The HotFix generates an error when manually updating the Artica version, it is normal. It can be applied only for Artica 4.50.00000 Service Pack 8 New Hotfix erase modifications of old applied HotFixes.
20260927-17: Fix: in Artica, The DHCP leases list no longer misses every lease whose device vendor is unknown (only 13 of 31 active leases were shown on a test server).
20260927-17: Fix: in Artica, A DHCP client sending a hostname with a quote can no longer empty the DHCP leases list, and clients without a hostname are no longer listed as "-na-".
20260927-17: Fix: in Artica, The DHCP reservations and leases pages no longer accept search text that could alter their database query
20260927-17: Fix: in Artica, Editing a computer now records its "updated" time in the same time zone as every other change.
20260927-17: Add: in Artica, The DHCP reservations page uses the new table design and flags reservations that the DHCP server does not serve
20260927-17: Add: in Artica, The DHCP leases page uses the new table design, shows active and expired leases and warns when the list is out of date compared with the DHCP server.
20260927-17: Fix: in Artica, The DHCP "Last computers" and "DHCP requests" pages no longer accept search text that could alter their database query
20260927-17: Add: in Artica, The DHCP "Last computers", "DHCP requests" and "DHCP events" pages use the new table design
20260927-17: Add: in Artica, The DHCP events page now pages through every event of the period instead of showing only the latest 250.
20260927-17: Add: in Artica, The DHCP statistics dashboard has been redesigned
20260927-17: Fix: in Artica, The log storage check no longer loads a whole compressed log in memory when its first line is very long.
20260927-17: Add: in Artica Reverse Proxy, the Docker Relay agent installs its own systemd service with the new install-service command, as the enrollment instructions now say.
20260927-17: Fix: in Artica Reverse Proxy, the Docker Relay pages now show the labels and never-enrolled badges.
20260927-17: Fix: in Artica, The network traffic statistics database is now limited to 1 GB and compacted at startup.
20260927-17: Fix: in Artica, The DHCP statistics pages now say that the Artica service is not answering instead of asking to enable the DHCP server.
20260927-17: Add: in Artica, The document search now also finds words from their first three letters, and the search box completes file names as you type.
20260927-17: Add: in Artica, The Docker Manager can open an interactive terminal inside a running container, in its own browser tab, from the containers list.
20260927-17: Add: in Artica, The DHCP statistics now track the occupancy of each DHCP pool over time and display it on the dashboard.
20260927-17: Add: in Artica, The DHCP service now notifies the administrator when a device renews its address in a loop
20260927-17: Fix: in Artica, The Docker containers list no longer shows two columns with the same title.
20260925-17: Add: in Artica, The Wazuh agent is now available as a ready-to-install package for Debian 12 and Debian 13
20260926-17: Fix: in Artica, All Docker Manager pages are now translated and follow the standard console layout (search, header buttons, confirmation windows).
20260926-17: Add: in Artica, The Docker permissions page shows which account the Docker Manager sees for you, whether it is allowed, and explains how to grant access.
20260926-17: Fix: in Artica, The Docker performance page no longer times out when many containers are running: statistics are loaded progressively.
20260926-17: Add: in Artica, Docker networks can now be disconnected from a container, and connecting one offers the list of containers instead of a free text field.
20260926-17: Add: in Artica, The Docker containers page can remove a running container after an explicit warning
20260926-17: Fix: in Artica, The Docker container console now states clearly that interactive execution is not available instead of pretending a command ran.
20260926-17: Fix: in Artica, The Docker Manager pages now escape container, image and volume names everywhere, so a crafted name can no longer inject code into the page.
20260926-17: Fix: in Artica Proxy, The PostgreSQL connection manager no longer reuses connections that PgBouncer has already closed for inactivity
20260926-17: Fix: in Artica Proxy, The nightly proxy statistics no longer fail with a closed database.
20260926-17: Fix: in Artica, Containers created from the Docker Manager now really get the memory and CPU limits.
20260926-17: Fix: in Artica, Opening a container that no longer exists in the Docker Manager now reports that it was not found instead of an engine error.
20260926-17: Fix: in Artica, The Docker Manager daemon no longer refuses to start after an interruption left its job history file damaged.
20260926-17: Fix: in Artica, An image download or build that the Docker engine refuses (authentication, network or corrupt layer) is now reported as failed instead of completed.
20260926-17: Fix: in Artica, The Docker Manager no longer shows container environment variable values (such as passwords) when a container is inspected.
20260926-17: Fix: in Artica, The Docker Manager no longer lets a container be mounted onto sensitive host paths ( through ".." sequences, symbolic links or the volumes field.
20260926-17: Add: in Artica, The Docker Manager page now has a Status tab showing the service state and version, with buttons to install, restart or uninstall the Docker Manager.
