megachangelog
Feature1.72.0

Tailscale v1.72.0

This release adds captive portal detection across all platforms, introduces new flags for certificate and lock commands, improves DNS health warnings, and enhances TCP performance in userspace mode. Platform-specific updates include macOS dropping Catalina support, improved VPN stability on iOS and tvOS, and better health warning visibility across mobile platforms.

All platforms
  • New: Captive portal detection is now supported.
  • New: The tailscale cert command now contains the --min-validity flag. Use this flag to request a specified minimum remaining validity on the returned certificate. This flag is intended for automation, like cron jobs, that periodically refreshes certificates.
  • New: The tailscale lock command now supports passing keys as files. To pass a key as a file, use the prefix file: followed by the path to the file: file:<path-to-key-file>.
  • Changed: A health warning is now raised if Tailscale is unable to forward DNS queries to the configured resolvers.
  • Changed: An increase in send and receive buffer sizes for userspace mode TCP improves throughput over high latency paths.
Linux
  • New: The addition of TCP generic segmentation offload (GSO) support to userspace mode improves throughput.
macOS

Note: macOS 10.15 Catalina is no longer supported. See the v1.60.0 changelog for our initial end of life announcement.

  • New: Notifications are sent when a captive portal is detected.
  • Fixed: Health warnings in the UI are now sorted by their severity level.
  • Fixed: Reliability of the authentication process when launching the web browser is improved.
  • Fixed: The VPN tunnel is no longer automatically restarted if toggling Tailscale from the system VPN settings without disabling VPN On Demand first.
iOS
  • New: Notifications are sent when a captive portal is detected.
  • New: Health warnings are displayed when connectivity is impacted.
  • Fixed: An error message is displayed while attempting to start the VPN when both Wi-Fi and cellular interfaces are down, instead of failing silently.
  • Fixed: The VPN tunnel is no longer automatically restarted if toggling Tailscale from the system VPN settings without disabling VPN On Demand first.
tvOS
  • New: Notifications are sent when a captive portal is detected.
  • Fixed: The VPN tunnel is no longer automatically restarted if toggling Tailscale from the system VPN settings without disabling VPN On Demand first.
Android
  • New: Health warnings, if any are present, are displayed in the main view of the app.
vpnnetworkingplatform-updatesperformancestabilityhealth-monitoring

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →