- Added a default-enabled X.509 authenticator option to abort login when the configured CRL is not up-to-date, enhancing certificate validation security.
- Introduced a “Force login after reset” option in the Send Reset Email authenticator to terminate the session and require a new login after password reset.
- Improved documentation (removed stale Node.js adapter docs, clarified IPv6 JGroups, updated usage notes) and fixed numerous bugs across LDAP, UI, login flows, and core components.