20260926-17: Add: in Artica, A Docker menu now gives administrators access to the Docker Manager pages when Docker is enabled.
20260926-17: Fix: in Artica, The Docker Manager pages can no longer crash when loaded alongside the existing Docker status components.
20260926-17: Fix: in Artica, Installing the Docker Manager pages no longer replaces the Docker library used by the system status and web server status pages.
20260925-21: Fix: SMTP mail log tracker memory leak on deferred messages.
20260925-21: Fix: in Artica SIEM, The statistics database is now restarted automatically when its logging stops working after the disk has been full
20260925-21: Fix: in Artica SIEM, The statistics database no longer writes its logs at trace level, which produced hundreds of kilobytes of messages per second.
20260925-21: Fix: in Artica SIEM, no longer reports hundreds of thousands of lost statistics buckets at each startup.
20260924-17: Fix: in Artica Proxy, A website is no longer dropped from the uncategorized queue when the categorization service fails to answer.
20260925-17: Fix: in Artica, The PostgreSQL connection manager no longer leaks a connection pool each time a health check fails.
20260925-17: Fix: in Artica Proxy, The nightly Kerberos renewal no longer reports an error on appliances where Kerberos authentication is not configured.
20260925-17: Fix: in Zabbix Agent, after a reboot or a sysctl reload the agent could announce the short hostname instead of the FQDN
20260925-17: Fix: in Zabbix Agent, the declared Hostname now always comes from the system hostname setting, whatever the kernel reports at that moment.
20260925-17: Fix: in Zabbix Agent, the watchdog now restarts the agent within 3 minutes when it runs under a hostname different from the configured one.
20260925-17: Fix: in System, the kernel hostname kept switching between the short name and the FQDN, at boot and after every sysctl reload.
20260925-17: Fix: in System, the sysctl configuration no longer writes the short hostname, and changing the hostname now sets the FQDN in the kernel.
20260925-17: Fix: in System, existing appliances are repaired automatically.
20260924-19: Fix: in Artica SMTP, The mail log tracker kept every retry of a deferred message in memory for up to 5 days;
20260924-19: Fix: in Artica SMTP, Repeated delivery retries of a message now collapse into a single timeline entry with a retry count.
20260924-19: Fix: in Artica SMTP, A message's timeline is now capped at 64 events, keeping the first 16 and the most recent ones.
20260924-15: Fix: in Artica SMTP, Saving a deferred message's history now writes a few rows instead of hundreds per message.
20260924-03: Fix TLS issue for smtpd CA file in Artica SMTP
20260924-01: Fix: The reputation service could lock itself up for good: leaving 34,000 stuck tasks, 1 GB of memory and 6 CPU cores busy for four days on one appliance.
20260924-01: Fix: One saturated database pool no longer blocks every other database of the Artica REST service
20260924-01: Fix: Reputation rules are now kept in memory and reloaded every 5 minutes and after every change
20260924-01: Fix: The reputation verdict cache was a single value rewritten on every request, which failed about 15,000 times a day
20260924-01: Fix: Reputation checks are now limited to one at a time per rule and address and 64 overall;
20260924-01: Fix: The Artica REST API now caps simultaneous connections at 4,096 per listener and closes idle ones after 120 seconds,
20260924-01: Add: The Artica REST service now watches its own task count: it saves a diagnostic dump above 1,500 tasks
20260924-01: Add: The support package now includes the Artica REST service's stuck-task dumps.
20260924-01: Add: New REST API /reputations/admin/* (20 routes) to manage reputation rules, groups and lists.
20260924-01: Fix: The reputation rules page no longer writes the database directly
20260924-01: Fix: The reputation rules page now loads its rule list in one request instead of one database query per rule.
20260924-01: Fix: The reputation rule form never saved its firewall, ports and ban-duration fields, and the group up/down buttons had no effect.
20260924-01: Fix: Names and URLs typed in the reputation rules page are no longer inserted unescaped into database queries or into the page.
20260924-01: Fix: A reverse-proxy site whose reputation rule is disabled or deleted no longer calls the reputation service on every request
20260924-01: Fix: Dangerous Paths banned ordinary visitors of WordPress sites with /wp-content/ and /wp-content/uploads/.
20260924-01: Add: The Dangerous Paths status now lists the rules neutralized by default on all sites.
20260923-00: Fix: misconfigurations in Active Directory acls groups.
20260922-18: Fix: Missing button in system tasks.
20260922-14: Fix: Memory leak on Proxy acls cache.
20260917-17: Fix: The daemon ignored SIGTERM and never ran its shutdown sequence; every stop ended in a kill.
20260917-17: Fix: Checking whether a firewall ipset exists no longer reads every entry of every ipset (320 MB per call, twice every 10 minutes)
20260917-17: Fix: Proxy memory is now measured from the Proxy processes only, instead of reading the memory map of every process on the machine.
