megachangelog
Announcement1.80.0

Tailscale v1.80.0

Version 1.80.0 brings policy-driven hostname management across platforms, exits alpha for the configure CLI command, fixes web interface and Funnel configuration issues, improves TLS certificate requests, and adds platform-specific enhancements including onboarding for Windows, DNS cache flushing for macOS, auth key support for iOS/tvOS, and subnet router configuration for Android.

All platforms
  • New: Hostname system policy is added for overriding the device hostname configured by the operating system, using an MDM solution.
  • Changed: tailscale configure CLI command and corresponding subcommands are no longer in alpha, except for the subcommand kubeconfig, which remains in alpha.
  • Fixed: Web interface displays a Login button instead of the Reauthenticate button when adding a new device to your tailnet.
  • Fixed: Tailscale Funnel configuration on devices displays errors when incoming connections are not permitted and connections are disallowed.
  • Fixed: Connections to a custom coordination server that does not support HTTPS will no longer fail when a custom port number is specified.
Linux
  • Changed: TLS certificate requests from Let's Encrypt include the device's DNS name in the CSR's SAN extension and set the Common Name field.
  • Fixed: Tailscale Funnel disabled on a device no longer displays enabled in the admin console.
Windows
  • New: Onboarding flow is added for easier initial setup of the app.
  • Changed: TLS certificate requests from Let's Encrypt include the device's DNS name in the CSR's SAN extension and set the Common Name field.
  • Fixed: Client installs as expected when using Group Policy Software Installation (GPSI).
  • Fixed: Race conditions that result in an incorrect state or a deadlock no longer cause issues when multiple Windows users are logged in simultaneously.
macOS
  • New: configure sysext activate, configure sysext deactivate, and configure sysext status CLI commands are added to the Standalone variant for managing the activation flow of the macOS system extension programmatically.
  • New: Standalone variant detects if the system extension is manually disabled or uninstalled by the user and displays a notice in the client UI.
  • New: Flush DNS Cache option is added to the Debug menu.
  • Changed: TLS certificate requests from Let's Encrypt include the device's DNS name in the CSR's SAN extension and set the Common Name field.
  • Fixed: App preferences re-set configures Use Tailscale Subnets to On and Allow Incoming Connections to Off as these are the default settings.
  • Fixed: Find Devices shortcut action no longer hangs.
  • Fixed: Standalone variant works as expected when users are not members of staff macOS user group.
iOS tvOS Android
  • New: Devices can be configured as a subnet router in the Settings menu of the app.
releasemdmclifunneltlsioswindowsmacos

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →