Impex release information

Release Type: General

Release date: 2026-08-19

The Impex 6.1.0 release

This release brings several new requested features, like the functionality to test a DataLock Flow directly from the ICC and compact station cards in the ICC GUI for installations with many stations.

It also adds editable configuration directly on the USBProtect station so that a user of the station can, for example, change receipt printing behaviour or whether the target drive is formatted on transfer. This is enabled by default on Offline Stations but turned off for online stations. It can be enabled in the Configuration card on the ICC.

As part of our ongoing efforts to improve the security of the product, we have further hardened a number of components and updated several system components.

ICC changes

  • The search field in the “Station identities” view now searches in the backend instead of only the identities already loaded in the frontend
  • Added a bulk import button in the “Station identities” view, which can be used to bulk-create identities from a file
  • Added a compact station card view for customers with more than 10 stations and improved the filtering code
  • Sensitive information in OpenID Connect debug logs is now redacted, with a knob in settings.py to turn the redaction off
  • Daily log timestamps are now labelled UTC

ICC fixes

  • Tightened file permissions on the Django secret key file
  • Ensured an operation can only be updated by the station that owns it
  • Newly created Configuration cards did not get any repo credentials; they are now copied from an existing configuration or from the repo settings
  • Fixed a potential path traversal security issue on the scan-upload endpoints (only reachable by authenticated users)
  • The OpenID Connect settings test endpoint now requires an Admin user; previously any authenticated user could use it

USBProtect changes

  • Some settings on the stations can now be changed by the user. This is only allowed if the station is an Offline Station, or if the new ICC setting for this is enabled. We welcome feedback on this change, since we believe it makes the station more versatile, but some customers might not want certain settings to be changeable.
  • Added a battery status icon for USBProtect stations running on hardware with a battery
  • Refreshed the station GUI with a new icon font, and fixed some translations
  • The locally encrypted file count is now shown per partition

USBProtect fixes

  • Fixed scan reports not being added to BitLocker devices
  • Refactored the Network Settings unlock code to avoid bugs that could leave it unlocked

DataLock changes

  • There is now a “Test upload” button for testing a DataLock Flow. This is very useful for admins configuring a new Flow, or when debugging an existing one.

DataLock fixes

  • If there were many Flow errors, the server database would reject Flow status updates. This has been fixed to instead rotate away the oldest error messages and, if needed, truncate the errors.
  • Removed the ECDHE-RSA-AES256-CBC-SHA384 cipher from the advertised cipher suites for the TLS stack. It was already disabled in the underlying OpenSSL configuration, so there is no practical difference.
  • Changed how the Apache security headers are applied so that they also cover error pages

Documentation changes

  • New multi-partition chapter in the station user manual (EN and SV, with screenshots). Note that the multi-partition feature itself shipped in 6.0.0.
  • The ICC bulk-add-identities script is now in the ICC manual

Information

Operating system packages

All system components have been updated to their respective latest versions.

It is worth mentioning that these include fixes for the latest ClamAV and kernel security issues.

Online Documentation

Further details and configuration guidance are available in the official documentation:

https://sysctl.se/impex/documentation/

SBOM

Each ISO and VHD release has a software bill of materials (SBOM) to make introspection of the release easy to integrate with a number of security tools. Current and historical SBOMs are available for download at the customer portal.

Update Instructions

For networked Impex stations, this release will be automatically installed as part of the regular update process. No manual steps are required from administrators or users. The system will apply the update seamlessly in the background, ensuring that the latest fixes are in place without any interruption to normal operations.

For standalone Impex stations, your organisation needs to download the update from portal.sysctl.se in accordance with the update instructions in the chapter “USBProtect in offline mode” in the Impex USB Protect user manual.

Sysctl web page

https://www.sysctl.se

Sysctl page for Impex releases

https://sysctl.se/impex/releases/

Sysctl documentation for Impex

https://sysctl.se/impex/documentation/

Sysctl customer portal

https://portal.sysctl.se/

Sysctl rss/atom

https://sysctl.se/feed.xml