7.9 7.8.1 7.8 7.7 7.6 7.5 7.4 7.3.2
7.9 7.8.1 7.8 7.7 7.6 7.5 7.4 7.3.2

SignServer 7.9 Release Notes

SEPTEMBER 2026

The SignServer team is pleased to announce the release of SignServer 7.9. This release consisted of a few improvements and mostly bug fixes.

For available deployment types and associated versions, refer to Supported Versions.

Highlights

Library Upgrades

This release includes library upgrades related to flagged CVEs.

Assorted Bug Fixes

This release includes several bug fixes, such as the Reload from Database button on the Global Configuration Page is operational again. Additionally, resolved an issue with a Worker going offline when the key usage counter was enabled and the certificate used explicit ECC parameters.

Announcements

From WildFly 41, AJP fails with an error message. It is recommend to switch away from AJP in favor of proxying with HTTP. For details and configuration information, see Configure a Reverse Proxy in SignServer.

Upgrade Information

Review the SignServer Upgrade Notes for important information about this release. For upgrade instructions, see Upgrade SignServer.

Change Log: Resolved Issues

The following lists implemented features and fixed issues in SignServer 7.9.

Issues Resolved in 7.9

Released September 2026

Improvements

DSS-3892 Support WildFly 41.0.1 and upgrade container

DSS-3910 Exclude additional worker templates when replacewithmanaged=true

DSS-3943 Fix AJP with WF 41 & document AJP deprecation

Bug Fixes

DSS-3781 Fixed the “Reload from Database” button on Global Configuration page

DSS-3821 Regression: Inconsistency with public key vs. certificate for key usage counter initialization causes worker to be offline if counter is enabled and certificate uses explicit ECC.

DSS-3824 Fixed inconsistencies in the responses of GET /publickeys and GET /certificates endpoints

DSS-3920 Can not build without using internal repository: Could not find artifact com.keyfactor:cryptotokens:pom:3.10.1 in central

DSS-3954 Made SignServer Helm chart work with NGINX after WF 41 upgrade

DSS-4011 Regression: BC upgrade to 1.85\+ makes re-signing of already signed Authenticode signatures not verify

DSS-4014 Regression: Security hardening measure