You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/nim/releases/release-notes.md
+60-18Lines changed: 60 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,13 +34,13 @@ This release includes the following updates:
34
34
- {{% icon-feature %}} **Expanded options for configuring security policies with F5 WAF for NGINX**<aname="2-21-0-whats-new-Expanded-options-for-configuring-security-policies-with-F5-WAF-for-NGINX-45801"></a>
35
35
36
36
You can now configure additional policy settings for F5 WAF for NGINX directly in the NGINX Instance Manager web interface, including:
37
-
37
+
38
38
- Signature sets
39
39
- Signature exceptions
40
40
- Parameters
41
41
- URLs
42
42
- Cookies
43
-
43
+
44
44
For more information, see the [F5 WAF for NGINX Integration Guide](https://docs.nginx.com/nginx-instance-manager/waf-integration/).
45
45
46
46
- {{% icon-feature %}} **Added support for bot signatures management in NGINX Instance Manager**<aname="2-21-0-whats-new-Added-support-for-bot-signatures-management-in-NGINX-Instance-Manager-45827"></a>
@@ -90,21 +90,21 @@ This release includes the following updates:
90
90
- {{% icon-feature %}} **On-demand WAF policy compilation (bundle creation) in NGINX Instance Manager web interface**<aname="2-21-0-whats-new-On-demand-WAF-policy-compilation-(bundle-creation)-in-NGINX-Instance-Manager-web-interface-46672"></a>
91
91
92
92
This release adds on-demand compilation of WAF policies in the NGINX Instance Manager web interface. Pre-compiling policies helps reduce publish times and improve reliability.
93
-
93
+
94
94
Previously, NGINX Instance Manager reused compiled bundles when available and compiled policies during publish if no bundle existed. This could slow down or occasionally fail. You can now compile policies in advance so they’re ready for immediate deployment to instances or instance groups.
95
-
95
+
96
96
**What’s new**
97
-
97
+
98
98
-**Web interface support for policy compilation:** Under **WAF > Policies**, select a policy and choose **Compile (bundle creation)** to start compilation on demand.
99
99
-**Compilation status visibility:** A new **Compilation Status** column shows which policies are already compiled and which need compilation.
100
100
-**Faster publishing:** When a compiled bundle exists for a selected policy, NGINX Instance Manager uses it to speed up publishing to instances and instance groups.
101
-
101
+
102
102
**Upgrade and compatibility**
103
-
103
+
104
104
- No breaking changes. Existing workflows continue to function as before. On-demand compilation through the web interface complements the existing API and can improve publish speed and reduce failures during WAF policy deployment.
105
-
105
+
106
106
**Limitations**
107
-
107
+
108
108
- By default, the **Compile** action uses the latest revision of the selected policy, the most recent compiler version, and the newest versions of attack signatures, bot signatures, and threat campaigns.
109
109
110
110
### Resolved issues {#2-21-0-resolved-issues}
@@ -129,19 +129,33 @@ NGINX Instance Manager 2.20.1 supports upgrades from these previous versions:
129
129
130
130
If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.
131
131
132
+
### Security updates{#2-18-1-security-updates}
133
+
134
+
{{< call-out "important" >}}
135
+
For the protection of our customers, NGINX doesn’t disclose security issues until an investigation has occurred and a fix is available.
136
+
{{< /call-out >}}
137
+
138
+
This release includes the following security updates:
139
+
140
+
- {{% icon-resolved %}} **Note on CVEs in this patch release**<aname="2-18-1-security-updates-CVEs-46911"></a>
141
+
142
+
This release does not include new fixes for security vulnerabilities (CVEs) present in this version. To receive security updates, please upgrade to the latest NGINX Instance Manager version. CVEs present in the latest version will be fixed in the upcoming 2.21.1 patch release.
143
+
132
144
### Changes in default behavior{#2-20-1-changes-in-behavior}
133
145
134
146
This release has the following changes in default behavior:
135
147
136
148
- {{% icon-feature %}} **Support for Entrust-CA deprecated**<aname="2-20-1-changes-in-behavior-Support-for-Entrust-CA-deprecated-46910"></a>
137
149
138
150
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
139
-
151
+
140
152
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
141
-
153
+
142
154
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
143
-
155
+
144
156
To prevent service interruptions and provide an extended window for customers to upgrade to version 2.21.0, we are also issuing minor patch releases for versions 2.18.1, 2.19.3, and 2.20.1.
157
+
158
+
For more information please see the [related KB Article](https://my.f5.com/manage/s/article/K000158775).
145
159
146
160
### Known issues {#2-20-1-known-issues}
147
161
@@ -229,19 +243,33 @@ NGINX Instance Manager 2.19.3 supports upgrades from these previous versions:
229
243
230
244
If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.
231
245
246
+
### Security updates{#2-19-3-security-updates}
247
+
248
+
{{< call-out "important" >}}
249
+
For the protection of our customers, NGINX doesn’t disclose security issues until an investigation has occurred and a fix is available.
250
+
{{< /call-out >}}
251
+
252
+
This release includes the following security updates:
253
+
254
+
- {{% icon-resolved %}} **Note on CVEs in this patch release**<aname="2-19-3-security-updates-CVEs-46912"></a>
255
+
256
+
This release does not include new fixes for security vulnerabilities (CVEs) present in this version. To receive security updates, please upgrade to the latest NGINX Instance Manager version. CVEs present in the latest version will be fixed in the upcoming 2.21.1 patch release.
257
+
232
258
### Changes in default behavior{#2-19-3-changes-in-behavior}
233
259
234
260
This release has the following changes in default behavior:
235
261
236
262
- {{% icon-feature %}} **Support for Entrust-CA deprecated**<aname="2-19-3-changes-in-behavior-Support-for-Entrust-CA-deprecated-46909"></a>
237
263
238
-
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
264
+
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
239
265
240
-
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
266
+
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
241
267
242
-
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
268
+
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
243
269
244
270
To prevent service interruptions and provide an extended window for customers to upgrade to version 2.21.0, we are also issuing minor patch releases for versions 2.18.1, 2.19.3, and 2.20.1.
271
+
272
+
For more information please see the [related KB Article](https://my.f5.com/manage/s/article/K000158775).
245
273
246
274
### Known issues {#2-19-3-known-issues}
247
275
@@ -398,19 +426,33 @@ NGINX Instance Manager 2.18.1 supports upgrades from these previous versions:
398
426
399
427
If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.
400
428
429
+
### Security updates{#2-18-1-security-updates}
430
+
431
+
{{< call-out "important" >}}
432
+
For the protection of our customers, NGINX doesn’t disclose security issues until an investigation has occurred and a fix is available.
433
+
{{< /call-out >}}
434
+
435
+
This release includes the following security updates:
436
+
437
+
- {{% icon-resolved %}} **Note on CVEs in this patch release**<aname="2-18-1-security-updates-CVEs-46911"></a>
438
+
439
+
This release does not include new fixes for security vulnerabilities (CVEs) present in this version. To receive security updates, please upgrade to the latest NGINX Instance Manager version. CVEs present in the latest version will be fixed in the upcoming 2.21.1 patch release.
440
+
401
441
### Changes in default behavior{#2-18-1-changes-in-behavior}
402
442
403
443
This release has the following changes in default behavior:
404
444
405
445
- {{% icon-feature %}} **Support for Entrust-CA deprecated**<aname="2-18-1-changes-in-behavior-Support-for-Entrust-CA-deprecated-46907"></a>
406
446
407
-
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
447
+
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
408
448
409
-
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
449
+
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
410
450
411
-
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
451
+
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
412
452
413
453
To prevent service interruptions and provide an extended window for customers to upgrade to version 2.21.0, we are also issuing minor patch releases for versions 2.18.1, 2.19.3, and 2.20.1.
454
+
455
+
For more information please see the [related KB Article](https://my.f5.com/manage/s/article/K000158775).
0 commit comments