December 2025
New Features
DSS-2130 Option in CMS Signer for specifying signature algorithm as rsaEncryption
DSS-3293 Option in CMS Signer to not add NULL for SHA-2
Improvements
DSS-3195 Add option to switch between using own implementation or Jsign for MSI in SignClient with client-side hashing \+ upgrading POI
DSS-3298 Merge epic branch for official java 21 support
DSS-3314 Community: Remove unused method with know race condition
DSS-3347 Support latest WildFly 37 version and upgrade base container image with it for November milestone
DSS-3348 Upgrade JNA to 5.12.1
DSS-3355 Upgrade to container base image with Java 21
DSS-3362 Upgrade to BC 1.82 \+ KFC libraries
DSS-3429 Fix ClientCertAuthorizerRdnTest failures introduced when running Java 21
DSS-3451 Support latest WildFly 38 version and upgrade base container image with it for November milestone
DSS-3476 Do not include SpcSpOpusInfo object in Authenticode signatures if both program name and URL are empty
Bugs
DSS-3158 Fix community/customer build failures due to service-manifest-builder
DSS-3412 Our legacy webtests needs updating to work after the introduction of login page and session
DSS-3430 SignServer Container having double JRE installations and pulls in additional dependencies
DSS-3453 Jenkins jobs P11NG\_with\_DB\_Protection and SunP11\_with\_DB\_Protection are using soft keys
DSS-3454 Regression: Database protection using P11NG or SunPKCS11 gives configuration error and stops deployment
DSS-3492 Regression: SignServer requires the OIDC extension in the application server even if OIDC is not going to be used