7.9 7.8.1 7.8 7.7 7.6 7.5 7.4 7.3.2
7.9 7.8.1 7.8 7.7 7.6 7.5 7.4 7.3.2

SignServer Change Log Summary

The following lists change logs for all SignServer versions released, sorted by date and listed per release in the table of contents below.

For more information on a specific release, see the respective SignServer Release Notes for details on issues resolved in the release.


SignServer 7.9

Released September 2026

Improvements

DSS-3892 Support WildFly 41.0.1 and upgrade container

DSS-3910 Exclude additional worker templates when replacewithmanaged=true

DSS-3943 Fix AJP with WF 41 & document AJP deprecation

Bug Fixes

DSS-3781 Fixed the “Reload from Database” button on Global Configuration page

DSS-3821 Regression: Inconsistency with public key vs. certificate for key usage counter initialization causes worker to be offline if counter is enabled and certificate uses explicit ECC.

DSS-3824 Fixed inconsistencies in the responses of GET /publickeys and GET /certificates endpoints

DSS-3920 Can not build without using internal repository: Could not find artifact com.keyfactor:cryptotokens:pom:3.10.1 in central

DSS-3954 Made SignServer Helm chart work with NGINX after WF 41 upgrade

DSS-4011 Regression: BC upgrade to 1.85\+ makes re-signing of already signed Authenticode signatures not verify

DSS-4014 Regression: Security hardening measure


SignServer 7.8

SignServer 7.8.1

August 2026

New Features

DSS-3867 Request metadata property SIGNATUREALGORITHM for PlainSigner

Improvements

DSS-3885 Update OIDC logout to use post_logout_redirect_uri for RP-Initiated Logout

Bug Fixes

DSS-3728 Fix failing probes on AJP ports

DSS-3819 Process by Certificate ID does not accept Worker name (String) as path parameter

DSS-3866 Request metadata property SIGNATUREALGORITHM introduced for PlainSigner - without requiring it to be explicitly configured to be allowed


SignServer 7.8.0

Released July 2026

New Features

DSS-3702 Add reload of cluster nodes to the admin interfaces

DSS-3774 Support for PGP signing with AWS Cloud HSM

DSS-3784 Introduce clustering mode where configuration is reloaded periodically

DSS-3785 Improve clustering mode to only reload changed configurations

DSS-3803 Add support to Renew Internal Key Binding Key During Certificate Renewal with AWS Cloud HSM

DSS-3834 Support for Git and Debian debsigs signing with SignWrapper GPG

Improvements

DSS-3657 Container: Set mandatory properties in the container in a default property file so they will not be mandatory in the user's deploy properties

Bug Fixes

DSS-3744 Hibernate error when using MS SQL Server and starting up SignServer with a non-empty database


SignServer 7.7

May 2026

New Features

DSS-3192 Add support for using a key URL to the JWT Authorizer

DSS-3320 Support for handling large input with the new -stdin flag

DSS-3387 Support for “-clientside” flag in SignClient in combination with the new “-stdin” flag

DSS-3475 Support for clientside hashing with PlainSigner and ML-DSA-EXTERNAL-MU

DSS-3535 Support for Composite signature in PlainSigner

DSS-3550 Support Generating SAN values in CSR

DSS-3579 Add support for NGINX as reverse proxy in SignServer Helm Chart

DSS-3633 Delete composite key

DSS-3689 Add get public key endpoint

DSS-3692 Add new Authenticode Signer using Jsign for all formats

Improvements

DSS-3243 OIDC environment variables for container

DSS-3310 Remove bundled selenium from SignServer

DSS-3383 Upgrade JJWT library

DSS-3668 Change loggings in CompositeHelper on each usage of a non-composite key to DEBUG

DSS-3688 Client-side hashing support for composites

DSS-3725 Update base image in container build for 7.7.0 release

DSS-3740 Upgrade log4j libs to version 2.25.4

Bug Fixes

DSS-3644 Can’t set composite key as a default key in CryptoToken.

DSS-3727 Regression: Container: 1G of memory not enough to deploy in WildFly



SignServer 7.6

February 2026

New Features

DSS-3350 Introduce new role for managed API calls by deploy-time configuration

DSS-3351 Support for read-only workers by deploy-time configuration

DSS-3352 Option to disallow the 'allow-any admin' setting by deploy-time configuration

DSS-3353 Support for making generated worker IDs start at a higher value by deploy-time configuration

DSS-3536 Sign with Extended CMSSigner and composite key

DSS-3635 Add support for the remaining composite algorithms supported by EJBCA and create test suite for all supported composite algorithms

Improvements

DSS-3500 Fix different base image being used for Ant download & Introduce ARG in Dockerfile to use the same everywhere

DSS-3522 Upgrade to BC 1.83

DSS-3526 Upgrade to P11NG 0.27.0

DSS-3559 Update copyright year for 2026

DSS-3565 Managed REST module should not startup if Managed roles are configured incorrectly

DSS-3571 Expose startup probe configuration in values.yaml for the SignServer Helm

DSS-3609 Support WildFly 39.0.1.Final and upgrade container to use it

DSS-3632 Update CloudHSM Docs to demonstrate how to set IDs of existing keys

Bug Fixes

DSS-3317 Make the SignServer Container runnable by other UID than 0 and 10001

DSS-3495 Regression: SoftHSM Clenkins job now broken with older SoftHSM version after fix supporting newer versions

DSS-3507 Regression: Failing timed services can cause excessive log output and increasing heap space usage

DSS-3610 Worker Name property is case sensitive when updating using different interfaces and allows duplicated worker names


SignServer 7.5

December 2025

New Features

DSS-2130 Option in CMS Signer for specifying signature algorithm as rsaEncryption

DSS-3293 Option in CMS Signer to not add NULL for SHA-2

Improvements

DSS-3195 Add option to switch between using own implementation or Jsign for MSI in SignClient with client-side hashing \+ upgrading POI

DSS-3298 Merge epic branch for official java 21 support

DSS-3314 Community: Remove unused method with know race condition

DSS-3347 Support latest WildFly 37 version and upgrade base container image with it for November milestone

DSS-3348 Upgrade JNA to 5.12.1

DSS-3355 Upgrade to container base image with Java 21

DSS-3362 Upgrade to BC 1.82 \+ KFC libraries

DSS-3429 Fix ClientCertAuthorizerRdnTest failures introduced when running Java 21

DSS-3451 Support latest WildFly 38 version and upgrade base container image with it for November milestone

DSS-3476 Do not include SpcSpOpusInfo object in Authenticode signatures if both program name and URL are empty

Bugs

DSS-3158 Fix community/customer build failures due to service-manifest-builder

DSS-3412 Our legacy webtests needs updating to work after the introduction of login page and session

DSS-3430 SignServer Container having double JRE installations and pulls in additional dependencies

DSS-3453 Jenkins jobs P11NG\_with\_DB\_Protection and SunP11\_with\_DB\_Protection are using soft keys

DSS-3454 Regression: Database protection using P11NG or SunPKCS11 gives configuration error and stops deployment

DSS-3492 Regression: SignServer requires the OIDC extension in the application server even if OIDC is not going to be used



SignServer 7.4

Released October 2025

New Features

DSS-3036 Add OIDC support in SignServer container

DSS-3230 Remove requirement for Crypto Workers to have a default key to be active

DSS-3234 Option to remove cmsAlgorithmProtect in ExtendedCMSSigner

DSS-3266 SignClient option for reading input from stdin \(working with rpmsign\)

DSS-3267 Support for RPM signing using SignWrapper-GPG

DSS-3279 Implement REST endpoints for listing workers/certificates supporting Signum MacOS Agent use case

DSS-3280 Add property to choose to use CRL or OCSP as priority in AdESSigner

Improvements

DSS-1814 PlainSigner should not require certificate

DSS-3025 Disable client certificate-based authorization in Admin web when OIDC is enabled \(by adding the oidc.properties file\)

DSS-3026 Error handling - oidc.properties file

DSS-3107 Add tests for OIDC implementation

DSS-3114 Remove EU repository cefdigital not needed anymore from pom.xml

DSS-3123 Issue with different provider rules

DSS-3124 Add visibility of authentication type in UI and style login/logout pages

DSS-3125 Add login/logout for client cert auth

DSS-3126 Add login/logout for OAuth

DSS-3147 Add validation of audience and configuration of it in oidc.properties

DSS-3160 Add support for Client side hashing for CAdES signer

DSS-3176 Add examples to OpenAPI and document the form-data fields

DSS-3202 Improve REST documentation

DSS-3224 Move hard coded callerGroupsClaim to oidc.properties

DSS-3226 Support Fortanix RSA with pre computed hash

DSS-3236 Allow caller to customize what's checked in healthcheck

DSS-3264 Change OpenPGPSigners to use RSA\_GENERAL instead of RSA\_SIGN or make it configurable

DSS-3265 Make OpenPGPSigner generated certificates with ECDSA work for RPM signing

DSS-3274 Change default signature algorithms in PlainSigner when client-side hashing is used

DSS-3294 Upgrade commons-lang3 to 3.18 or later due to CVE

DSS-3316 Change naming of managed key to be supported by AKV

DSS-3374 Upgrade commons-lang3 to 3.18 or later due to CVE

DSS-3392 OIDC callback servlet should not process callbacks when already logged in

DSS-3397 Improve list cert Ids test to not assume a specific order is returned

DSS-3400 Improve oidc.properties.sample

DSS-3402 Security hardening of legacy WS redirects

Bugs

DSS-3088 Documentation for enabling OpenAPI endpoint not working with WildFly 32/35 and EAP 8

DSS-3134 Incorrect "-" instead of "\_" in INTERNALLY-DETACHED/INTERNALLY\_DETACHED in template and docs

DSS-3146 cspPolicies cause to OIDC logout doesn't work properly in Chrome

DSS-3250 Admin web changes in the OIDC epic introduced new test failures

DSS-3255 Test keystore dss10\_signer1.p12 certificate expired Sun Jun 01 16:04:41 CEST 2025

DSS-3276 Authorization rule only imported for one worker when adding multiple using AdminCLI setproperties command

DSS-3345 Regression: Signing with PlainSigner always throws NullPointerException when NOCERTIFICATES=true and debug logging enabled

DSS-3361 PlainSigner set with NOCERTIFICATES=true with a Non existing DEFAULTKEY has Active status but throws an error when signing

DSS-3389 Regression: Status of worker is shown as OFFLINE if NOCERTIFICATES is used but key usage counter is not disabled and the key did not exist when the worker was loaded

DSS-3391 Regression: User name missing in top-right area in AdminWeb when client cert is used

DSS-3403 Regression: x509-common-util pom file breaks container build / pipeline that does not use JFrog repository

DSS-3410 Regression: Worker status reports error about missing key even when key has not been specified


SignServer 7.3

Released Internally May 2025

New Features

DSS-2803 Add Support for Thales DPOD for SignServer container

DSS-3014 Support for NONEwithRSAandMGF1 in SignumSigner

DSS-3069 Add support for WildFly 35.0.1.Final

DSS-3094 Contribution: Transaction support for signing and timed service (#111)

DSS-3117 Add support for running SignServer with all existing PKCS11 CryptoTokens instead backed by P11NG

Improvements

DSS-2798 Add support to REST for signing uploaded files

DSS-3077 Upgrade to BC 1.80 + KFC libraries

DSS-3104 Switch container base image to main keyfactor-commons/wildfly (using WF 35)

DSS-3105 Add support for AWS CloudHSM in container

DSS-3135 Implement KFC CryptoToken changes in SignServer for ML-DSA support in Fortanix

DSS-3155 Update container to use upgraded base image for SignServer 7.3.0

DSS-3178 Update documention link on public web to http://docs.keyfactor.com

Bug Fixes

DSS-2879 Can not sign (time-stamp) using Ed25519 with SoftHSM

DSS-3047 Regression: "Issue singing certificate" from EJBCA with peers/keybinding fails with only dummy cert in token

DSS-3119 OneTimeEJBCACAConnector and RenewalWorker etc., relaying on EjbcaWS/mTLS unsupported with P11NG

DSS-3120 OneTimeCryptoToken not working with P11NG

DSS-3139 OCSP required by AdESSigner even if signer certificate only has CRL, when level >= LT

DSS-3152 Make SunPKCS11 wrapper available from unnamed module for SignServer-DatabaseCLI to work with Java 17+



SignServer 7.2

Released February 2025

New Features

DSS-2807 Database Integrity Protection via CryptoTokens that are using their REST APIs

DSS-2847 Support Fortanix ECDSA with pre computed hash

DSS-2968 Add support for h2 database in container

DSS-2972 Add SignServer Dockerfile

Improvements

DSS-2891 Adding CAdES-B/T/LT/LTA to AdES signer

DSS-2892 Upgrade org.eclipse.jetty:jetty-http to version 12.0.12 or later

DSS-3029 Upgrade to P11NG 0.25.4 to enable Java TLS connections with the use of NJI11StaticSessionPrivateKey

DSS-3030 Increase number of threads available for REST based crypto tokens

DSS-3035 Update copyright year for 2025

DSS-3052 Bump up WildFly base image version for next release

Bug Fixes

DSS-2874 Regression: InvalidKeyException: Supplied key ... is not a RSAPrivateKey instance failures for XAdESSigner with SunP11 and P11NG after signing XAdES with AdESSigner

DSS-2878 P11NG: Signing of large files broken with PlainSigner as P11NG puts all data in memory before hashing

DSS-2880 P11NG: Importing certificate chain with duplicated certificate results in key entry without any certificate and the entry disappears

DSS-3050 Regression: Missing labels in container

DSS-3058 Security Issue



SignServer 7.1

Released November 2024

New Features

DSS-2858 Replace ML-DSA to SignServer

DSS-2866 Replace SLH-DSA to SignServer

Improvements

DSS-2790 Extend Support of the AppX Signer to support bundle signing

DSS-2855 Implement BC Beta 1.79

DSS-2856 Remove All Experimental PQ from SignServer

DSS-2857 Implement final BC PQC Production version ~1.79

DSS-2890 Upgrade commons-io:commons-io to 2.14.0 or later

DSS-2893 Refactor checks on top of all REST API methods

DSS-2895 Upgrade BC Beta version for 7.1 Beta release \(BC release October 25th, 2024\)

DSS-2901 Add tests and documentation for APPX bundle signing

DSS-2934 Add default signature algorithm for SLH-DSA and ML-DSA when signing


SignServer 7.0

Released October 2024

New Features

DSS-2786 Add Support for Thales DPOD when using P11NG

DSS-2800 Support for JBoss EAP 8 - Support for Jakarta EE 10

Improvements

DSS-1748 Test and Support SignServer with PostgreSQL 10+

DSS-2695 Upgrade to OpenPDF 1.3.34

DSS-2811 Drop support for DSA

DSS-2812 Upgrade x509-common-util and P11NG for 7.0

DSS-2814 PR #92 Update links in README etc

DSS-2815 Upgrade to Jakarta EE 10

DSS-2816 Upgrade sd-dss to 6.0

DSS-2817 Upgrade cesecore with support for Jakarta EE 10

DSS-2819 Patch commons-fileupload 1.5 to support Jakarta EE 10

DSS-2820 Upgrade REST Assured to 5.5.0

DSS-2821 Upgrade xmlsec to version 3.0.3

DSS-2822 Patch xades4j 2.2.1 to support Jakarta EE 10

DSS-2823 Upgrade guide to 7.0.0

DSS-2824 Upgrade apache cxf to version 4.0.4

DSS-2825 Upgrade jackson.core and jackson.module to 2.17.0

DSS-2826 Upgrade DeployTools to 2.3

DSS-2828 Upgrade to jakarta.jakartaee-api 10.0.0

DSS-2829 Upgrade jetty-util, jetty-io, jetty-http, and jetty-server to the same version and to work with Jakarta EE 10.

