whether it is enabled, and the audit trail records each removal. -
TKH-3971When a group membership reached its end date, the membership was removed and audited but the follow-up work was quietly dropped: connected systems were not synchronised, vault records shared through the group stayed shared, and OAuth2 tokens issued for that membership stayed valid. Expiry now completes all of that straight away. -
TKH-3977A full synchronisation used to ask a linked system the same question once per account: which groups is this account in? Systems that can hand over every membership in a single query, such as LDAP, Active Directory and many SCIM services, are now read once for the whole system and the rest of the sync is answered from that, so a sync over a large directory does a fraction of the talking it used to. Each system declares what it is capable of, and for SCIM you say so with the "Returns group members when listing groups" option. -
TKH-3990While the attribute script engine was unreachable, a script-backed custom attribute looked simply empty, and every synchronisation dutifully cleared it on the target system, whether that was Entra ID, LDAP, Active Directory or SCIM. Topicus KeyHub now tells "this account has no value" apart from "the value could not be worked out": an attribute that cannot be resolved is left exactly as it is on the target and the failure is written to the provisioning log. Only the attributes that name or locate the account, such as the username or the distinguished name, still fail the operation, because there is no safe way to write without them. -
TKH-4001Accounts provisioned into Active Directory can be given the "Account is sensitive and cannot be delegated" flag, so a Kerberos ticket for such an account cannot be reused to move sideways through the network. Because the opposite is an equally valid setup on the very same system, this is opt-in per linked system through a custom attribute named userAccountControl.notDelegated, which takes a boolean and can be worked out by an attribute script. -
TKH-4011An AFAS identity source can be given an "Account identifier": a unique, single-valued, mapped attribute that Topicus KeyHub uses to look up an incoming identity. When it matches, the identity is merged into the existing account and that account is linked to the identity source, instead of a duplicate turning up among the pending accounts. Without an identifier the old behaviour stands, and a value that matches more than one account is rejected rather than guessed at. -
TKH-4040After changing a password in the directory and synchronising it in Topicus KeyHub, group activation on a source directory kept coming back with "configuration required", and the password prompt it sent you to quietly discarded what you typed. Accounts on a system Topicus KeyHub is not allowed to write to are no longer marked as having an unset password, and accounts already stuck in that state are repaired during the upgrade.
Accessibility
Topicus KeyHub has been measured against WCAG 2.2 AA and brought up to it, across the web console and the appliance manager alike.
-
TKH-4029Colours that missed the 4.5:1 contrast ratio have been raised, focus rings are visible and correctly shaped on every control, form fields are properly tied to their labels and error messages, status signals no longer depend on colour alone, and every button, select and table gives a screen reader something sensible to announce. An axe-core scan runs over every page and dialog the test suite opens, so accessibility regressions are caught long before they reach you. -
TKH-4032Several tables on the access profile page were close to unusable on a phone: every cell carried an expand button of its own, opening one row made those buttons overlap the whole panel, and the values that appeared gave no clue which column they came from. A collapsed row now has a single expand control in the name column, and stacked values carry their own label, icon actions included. Fourteen tables that had quietly inherited the collapsing layout were reviewed and given the responsive behaviour that actually suits them. -
TKH-4034Table cells that are themselves an action, such as a delete icon or the link to a vault record's URL, announce as links again, so screen reader users find them through link navigation instead of hearing a table cell with nothing to say. The icon actions in tables are also properly focusable and fire on Enter. -
TKH-4049A new version of the browser extension was released for all supported browsers with the same accessibility improvements included.

New colours on the vaults page
Infrastructure and dependency upgrades
-
TKH-3546The appliance host firewall now runs natively on nftables, the supported stack on AlmaLinux 9. The whole ruleset loads in one atomic transaction and lives in its own table, so changing the firewall zones from the Management Console no longer restarts the container stack. The management, monitoring and backup zones behave exactly as before. -
TKH-3659Topicus KeyHub now declares PostgreSQL version 18 to its persistence layer, matching the database that every supported appliance actually runs. -
TKH-3976The JavaScript libraries that used to live as copies inside Topicus KeyHub now come from managed dependencies, which keeps them on a supported version automatically, and one library that nothing used at all was dropped. The multi-select filters, such as the audit log type filter and the directory filter on account cleanup, moved to the same search-as-you-type dropdown used elsewhere and no longer tower over the fields next to them. -
TKH-3986The appliance boot image carries the NVMe and ENA drivers, so the appliance boots under its own power on current AWS EC2 hardware, where the root disk is presented as an NVMe device. Until now that only worked because AWS quietly repaired the image during one particular import path; uploading the disk directly left you at an emergency prompt. -
TKH-3987A cluster node published its failure-detection port from the range the operating system also hands out to outgoing connections. On rare occasions that port was already taken when the application container started after a reboot, the container refused to start, and the node stayed down until someone stepped in. The port has moved below that range, which removes the clash entirely. -
TKH-3999Push notifications to the Topicus KeyHub app for iOS are authenticated to Apple with a signing key that does not expire, replacing a certificate that had to be renewed by hand every year. Push messages Apple rejects are now recorded in the log instead of vanishing.
Assorted improvements
The following improvements and bug fixes both large and small were made:
-
TKH-3643Group exclusions can be supplied in the same call that creates a group through a client, so an automation run can declare a separation of duties up front instead of waiting for a separate exclusion request to be approved. If the new group would contain someone who is already in an excluded group, the call is refused with a conflict rather than silently removing that person. -
TKH-3846Access profiles show their audit log on the details page, most recent records first, with a link through to the full searchable log, exactly as groups and accounts already do. The audit panel on the account details page came up empty for viewers without full audit log access, and now shows what they are allowed to see. -
TKH-3868The header of every object details page has gained a copy button for the object's name. For a group on system that name is the CN you need to remove the group on the linked system, which until now had to be retyped by hand. -
TKH-3923On an access profile, a predicted transition could be cut off halfway through its date, and rows under "Upcoming and recent transitions" were still worded in the present tense after the transition had happened, so a departed member read "Is removed". Columns now share their width more sensibly, dates follow the locale, and transitions in the past read as past. -
TKH-3963On the auditor dashboards the A-Z strip above the table kept the letters from the previous page load whenever the filter bar or a chart narrowed the selection, and clicking a letter that had meanwhile disappeared produced an error. The strip is now repainted together with the table and the charts. -
TKH-3964The letter strip on the auditor provisioning dashboard was built from the raw name a group carries in the target system, so groups identified by an object identifier each got a segment of their own and LDAP groups all piled up under the "c" of "cn=". Groups on systems are now filed and sorted under the first letter of the name you actually see, and the dashboard gained the free-text search box the other three auditor dashboards already had. -
TKH-3969The License CLI now generates files ending in ".keyhub" instead of ".txt", so a browser offers them as a download instead of opening them in a tab. Files already issued as ".txt" keep working. -
TKH-3972Activating a group immediately after re-entering your password could fail with the generic error page, because the repair work that runs when a vault unlocks and the activation itself were writing the same records at the same instant. Those repair tasks now wait until the account has been quiet for a couple of seconds. -
TKH-3974Adding someone to a group used to stamp "group last used" with that day's date, so a member who had never so much as opened the group looked like its most active user. The date stays empty until the member really uses the group, and never-used memberships sort as the oldest whichever way you sort, which is exactly what you want when auditing a group for dormant members. -
TKH-3978Opening an account's details could end in an error page when the account still carried an identity value from before Topicus KeyHub validated these fields, for example a telephone number consisting only of spaces. Upgrading to version 51 sweeps through the accounts and tidies those values up: anything still parseable is written back in normalised form, and only genuinely unusable values are cleared and reported as missing for an administrator to fill in. -
