EJBCA 9.1 Upgrade Notes
Below are important changes and requirements when upgrading from EJBCA 9.0 to EJBCA 9.1.
For upgrade instructions and information on upgrade paths, see Upgrading EJBCA. For details of the new features and improvements in this release, see the EJBCA 9.1 Release Notes.
Behavioral Changes
NIST Approved Quantum-Safe Algorithms ML-DSA and ML-KEM
EJBCA versions prior to 9.1 supported NIST candidate PQC algorithms Dilithium and Kyber. These algorithms are removed in EJBCA 9.1 and replaced by the NIST-approved quantum-safe algorithms ML-DSA and ML-KEM.
Increased Maximum OCSP Nonce Length
As per RFC-9654, which supersedes RFC-8954, the maximum length of a nonce extension in an OCSP request has been increased from 32 to 128 bytes.