DSS-2833 Make SELFSIGNED_VALIDITY more robust

DSS-2834 Removed patched class after upgrade of OpenPDF

DSS-2836 Upgrade jacoco-maven-plugin to work with Java 17

DSS-2860 Drop support for Java 11

DSS-2867 Upgrade dependencies with reported vulnerable versions for 7.0

DSS-2869 Documentation: Clarify regarding masking of property value output in Admin CLI

DSS-2870 Add support for masking the output for getproperty and getconfig Admin CLI commands

DSS-2862 Changed the behavior of the SignServer Admin CLI when using the setproperty command to mask the PIN value

DSS-2791 Changed the behavior of the SignServer Admin CLI when using the setproperties command to mask the PIN value

Bug Fixes

DSS-2641 Authentication configuration not parsed properly when importing 2 or more workers

DSS-2773 JAR signature verification can fail after signing a jar file already signed by another tool

DSS-2780 Running admin CLI getstatus on a ZoneFileServerSideSigner gives exception

DSS-2784 Using large validity dates for self signed certificate is giving date in the past.

DSS-2796 JAR signature verification fails after signing a jar file already signed by another tool

DSS-2805 AdESSigner always checks revocation status of signer cert, even when NOCERTIFICATES=true is set

DSS-2808 Regression: P11NG: Key objects created when generating a wrapped key not explicitly removed

DSS-2818 Change in Java 17 breaks RenewalUtils.getRequestSignatureAlgorithm for EdDSA if a JCE cert is used

DSS-2830 Regression: Can not call RenewSignerBulkBean via JSF

DSS-2831 AdES Signer template can not be applied in AdminWeb

DSS-2832 Favicon not loading properly after JEE10 migration

DSS-2841 Regression: Can't add properties by clicking add in GUI

DSS-2850 Fix output of path to shortcut icon

DSS-2868 JSP error pages not loading different resources properly

DSS-2871 Regression: P11NG CryptoToken in web “RSA” shows as null

DSS-2872 Regression: "Missing key encoding" exception signing with XAdES Signer using PKCS#11



SignServer 6.3

Released May 2024

New Features

DSS-2658 - JUnit test - Support for SignServer REST interface in SignClient

DSS-2693 - MS SQL Support Part 2

DSS-2713 - Support of Signed Audit Logs on SignServer Container

DSS-2727 - Support for TimeMonitor in SignServer Container

DSS-2730 - Add environment variable support to enable (signed) audit logging

DSS-2735 - As an administrator I would like to use the REST API to be able to List and Get Workers and configuration

DSS-2747 - JUnit test - Support for SignServer HTTP interface in SignClient

DSS-2753 - Create a container for TimeMonitor

DSS-2755 - Documentation for SignServer Container Deployment

DSS-2770 - SBOM for SignServer Container

Improvements

DSS-2575 - Add list/table of deprecated and dropped features to the documentation

DSS-2576 - Upgrade the pending Maven plugin versions

DSS-2586 - Upgrade dnsjava to 3.5.2 and remove dnssecjava

DSS-2596 - Remove dependency: dom4j

DSS-2598 - Add tests for zone file signing using P11NG

DSS-2678 - Reduce overhead for listing keys with P11NG Crypto token

DSS-2702 - Move /openapi to /signserver/openapi

DSS-2703 - Document authorization/role needed for each REST call

DSS-2708 - Add systemtests for SignClient+REST+cert

DSS-2712 - Status Code Messages Mismatches on OpenAPI

DSS-2723 - Upgrade to P11NG 0.5.15

DSS-2750 - Upgrade org.eclipse.jetty:jetty-http to 9.4.52 or later

DSS-2751 - Upgrade org.apache.santuario:xmlsec to 2.2.6 or later

DSS-2764 - Upgrade Bouncy Castle to 1.78

Bug Fixes

DSS-2340 - Signature scheme RSASSA-PSS not working with XAdES-Baseline-T and higher profiles

DSS-2556 - Signature output tests fails on Windows (line-ending issue?)

