Security Changelog
This log lists important security-related changes and fixes in ITVDesk releases.
ITVDesk 10.8.0 - Security Update
Released: September 20, 2026 · Build: 7.7.11.2
This release adds security controls for hardened deployments and DISA STIG-related configuration requirements. Deployment-specific assessment and configuration are still required.
New Security Features
- Added optional HTTPS-only and RTSPS-only operation.
Administrators can disable plain HTTP per camera and plain RTSP for the streaming service. SRTP remains a separate option for encrypted audio/video. - Added Windows-protected storage for configuration, UI accounts, security settings, audit records and imported TLS private keys.
Windows DPAPI adds protection tied to the Windows installation while supporting the existing application and SYSTEM Broker workflow. - Added shared certificate management for RTSPS and camera HTTPS services.
Administrators can validate and save a certificate pair, apply it to all cameras, or select individual camera certificates under Advanced.
Apply to All Cameras reloads the saved pair by restarting the relevant active services; clients may briefly disconnect. - Added an administrator-controlled certificate recovery policy.
When the entire protected certificate store is missing, the optional fallback can use the bundled default certificate with a visible warning. Damaged or unreadable stores do not trigger fallback. - Added optional forwarding of Security Audit events to the Windows Application Event Log.
Events use the ITVDesk Security source and can be collected through Windows Event Forwarding or existing monitoring tools. Collection and retention are configured by the administrator. - Added Change Password to UI Protect, including protection against reuse of the current and previous five passwords.
Changes require the current password and TOTP code when enabled. Password history is retained if the same username is removed and added again. - Added an optional 15-character minimum-password policy for new or changed UI and supported network account passwords.
Existing passwords remain valid until changed. - Added independent Local UI and Network Account Lockout controls.
Both are disabled by default, with initial values of three failed attempts within 15 minutes and a 10-minute lock duration. - Added per-stream snapshot access control.
Administrators can disable snapshot generation and retrieval, including access to previously cached images. - Added automatic Web Management sign-out after 10 minutes of inactivity.
The panel is Administrator-only. Background image and status refreshes do not extend the session; sign-out is audited and does not stop separate ONVIF or VMS/NVR streams.
Security Improvements
- Strengthened Local UI password protection with salted PBKDF2-HMAC-SHA256 hashing.
New or changed UI passwords require at least eight characters, including uppercase and lowercase letters, a number and a special character. Existing accounts remain usable. - Improved network account setup by removing the predefined Add Camera password and validating new or changed camera passwords.
The basic camera password policy requires at least eight characters with letters and numbers when the optional 15-character policy is disabled. - Added clearer ONVIF Administrator, Operator and User permissions and an Operator option in Login Management.
Operator supports media configuration and PTZ; User supports viewing, events and playback/search. System, network and account administration require Administrator. - Protected direct HTTP/HTTPS snapshot access with Digest authentication when camera ONVIF authentication is enabled.
Snapshot requests use the existing audit and optional network lockout policy, and responses instruct browsers and proxies not to cache images. - Expanded Security Audit with application and Broker startup/shutdown, UI authentication, supported UI configuration changes and Web profile/account saves.
Administrative records identify the verified user, target, action and result without recording passwords or private keys. - Improved audit persistence with periodic and orderly-exit saving and coordinated application/Broker updates.
With Windows Event Log forwarding enabled, local audit-save failures also generate a rate-limited error event. - Strengthened RTSP session-ID and SRTP key generation with a cryptographically secure random source.
Active RTSP session IDs are checked for duplicates. Existing ID formats and SRTP key lengths remain unchanged. - Simplified HTTPS, RTSPS, SRTP and Certificate Management settings with clearer labels, status messages and aligned controls.
- Added quick access to temporary Account Lockouts from the camera menu and automatic list refresh when opening the Account Lockout tab.
Manually blocked IP addresses remain separate under Blocked Clients. - Updated the bundled default TLS certificate to RSA-2048 / SHA-256 and improved certificate validation messages.
- Reduced internal Release log noise and improved encrypted configuration saving with atomic file replacement.
Security and Reliability Fixes
- Fixed pending Security Audit records being lost after reopening the application and incorrect success reporting when clearing the audit fails.
- Fixed normal Digest authentication challenges being counted as failed logins and already-blocked requests extending account lockout.
- Corrected Burst Protection escalation and cleanup of expired counters.
- Fixed RTSPS-only setup rejecting certificate pairs already saved in Windows-protected storage.
- Fixed Web Management signing out prematurely after a temporary connection or status-check error.
- Improved ONVIF XML depth validation to prevent parser stack overflow without changing the accepted nesting limit.
- Fixed Windows license-history saving failures and Qt 6 compatibility for UI password-length validation.
Important Upgrade Notes
- Windows configuration gains DPAPI protection on its next successful save. macOS and Linux storage behavior is unchanged.
Keep a backup before upgrading: older builds cannot read protected files, and moving to another Windows installation requires planned recovery.
Updates and in-place reinstalls retain access when configuration and the Windows installation are preserved. Windows file permissions remain necessary. - Import a deployment-specific certificate for production and configure client trust. Keep a secure backup of the original certificate and private key.
Clients using the previous bundled certificate may require a trust update. Strict installations can disable default-certificate fallback. - VMS/NVR accounts that change media settings or use PTZ require Operator or Administrator; system and account changes require Administrator.
Web Management supports browser Digest login over HTTP and HTTPS. HTTPS is recommended; Sign in may reuse credentials already cached by the browser. - UI password history applies to local UI accounts, not network accounts. Secure-only modes and Windows Event Log forwarding remain optional and disabled by default.
- v8.6 – October 2025 – Added CRA compliance, Watcher integrity verification, and signed update validation
Added RTSP over HTTPS and improved certificate validation.
Added RTSPS support.
Added ITVDeskWatcher servise for protect ITVDesk in case of a crash or hang it safely restarts the app and restores all previously in case of a crash or hang it safely restarts the app and restores all previously configured streams (desktop, camera, audio), keeping transmissions online with no manual intervention. - v8.5 – September 2025 – SRTP (Secure Real-Time Transport Protocol) support added for IP camera streams.
- v8.4 – July 2025 – Fixed potential buffer overflow in encoder video handling
Older versions change look link or upon request: This email address is being protected from spambots. You need JavaScript enabled to view it.
🛡️ EU CRA READY – Certified Software

