---
title: cert-manager Operator for Red Hat OpenShift release notes
---

# cert-manager Operator for Red Hat OpenShift release notes {#cert-manager-operator-release-notes}

The cert-manager Operator for Red Hat OpenShift is a cluster-wide service that provides application certificate lifecycle management.

These release notes track the development of cert-manager Operator for Red Hat OpenShift.

For more information, see [About the cert-manager Operator for Red Hat OpenShift](/openshift-docs-markdown/security/cert_manager_operator/index#cert-manager-operator-about).

## cert-manager Operator for Red Hat OpenShift 1.20.0 {#cert-manager-operator-release-notes-1-20-0_cert-manager-operator-release-notes}

Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.20.0 to learn what is new and updated with this release.

Issued: 2 July 2026

The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.20.0:

- [RHBA-2026:34294](https://access.redhat.com/errata/RHBA-2026:34294)
- [RHBA-2026:34309](https://access.redhat.com/errata/RHBA-2026:34309)
- [RHBA-2026:34336](https://access.redhat.com/errata/RHBA-2026:34336)
- [RHBA-2026:34714](https://access.redhat.com/errata/RHBA-2026:34714)

Version `v1.20.0` of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version `v1.20.3`. For more information, see the [cert-manager project release notes for v1.20.3](https://cert-manager.io/docs/releases/release-notes/release-notes-1.20/#v1203).

### New features and enhancements {#cert-manager-operator-1-20-0-features-enhancements_cert-manager-operator-release-notes}

> [!IMPORTANT]
> TLS adherence for cert-manager operands is a Technology Preview feature only. Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.
>
> For more information about the support scope of Red Hat Technology Preview features, see [Technology Preview Features Support Scope](https://access.redhat.com/support/offerings/techpreview/).

TrustManager Technology Preview no longer requires a cluster preview FeatureSet
:   With this release, the cert-manager Operator for Red Hat OpenShift no longer requires the `featuregates.config.openshift.io/cluster` object to use a preview `FeatureSet`, such as `TechPreviewNoUpgrade`, in order to enable the TrustManager Technology Preview operand.

    Previously, enabling TrustManager required both of the following conditions to be met:

    - The cluster `FeatureSet` must be set to a preview value, such as `TechPreviewNoUpgrade`, `DevPreviewNoUpgrade`, or `CustomNoUpgrade`.
    - The Operator subscription must opt in to TrustManager by setting `UNSUPPORTED_ADDON_FEATURES=TrustManager=true`.

    Customers running clusters with the `Default` `FeatureSet` were unable to evaluate TrustManager without first switching the cluster to a preview `FeatureSet`, which is a disruptive, cluster-wide change that prevents upgrades.

    With this update, the cluster `FeatureSet` requirement is removed. Enabling TrustManager now requires only that the Operator subscription includes `UNSUPPORTED_ADDON_FEATURES=TrustManager=true`. TrustManager remains a Technology Preview feature and is disabled by default.

    For more information, see [Enabling the TrustManager Operand](/openshift-docs-markdown/security/cert_manager_operator/cert-manager-trust-manager#cert-manager-trust-manager-install_cert-manager-trust-manager).

New performance-tuning override arguments for the cert-manager controller
:   With this release, the cert-manager Operator for Red Hat OpenShift supports configuring performance-tuning parameters for the cert-manager controller by using the `overrideArgs` field of the `CertManager` custom resource (CR). Previously, users had to rely on `spec.unsupportedConfigOverrides` to tune these settings.

    You can now set the following arguments under `spec.controllerConfig.overrideArgs`:

    - `--concurrent-workers`: The number of concurrent workers for each controller. The default value is `5`.
    - `--kube-api-qps`: The maximum number of queries per second sent to the Kubernetes API server. The default value is `20`.
    - `--kube-api-burst`: The maximum burst of queries per second sent to the Kubernetes API server. Must be greater than or equal to `--kube-api-qps`. The default value is `50`.
    - `--max-concurrent-challenges`: The maximum number of ACME challenges that can be scheduled as processing at the same time. The default value is `60`.

    The Operator validates that `--kube-api-burst` is greater than or equal to `--kube-api-qps` when both values are set. If this constraint is not met, the Operator sets the `Degraded` condition on the `CertManager` CR and does not apply the invalid configuration to the controller deployment.