20260917-17: Fix: Proxy memory was overstated: dirty memory was counted twice on kernels 5.14 and later.
20260917-17: Fix: The process tree is now read once per pass instead of once per service and per process.
20260917-17: Fix: Docker failed to start on sysvinit systems (cgroups not mounted) and the failure was reported as a success.
20260917-17: Fix: Docker is now reported as started only once it answers, and a failed start raises a notification once per hour instead of retrying silently.
20260917-16: Fix: Two identical antivirus detections in the same second were merged into a single SIEM event.
20260918-16: Fix: PostgreSQL work_mem could not be set below 50 MB — a clamp forced any lower value back to 200 MB
20260918-16: Fix: PostgreSQL effective_cache_size defaulted to 256 MB whatever the machine's size, making the query planner avoid index scans; it now defaults to 40% of RAM.
20260918-16: Fix: Writing to the filtering engine's in-memory cache concatenated values instead of replacing them.
20260918-16: Fix: The filtering engine's cache counters doubled the length of their value on every call and crashed the service when the key was missing.
20260918-16: Fix: Category clients synchronized from a categories server stored every category without its name; the "Categories" column of the categories page was empty.
20260918-16: Fix: PostgreSQL work_mem could not be set below 50 MB; any lower value was silently replaced by 200 MB (70 GB worst case with 350 connections).
20260918-16: Fix: PostgreSQL work_mem now defaults to 25% of RAM shared across connections (4 to 64 MB), and effective_cache_size to 40% of RAM instead of a fixed 256 MB.
20260918-15: Fix: "Purge obsolete packages" left old kernels installed (the previous kernel and any kernel marked manual), keeping about 600 CVEs reported by scanners
20260918-15: Fix: "Update softwares packages" marked every upgraded package as manually installed, so new kernels could never be removed automatically.
20260917-15: Feature: Antivirus (eCAP ClamAV) detections are now sent to the SIEM as WebFiltering events.
20260918-14: Fix: The uncategorized websites queue never drained: every pass resolved again the domains already queued or already categorized
20260918-14: Fix: The uncategorized websites queue is now re-checked in full at each pass (within 10 minutes) instead of 500 domains every 2 hours
20260918-14: Fix: Uncategorized websites are now submitted to the Artica cloud in batches of up to 5,000 per run, only once re-checked, instead of the same 100 domains.
20260918-14: Fix: Log rotation left every compressed copy behind, uncompressed: 248 files and 17.7 GB piled up in five days on one appliance
20260918-14: Fix: The interface watchdog ran a full `nginx -T` every minute — 0.40 s and 112 MB of peak memory, 1,440 times a day; it now runs only when the listen directives on disk change, or every 30 minutes, and keeps running every minute while a mismatch lasts.
20260918-14: Fix: The nightly master replacement waited 10 seconds for the old master to exit while nginx allows its workers 30 seconds to drain, so three nights out of fourteen were reported as "hot restart incomplete" although the replacement had succeeded; the wait now follows the configured drain time plus a margin.
20260918-14: Fix: WAF report ingestion was abandoned every 10 minutes with "driver: bad connection" — 3,401 times on one appliance — although PostgreSQL was answering normally; the entry check now reconnects instead of giving up.
20260918-14: Fix: The PostgreSQL pool kept connections idle for 5 minutes while PgBouncer closes them after 60 seconds, so every task spaced by more than a minute was handed a dead connection; connections through PgBouncer now expire after 30 seconds.
20260918-13: Fix: The console answered "Error Connecting to the REST API server 7" on the greylist page after every milter restart
20260918-13: Fix: Several passes over the uncategorized websites file could run at the same time, resolving the same domains again and truncating the file under each other.
20260918-13: Fix: Importing an uncategorized websites export no longer decompresses without limit (gzip bomb); the import is capped at 64 MB decompressed and fully rolled back on error.
20260918-13: Fix: The system metrics database kept one table file open per daemon restart (766 open files for 3.2 MB of data); it is now rebuilt at startup beyond 32 tables.
20260918-13: Fix: System metrics reserved 83 MB of memory for a 3.2 MB database.
20260918-13: Fix: The daemon restarted itself every 18 to 30 minutes
20260918-13: Fix: The uncategorized websites file was loaded entirely in memory (152 MB for a 97 MB file); it is now read line by line.
20260918-13: Fix: Converting a category ID to its name rebuilt a 240-entry table on every call, the daemon's largest memory allocator.
20260918-13: Fix: The system-metrics database accumulated one file per daemon start and never merged them
20260918-13: Fix: The system-metrics database reserved 83 MB of memory for 3.2 MB of data; it now uses the same 4 MB write buffer as the other metric stores.
