February 2026
New Features
DSS-3350 Introduce new role for managed API calls by deploy-time configuration
DSS-3351 Support for read-only workers by deploy-time configuration
DSS-3352 Option to disallow the 'allow-any admin' setting by deploy-time configuration
DSS-3353 Support for making generated worker IDs start at a higher value by deploy-time configuration
DSS-3536 Sign with Extended CMSSigner and composite key
DSS-3635 Add support for the remaining composite algorithms supported by EJBCA and create test suite for all supported composite algorithms
Improvements
DSS-3500 Fix different base image being used for Ant download & Introduce ARG in Dockerfile to use the same everywhere
DSS-3522 Upgrade to BC 1.83
DSS-3526 Upgrade to P11NG 0.27.0
DSS-3559 Update copyright year for 2026
DSS-3565 Managed REST module should not startup if Managed roles are configured incorrectly
DSS-3571 Expose startup probe configuration in values.yaml for the SignServer Helm
DSS-3609 Support WildFly 39.0.1.Final and upgrade container to use it
DSS-3632 Update CloudHSM Docs to demonstrate how to set IDs of existing keys
Bug Fixes
DSS-3317 Make the SignServer Container runnable by other UID than 0 and 10001
DSS-3495 Regression: SoftHSM Clenkins job now broken with older SoftHSM version after fix supporting newer versions
DSS-3507 Regression: Failing timed services can cause excessive log output and increasing heap space usage
DSS-3610 Worker Name property is case sensitive when updating using different interfaces and allows duplicated worker names