    For more information, see [Overridable arguments for the cert-manager components](/openshift-docs-markdown/security/cert_manager_operator/cert-manager-customizing-api-fields#cert-manager-overridable-arguments_cert-manager-customizing-api-fields).

Cluster TLS security profile applied to cert-manager operands
:   With this release, the cert-manager Operator for Red Hat OpenShift can read the cluster TLS security profile from the `apiserver.config.openshift.io/cluster` object and automatically apply the corresponding TLS configuration to the cert-manager controller, webhook, and CA injector deployments.

    Previously, the TLS configuration for cert-manager operands was not tied to the cluster-wide TLS security profile. Cluster administrators who configured a stricter TLS profile at the cluster level had no automated mechanism to propagate those settings to cert-manager operands, creating a gap in cluster-wide TLS posture enforcement.

    With this update, when the `spec.tlsAdherence` field of the `CertManager` custom resource (CR) is set to `StrictAllComponents`, the Operator reads the `spec.tlsSecurityProfile` value from `apiserver.config.openshift.io/cluster` and applies the corresponding TLS arguments to the cert-manager operand deployments. The Operator reconciles the deployments whenever the cluster TLS profile changes.

    TLS arguments are applied per operand component as follows:

    - `cert-manager-webhook`: serving TLS flags and metrics endpoint TLS flags.
    - `cert-manager` (controller): metrics endpoint TLS flags only.
    - `cert-manager-cainjector`: metrics endpoint TLS flags only.

    TLS profile enforcement is not yet supported for the IstioCSR and TrustManager operands.

    To support this feature, the Operator now requires `get`, `list`, and `watch` permissions on the `apiservers` resource in the `config.openshift.io` API group.

    This feature is gated by the `TLSAdherence` feature gate. To use this feature, you must enable the `TechPreviewNoUpgrade` feature set. For more information, see [Understanding feature gates](/openshift-docs-markdown/nodes/clusters/nodes-cluster-enabling-features#nodes-cluster-enabling-features-about_nodes-cluster-enabling).

    > [!NOTE]
    > Elliptic curve preferences are not configurable because cert-manager does not yet support specifying curve preferences upstream.

    > [!IMPORTANT]
    > TLS adherence for cert-manager operands is a Technology Preview feature only. Technology Preview features are not supported with Red Hat production service level agreements (SLAs) and might not be functionally complete. Red Hat does not recommend using them in production. These features provide early access to upcoming product features, enabling customers to test functionality and provide feedback during the development process.
    >
    > For more information about the support scope of Red Hat Technology Preview features, see [Technology Preview Features Support Scope](https://access.redhat.com/support/offerings/techpreview/).

### Fixed issues {#cert-manager-operator-1-20-0-fixed-issues_cert-manager-operator-release-notes}

- Before this update, the cert-manager Operator for Red Hat OpenShift installation failed on clusters with the Console capability disabled because the `ConsoleYAMLSample` resources were missing the required capability annotation. With this release, the Operator installs successfully on Console-less clusters. ([OCPBUGS-85579](https://redhat.atlassian.net/browse/OCPBUGS-85579))

## cert-manager Operator for Red Hat OpenShift 1.19.1 {#cert-manager-operator-release-notes-1-19-1_cert-manager-operator-release-notes}

Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.1 to learn what is new and updated with this release.

Issued: 13 August 2026

The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.1:

- [RHSA-2026:54527](https://access.redhat.com/errata/RHSA-2026:54527)
- [RHBA-2026:54529](https://access.redhat.com/errata/RHBA-2026:54529)
- [RHSA-2026:54531](https://access.redhat.com/errata/RHSA-2026:54531)
- [RHBA-2026:54551](https://access.redhat.com/errata/RHBA-2026:54551)

Version `v1.19.6` of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version `v1.19.6`. For more information, see the [cert-manager project release notes for v1.19.6](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19#v1196).

