IT Audit Factory MSP 4.1.8 C10-H2 — file version 4.1.8.3 Updated October 7, 2026 MSP 4.1.8 C10-H2 release notes Version and validation Product version 4.1.8; revision C10-H2; Windows file version 4.1.8.3. Build and regression checks passed. On October 6, 2026, the site owner confirmed that both the client and server installers worked. This is an unsigned test build; broader runtime acceptance and live Enhanced/DoD-Aligned verification remain pending. Client changes The client opens on Dashboard while retaining saved client, program and experience preferences. Settings & Credentials offers Guided setup and Manual setup. Coordinated User Experience is under Setup & Branding. Assessed client identifiers (CAGE/NCAGE) are under Clients and apply to the active client selected at the top. Evidence review The disabled Evidence sufficiency dropdown is replaced by Review evidence sufficiency. Select a linked evidence version, open the review form, enter the reviewer, decision and reason, confirm the exact version was reviewed, then save. New links start as Needs Review; linking a file does not approve it. Server changes Selecting a security profile fills its recommended settings in Automatic mode. Manual settings retains edited values when selecting a profile; validation still enforces profile requirements. Guided certificate setup offers a dropdown of alternatives with an explanation and Continue button. Successful database TLS tests and saves clear the earlier error from the status bar. Secure upgrades Includes the C10-H1 repair for recognized legacy ITAF-managed PostgreSQL installations. Upgrade checks retain data-directory ownership validation and verified database TLS. Use the Server Setup EXE and Upgrade / Use Existing Database. Download availability Use Downloads for the actual published installer version and checksum. This website update does not publish installers or change download counters. Matching Free and Professional releases are not established by this MSP update. Product Tour screenshots retain their original 4.1.0 identity. MSP 4.1.8 security and setup Choose Automatic or Manual settings In Server Administration, Security & Communications, choose the communication profile. Automatic fills the recommended controls. Manual retains edited control values. Neither selection activates the listener: save settings and restart the MSP Server service. Certificate prerequisites and validation still apply. Profile requirements OFF uses HTTP. Standard defaults to TLS 1.2/1.3 without mTLS, request signing or revocation checks. Enhanced adds CA trust, request signing and API certificate revocation. High Assurance requires TLS 1.3, mTLS, signing, revocation and CA-chain trust. DoD-Aligned also enforces its Windows FIPS prerequisite. The DoD-Aligned label is a technical profile, not certification. Certificate choices are alternatives Choose one option: an existing server certificate, import a server PFX, or create a Standard lab certificate. Continue performs the selected action. Then check the address and certificate; export the public certificate when clients need it. A lab certificate is for Standard testing and requires explicit client trust. Never distribute the private server PFX to clients. Verify the running listener Check Settings (Preflight) checks configuration before activation; it does not verify the live listener. After saving and restarting, run Verify Current Secure Connection from the client. Confirm TLS, authentication and server security status for the intended profile. Reverify after changing profiles. Protect the database connection For a recognized ITAF-managed local PostgreSQL installation, use Prepare managed database TLS and review its confirmation. Keep VerifyFull and the matching CA file. API TLS and database TLS are separate. A generated local database CA may not offer revocation information; investigate that specific database test failure rather than weakening API profile requirements. Client connection setup Use Guided setup for device request, administrator approval and importing the approved setup on the requesting device/account. Manual setup exposes the connection fields for administrator-supplied values. Verify the live connection after either method. Integration settings Air-gapped mode blocks the integration webhook test; it is not Windows network isolation. The human-approval checkbox records a preference; it does not enforce an approval workflow. An optional HTTPS webhook receives a small test message when Test Integration Webhook is clicked. Save the settings before testing. Troubleshoot MSP 4.1.8 Confirm the exact build Include MSP Server or MSP Client, version 4.1.8, revision C10-H2 and file version 4.1.8.3 in a support request. Include the failing action and the selected security profile. Install or upgrade Back up using your existing procedure. Close Server Administration, run the Server Setup EXE as administrator, and choose Upgrade / Use Existing Database. Retain your database and network settings. Install the matching Client MSI on each client workstation. Do not choose Create New Database for an upgrade. Preflight passed, listener not verified Save settings, restart the service, then verify from the client with Verify Current Secure Connection. A running service or an open TCP port alone does not prove the requested security profile is active. Database SSL handshake errors Check the database certificate name/SAN, issuing CA, validity, revocation support and configured host. Keep VerifyFull. Use Database TLS & Recovery to test the actual database session. A successful test/save updates the bottom status bar in C10-H2. Review the precise failure before changing settings. Evidence sufficiency Link an evidence version first, select it in the linked list, then choose Review evidence sufficiency. Record the reviewer, decision, reason and review confirmation. Save requirement edits separately. Evidence linking and requirement implementation do not substitute for an evidence review. Collect useful diagnostics Export a server troubleshooting report from Database TLS & Recovery and collect client connection diagnostics after reproducing the failure. For Enhanced or DoD-Aligned, record the intended profile and the actual verification result. Review reports before sharing; omit API keys, passwords, private keys and customer evidence. Where settings moved Coordinated User Experience is under Setup & Branding. CAGE/NCAGE identifiers are under Clients. The client starts on Dashboard. Connection setup offers Guided and Manual choices under Settings & Credentials. CURRENT MSP INSTALLER IDENTITIES Both components: product 4.1.8, revision C10-H2, file version 4.1.8.3. MSP Server File: ITAF-MSP-Server-Setup-4.1.8-C10-H2-x64.exe SHA-256: ebb7603fd6ae8566cd8e2fa71c32a39821e486f7beb4de5f38d74ae24a884a1d MSP Client File: ITAF-MSP-Client-4.1.8-C10-H2-x64.msi SHA-256: 0bd7f3eb8641bcef2be95912802d181516a6f1356da983b6bcf11102cd1d56ea Verify the downloaded file before installation. In PowerShell, run: Get-FileHash -Algorithm SHA256 -LiteralPath "C:\Downloads\" Compare the full hash with the matching value above. These hashes identify the installers confirmed working by the owner. Documentation-only updates do not change installer versions or hashes. Historical Free/Professional release numbers are separate.