20260918-13: Fix: The daemon was restarted by its own memory watchdog every 18 to 30 minutes because nothing capped the heap
20260918-13: Fix: The uncategorized-domains file is now read line by line instead of loaded whole; a 97 MB file held 152 MB of memory for the entire import.
20260918-13: Fix: The category-name table was rebuilt on every single lookup, making it the daemon's largest source of memory allocation — 3 GB in 20 minutes.
20260918-12: Fix: Each domain categorization opened a new connection to GoShield and never released it.
20260918-11: Add: New setting to keep the appliance's own DNS lookups out of /var/log/dns-queries.log
20260918-11: Add: The DNS collector status now reports how many events were counted but deliberately kept out of the log file.
20260918-11: Add: New setting : DNS queries made by the appliance itself (loopback) are no longer written to dns-queries.log by default (13.6 GB per day observed, 99.8% loopback).
20260918-11: Add: A pending greylist entry from a public IP gets an "Accept" button that permanently allowlists the /32 in the instance's greylisting rule
20260918-09: Add: New console page (milter sub-menu): lists the greylisting entries with their state (pending, accepted, authenticated, expired), attempts, retention
20260918-09: Add: A greylist entry can be edited in a modal (state and retention in hours from now) and deleted with confirmation;
20260918-09: Add: Milter API routes /greylisting/entries (search, state, paging, total) and GET/POST/DELETE /greylisting/entries/{id} for the console
20260918-01: Fix: Every greylisted message produced two smtplog rows, doubling the refusal statistic
20260918-01: Fix: The greylisting decision journal had been silent for six days: the milter's syslog writer cached a failed connection to /dev/log for the life of the process.
20260918-00: Fix: The SIEM had no GeoIP database at all: the mirror index publishes "date" as unix seconds and the decoder expected a string, so every sync failed before downloading anything.
20260917-17: Fix: The daemon ignored SIGTERM and never ran its shutdown sequence; every stop ended in a kill.
20260917-17: Fix: Checking whether a firewall ipset exists no longer reads every entry of every ipset (320 MB per call, twice every 10 minutes)
20260917-17: Fix: Proxy memory is now measured from the Proxy processes only, instead of reading the memory map of every process on the machine.
20260917-17: Fix: Proxy memory was overstated: dirty memory was counted twice on kernels 5.14 and later.
20260917-17: Fix: The process tree is now read once per pass instead of once per service and per process.
20260917-16: Fix: Two identical antivirus detections in the same second were merged into a single SIEM event.
20260917-15: Add: Antivirus detections (eCAP/ClamAV) are sent to the SIEM as Web Filtering events, under the "antivirus" category, with the signature name.
20260917-15: Fix: The proxy real-time page queried the category API with a full URL, which always failed.
20260917-15: Fix: The 3,666 fixed domain categories of categories.org were never used by the proxy real-time page.
20260917-14: Fix: A URL longer than 1 KB logged by the antivirus killed a Proxy worker (buffer overflow in the eCAP adapter).
20260917-14: Add: The eCAP antivirus adapter is now compiled from source by the Compilator and shipped in the Proxy package.
20260917-13: Fix: Load-balancer health and agent checks were never started on servers added at runtime; the load balancer routed traffic with no failure detection.
20260917-13: Fix: A failed read of the load balancer database produced an empty configuration (node disabled, weight 0, certificate lost).
20260917-13: Fix: Truncating an oversized cache.log no longer reloads proxy server.
20260916-18: Add: Possibility to purge old Debian packages trough the Web Console.
20260916-18: Fix: Remove diffie-hellman-group14-sha1 in OpenSSH SSH key-exchange algorithms
20260916-18: Fix: FTP protocol is allways allowed by default in the Artica proxy - new option to enable it.
20260916-12: Fix categories tempfiles download from the category server are not cleaned
20260916-01: Add: Watchdog for proxy service for Collapsed forwarding queue overflow
20260915-19: Redesign: Proxy Multi-core section
20260915-19: Fix: Unable to start the Fortigate feature in Proxy
20260915-19: Fix: Unspecified GSS failure. Minor code may provide more information. Permission denied on Artica Proxy → caused by CIS Hardening
20260915-19: Fix: NTP Service (Chrony): reinstall did NOT produce a matching systemd
20260915-19: Fix: Artica restarts when the Proxy session status is more than 32MB
20260915-19: Fix: Internet access error via proxy — Code 503 / ERR_CONNECT_FAIL 110 on the notifications bell when the defined outgoing address is wrong
20260914-16: Fix: Unable to install the OpenVPN server
20260914-16: Redesign: The proxy authentication whitelists
20260914-16: Add: Proxy accesses Realtime monitor in the SIEM web console.
20260914-02: Fix: Sometimes, Artica is unable to extend partitions.
20260914-02: Fix: Support for wildcard characters in proxy authentication whitelists.