### Fixed issues {#cert-manager-operator-1-19-1-fixed-issues_cert-manager-operator-release-notes}

- Before this update, the cert-manager Operator for Red Hat OpenShift installation failed on clusters without the console capability because the OLM bundle included `ConsoleYAMLSample` and `ConsoleQuickStart` resources that require the `console.openshift.io` APIs. With this release, the Operator creates the console resources at runtime only when the required APIs are available, ensuring successful installation. ([OCPBUGS-85579](https://redhat.atlassian.net/browse/OCPBUGS-85579))

### CVEs {#cert-manager-operator-1-19-1-cves_cert-manager-operator-release-notes}

- [CVE-2026-33186](https://access.redhat.com/security/cve/CVE-2026-33186)
- [CVE-2026-46595](https://access.redhat.com/security/cve/CVE-2026-46595)
- [CVE-2026-39821](https://access.redhat.com/security/cve/CVE-2026-39821)
- [CVE-2026-39828](https://access.redhat.com/security/cve/CVE-2026-39828)
- [CVE-2026-39830](https://access.redhat.com/security/cve/CVE-2026-39830)
- [CVE-2026-42499](https://access.redhat.com/security/cve/CVE-2026-42499)
- [CVE-2026-25681](https://access.redhat.com/security/cve/CVE-2026-25681)
- [CVE-2026-39820](https://access.redhat.com/security/cve/CVE-2026-39820)
- [CVE-2026-46597](https://access.redhat.com/security/cve/CVE-2026-46597)
- [CVE-2026-27145](https://access.redhat.com/security/cve/CVE-2026-27145)
- [CVE-2026-42504](https://access.redhat.com/security/cve/CVE-2026-42504)
- [CVE-2026-27136](https://access.redhat.com/security/cve/CVE-2026-27136)
- [CVE-2026-42502](https://access.redhat.com/security/cve/CVE-2026-42502)

## cert-manager Operator for Red Hat OpenShift 1.19.0 {#cert-manager-operator-release-notes-1-19-0_cert-manager-operator-release-notes}

Review the release notes for the cert-manager Operator for Red Hat OpenShift 1.19.0 to learn what is new and updated with this release.

Issued: 20 April 2026

The following advisories are available for the cert-manager Operator for Red Hat OpenShift for OpenShift Container Platform 1.19.0:

- [RHBA-2026:9064](https://access.redhat.com/errata/RHBA-2026:9064)
- [RHBA-2026:9024](https://access.redhat.com/errata/RHBA-2026:9024)
- [RHBA-2026:8953](https://access.redhat.com/errata/RHBA-2026:8953)
- [RHBA-2026:9025](https://access.redhat.com/errata/RHBA-2026:9025)
- [RHBA-2026:8956](https://access.redhat.com/errata/RHBA-2026:8956)

Version `v1.19.4` of the cert-manager Operator for Red Hat OpenShift is based on the upstream cert-manager version `v1.19.4`. For more information, see the [cert-manager project release notes for v1.19.4](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19#v1194).

### New features and enhancements {#cert-manager-operator-1-19-0-features-enhancements_cert-manager-operator-release-notes}

Distribution of trust bundles with the trust manager operand (Technology Preview)
:   In this release, the cert-manager Operator for Red Hat OpenShift adds support for the trust-manager operand as a Technology Preview feature. You can now install the trust-manager operand to automate the secure distribution of trust bundles, such as certificate authority (CA) certificates, to application namespaces across your cluster. For more information, see [Distributing certificates by using trust-manager operand](/openshift-docs-markdown/security/cert_manager_operator/cert-manager-trust-manager#cert-manager-trust-manager).

Support for configuring the certificate request backoff duration
:   In this release, the cert-manager Operator for Red Hat OpenShift adds support for the `--certificate-request-minimum-backoff-duration` flag. With this flag, you can configure the minimum backoff period for certificate requests by overriding the default configuration. For more information, see [Overridable arguments for the cert-manager components](/openshift-docs-markdown/security/cert_manager_operator/cert-manager-customizing-api-fields#cert-manager-overridable-arguments_cert-manager-customizing-api-fields).

### Fixed issues {#cert-manager-operator-1-19-0-fixed-issues_cert-manager-operator-release-notes}

- Before this update, the **ClusterIssuer** form view lacked an option to remove the self-signed field. As a consequence, you could not create issuer types other than self-signed. With this release, the form view sets the certificate authority (CA) as the default issuer type. As a result, you can switch to other issuer types by using the form view. ([OCPBUGS-65620](https://redhat.atlassian.net/browse/OCPBUGS-65620))