TKH-3981The key pair that encrypts the appliance's backups is generated during installation, and if that generation went wrong it did so in silence: the wizard finished green, the administrator downloaded an empty key file, and from then on every configuration change was refused with an error nobody could act on. Generation no longer depends on the step that failed, and a key pair that did not come out right stops the installation instead of sailing past it. -
TKH-3983Starting to approve a request, cancelling, and then declining it after all ended in an error instead of a declined request. The console builds the approval details only when the request is actually being approved, and the reject link in the notification e-mail no longer asks for approval-only fields either. -
TKH-3984Creating several vault records in one call against a personal vault that did not exist yet could fail with a server error and roll the whole batch back. Every record in such a batch now lands in the vault that the first one brings into being. -
TKH-3985Reading the plaintext secret of a vault record over the API requires a step-up to strong authentication, but a client that asked for the secret using the bracketed spelling of the additional-objects parameter slipped past that check. Both spellings are now recognised, so an integration using the bracketed form will receive a step-up requirement where it previously received a secret. -
TKH-3993An API request that referred to another object by name but forgot its link answered with a server error rather than telling the client what was wrong. Such a request now comes back as a bad request naming the missing property. -
TKH-3994Group nesting has never mixed with group exclusions, with delegated management, or with an authorising group for membership, but creating a group through the API was the last route that skipped those rules. Group creation now applies the same checks as a nesting request, including the rule that a nested group and its parent share an organisational unit, and reports the same errors. -
TKH-3998A directory with no accounts in it showed no accounts block at all, which was hard to tell apart from a section that had failed to load. The block stays put and simply says there are no elements. -
TKH-4004Creating a password recovery request demands credentials no older than five minutes, but the prompt blamed the four-hour timeout and claimed a password check from seven minutes earlier had expired. Prompts caused by that short window now simply state that reauthentication is required for this action, while a credential that really has lapsed, or a session seen from a different IP address, keeps its own accurate message. -
TKH-4005A carefully shaped URL could talk the handler that serves the web console's static assets into returning other files from the application's classpath. It has been replaced by a hardened version that resolves a request for where it actually lands rather than for how it looks; the asset URLs themselves are unchanged. -
TKH-4006Adding a node to a cluster could abort with "The status of the database has changed." when pgpool briefly attached the new node's still-empty database, and the step that failed then sat on a spinner forever without ever showing the message. A join no longer applies the state check that belongs to the administrator's repair action, and a failed step now reports what went wrong. The cluster overview also gained a "Database empty" problem, so a node whose database holds no Topicus KeyHub data is named for what it is. -
TKH-4009The record type filter on the audit log crammed its long labels onto three or four lines. The dropdown now sizes itself to its content, and while we were in there every select list in Topicus KeyHub grew to show roughly ten options at a time instead of six. -
TKH-4030The group on systems export took the organisational unit from the provisioned system rather than from the owning group, so a centrally registered system pinned every single row to the root organisational unit. The export now reports the owner's unit, which is what the dashboard, the permission checks and the audit log were showing all along. -
TKH-4031Of the four exports on the auditor provisioning dashboard, only "Group on systems" produced anything for an auditor whose role is scoped to an organisational unit; the other three handed back a CSV with nothing but a header. All four now return the rows the auditor is entitled to. Auditing an organisational unit also no longer reaches up into its ancestors, so the dashboard and its exports show exactly the units you audit and nothing more. -
TKH-4035An access profile rule run that removed members could collide with itself and roll back, leaving the accounts in the profile as though nothing had happened. Memberships and their predicted changes are reconciled in one place per run, so an account the match rule no longer accepts really does leave the profile. -
TKH-4037Adding a security key shortly after registering could leave you with a registered key that had no vault unlock and no way to add it later. When a key exists only to unlock the vaults, Topicus KeyHub now opens the vaults first and registers the key afterwards, and a failed linking step can simply be retried rather than leaving something half-configured behind. Activation by way of a directory now also passes through the two-factor setup step where the optional vault unlock key is offered; that step used to be skipped on that route. -
TKH-4076The authenticator now correctly resolves over 100 SAML2 clients for authentication. Similar restrictions were lifted in a few other places throughout the application.
