Skip to content

Dev Blog

Dev Blog

Short notes on building Taranac — new features, demos and behind-the-scenes.

Versions2026-08-25 1.2.8 — MS-CHAPv2 without a domain, and the rest of what you asked for Two more public issues closed, and both of them were the product holding a belief about itself that was never true. MS-CHAPv2 now works against FreeIPA with no domain join and no winbind. A directory synced for policy no longer hands thousands of accounts a login to the management console. TACACS+ gets a login banner at the one scope the protocol can actually carry it. And the worker that used to ask a switch whether a session was still alive is gone, because on a customer's Huawei that question stripped the VLAN off the users it was asking about. Versions2026-08-18 1.2.7 — four issues, and the first cluster in the field Last week the product found its own faults. This week other people did — four public issues, one customer's Calix switch, and the first high-availability cluster built by somebody outside our lab, which turned up five defects in its own lifecycle. An endpoint can now be classified by where its machine sits in the directory. A TACACS+ password prompt that was saved, rendered and never once sent reaches the device. An attribute declared optional stops going out mandatory. And a witness stops trying to run the whole product on the host whose purpose is to be cheap to lose. Versions2026-08-14 1.2.6 — the third one this week Wednesday, Thursday, Friday. The diagnostic collector grew two more modes — one command for a whole HA cluster, one for a single configuration collection that explains itself in four layers. Three Huawei faults, one of which stopped every 802.1X login the moment a client had IPv6 and another of which silenced the authentication journal entirely. Windows machine certificates stop being logged as PEAP. Updating stops hoarding superseded images. And a change to mail that quietly loosens security on every installation, which is the one section to read. Versions2026-08-13 1.2.5 — what actually happened on the wire One command now collects the evidence for a failure that nobody can gather by hand while it is happening — the packets, the daemon's log for those seconds, the records Taranac wrote and how the device is configured — decodes it so you can read it yourself, and never writes a shared secret into the archive. Plus two cases where Taranac misread what a device actually said on the wire — an enable request over RADIUS reported as a user who does not exist, and a PAP login reported as a failed enable, which also let it past multi-factor authentication. Versions2026-08-12 1.2.4 — tightening the bolts A fix release, and a particular kind of fix keeps recurring — something reported success and did nothing. A custom 802.1X certificate the page called deployed and no supplicant ever saw. A RADIUS attribute the log called applied and the switch never received. A directory synchronisation that finished green with zeroes in every column. An update that replaced half the product and said it was done. Plus two new things — your own RADIUS attribute dictionary, and groups inside groups — and one breaking change that wants five minutes before you pull. Versions2026-08-10 1.2.3 — a module in one command, a cluster in three One appliance image is now four — Taranac, a collector, a captive portal or an HA witness, chosen on first boot and installed with no registry in reach. A remote collector or a DMZ portal attaches with the single command the core prints, and a cluster is built with three commands instead of a runbook of scp'd TLS files and a hand-carried master key. Plus a backup that used to fail outright on every installation. Versions2026-08-06 1.2.2 — MS-CHAPv2, and a directory that isn't AD MikroTik administrators can finally log in, domain accounts authenticate over 802.1X with PEAP and EAP-TTLS, the node joins Active Directory by itself — and a directory no longer has to be Active Directory at all. Certificate enrollment works end to end for the first time, 802.1X sessions stop lying about themselves, and ten security findings are closed. Versions2026-07-30 1.2.1 — more vendors, lighter pages Seven more vendors for device administration and two more 802.1X authenticators, readable FortiGate command accounting, configurations too big to store now tracked instead of failed, and a UI that stopped downloading catalogues it never needed — one NCM page went from 37 MB to 2.5 MB. Versions2026-07-27 1.2.0 — reports, without writing a single query Reporting across AAA, NAC and audit data — 43 ready-made templates, saved as datasets, composed into multi-page reports, exported to PDF/CSV/XLSX and mailed on a schedule. Plus a round of UX sharpening and a stack of fixes. Versions2026-07-23 1.1.2 — you wrote this one A thank-you release. Almost every line of it came from people who spun Taranac up, hit an edge, and told us about it — vendor profiles that now deploy exactly as previewed, sharper LDAP errors, cluster-wide MFA replay protection, and more. Versions2026-07-20 Boot it and it's done — Taranac now ships as a VM An OVA for VMware and a QCOW2 for Proxmox and KVM, with every container image already inside. Import one file, answer four questions on the console, and the stack installs offline — no Docker to set up, no registry to reach. Versions2026-07-18 1.1.1 — ArcSight-ready, and a JIT fix under real load A fast follow to the Configuration Tracker — CEF output for your SIEM, plus the concurrency and durability fixes a week of real use turned up. Versions2026-07-17 1.1.0 — Configuration Tracker ships Backup, versioning and diff for your device configs — collected over SSH, Telnet, SCP/SFTP or HTTPS, with logins nobody ever sees because Taranac mints and rotates them itself. Project Life2026-07-07 What's next — a config tracker that knows who typed what A sneak peek at Configuration Tracker, a third pillar next to AAA and NAC. Versions2026-07-06 1.0.8 — 1792 tests and nothing to hide A release built on top of HA, plus a receipt for every green checkmark. Project Life2026-07-05 Learning to fall over gracefully Taranac grew a second node — and the good manners to survive losing one. Versions2026-06-10 Taranac 1.0.0-rc Release candidate — AAA, NAC, captive portal and PKI, all on one core. Project Life2026-01-12 One policy core — the idea behind Taranac Why one engine should decide every TACACS+, RADIUS and 802.1X request. Project Life2026-01-05 From TACACS GUI to Taranac — the long way round A three-year project I loved, an architecture I carried in my head, and the help that finally let me build it.

Get the release notes

Release notes go to Taranac account holders. Create a free account and tick “Email me about new releases” — one short email a month, what changed and what to upgrade first. Your account also gets you support tickets and licensing.

Create a free account →