Hi all, @Tom-Elliott @Sebastian-Roth
I found a bug in the Windows product key validation introduced in the Channel Beta | Version 1.6.0-beta.5384.
Issue:
A legitimate corporate Windows 11 Enterprise volume-license product key (containing the letter N) was rejected on the Host Management “General” tab with the error “Invalid Windows product key” (HTTP 400). The same key was accepted without issue on older FOG versions (pre-1.6.0-beta strict validation).
Root cause:
File: src/Base/FOGBase.php, function productKeyIsValid() (around line 2758)
public static function productKeyIsValid($val)
{
return (bool)preg_match(
'/^[BCDFGHJKMPQRTVWXY2346789]{25}$/',
self::productKeyStrip($val)
);
}
The allowed character class BCDFGHJKMPQRTVWXY2346789 is missing the letter N, which IS a valid character in the official Windows product key alphabet.
Evidence N is valid:
Many official Microsoft KMS Client Setup Keys contain N, e.g.:
Windows 10/11 Pro: W269N-WFGWX-YVC9B-4J6C9-T83GX
Windows 10/11 Enterprise: NPPR9-FWDCX-D2C8J-H872K-2YT43
Windows 10/11 Pro N: MH37W-N47XK-V7XM9-C7227-GCQG9
Source: https://learn.microsoft.com/en-us/windows-server/get-started/kmsclientkeys
Steps to reproduce:
Host Management → edit a host → General tab
Enter a valid Windows Enterprise/volume product key containing the letter N
Click Update
FOG rejects it as “Invalid Windows product key”
Suggested fix:
Add N to the character class:
‘/^[BCDFGHJKMNPQRTVWXY2346789]{25}$/’
Workaround applied locally (via sed) while waiting for an official fix:
sudo sed -i “s/[BCDFGHJKMPQRTVWXY2346789]/[BCDFGHJKMNPQRTVWXY2346789]/” /var/www/fog/src/Base/FOGBase.php
Confirmed working after this change.
Environment:
FOG Version: 1.6.0-beta.5384 (Channel Beta, branch working-1.6)
OS: Ubuntu 26.04.1 LTS “Resolute”
Thanks!