DSS-2631 - Reproducible build (-DfixedTime) fails with Java 11

DSS-2633 - Performance/stresstest client does not print the results after SignServer 5.8.1

DSS-2670 - Can not install certificates with explicit ECC parameters

DSS-2701 - Dead code outside of source folder

DSS-2706 - SignClient gives full JSON response instead of just response data with protocol REST


SignServer 6.0

Released June 2023

New Features

DSS-2458 - Support for WildFly 26

DSS-2522 - Option to choose hash algorithm and to request certificate in performance test client

DSS-2529 - Use of other signature algorithm than SIGNATUREALGORITHM property for peers/remote key binding initiated signing requests

DSS-2538 - Dilithium algorithm support in CMS Signer

DSS-2539 - Support for CRYSTALS-Dilithium in Post Quantum verifier app

DSS-2560 - Add global configuration option to not display statuses on the workers page

DSS-2562 - CMS Signer re-signing support

DSS-2568 - Support for running on Java 17

DSS-2615 - Implement REST interface

Improvements

DSS-1921 - Switch default time-stamp format for MSAuthCodeSigner to RFC3161

DSS-2104 - Remove AdminGUI standalone application

DSS-2552 - Upgrade to Jakarta EE 8 API

DSS-2553 - Switch Java source level to 11

DSS-2555 - Upgrade BC to 1.73

DSS-2559 - Increase Zone file signers admin performance and options for disabling checks

DSS-2561 - Rename JackNJI11CryptoToken to P11NGCryptoToken

DSS-2564 - Update documentation after dropping Java 8 support

DSS-2565 - Drop support for older application servers

DSS-2566 - Drop support for OOXML signer

DSS-2567 - Drop support for ODF signer

DSS-2574 - First preliminary import of P11NG build from KFC

DSS-2577 - Upgrade library

DSS-2579 - Add script for manually installing dependencies that are not yet in Central repo

DSS-2581 - Upgrade to Jakarta XML Web Services (still using javax namespace)

DSS-2582 - Upgrade OpenPDF to 1.3.30

DSS-2587 - Upgrade jjwt to 0.11.5 and jackson to 2.12.6.1

DSS-2592 - Upgrade cxf to 3.5.5 and httpcomponents and jetty etc.

DSS-2594 - Upgrade xmlsec to 2.2.3

DSS-2597 - Contribution: Fix typo in error message of SignClient

DSS-2603 - Second preliminary import of P11NG build from EJBCA/KFC

DSS-2609 - Updated SignServer logo based on Keyfactor rebranding

DSS-2611 - UI dropdowns for PQ algorithms

DSS-2616 - Upgrade Xalan to 2.7.3

DSS-2617 - EJBCA Peer connection support for TLS 1.3

DSS-2621 - Exclude SignServer release notes from release package

Bug Fixes

DSS-2527 - SignServer changes the uploaded file name if contains special characters like "ä"

DSS-2550 - Drop support for patched JRE/SunPKCS11 and re-enable Javadoc building in Java 11

DSS-2551 - Remove SHA1 and DSA from JArchive Unit tests and enable ECDSA tests

DSS-2554 - Split tests for Debian Dpkg-sig signer to fix CE failures in jenkins

DSS-2573 - Regression: BC version number not updated in jboss-deployment-structure.xml

DSS-2580 - Keys not listed with P11NG Crypto Token after activation until after 2 min or after a new key is generated

DSS-2602 - Regression: Webtest DssQa97_SelectAllCheckbox fails on generate CSR page

DSS-2607 - Regression on running SignServer 6.0.0.Alpha3 from container - KFC issue

DSS-2624 - Regression: SunP11 broken with Java 17 also in EE after P11NG 0.1.1 upgrade (Part of DSS-2614)

DSS-2627 - Generating CSR using Dilithium not working


SignServer 5.11

SignServer 5.11.3

Internal Release

New Features

DSS-2522 - Option to choose hash algorithm and to request certificate in performance test client

DSS-2529 - Use of other signature algorithm than SIGNATUREALGORITHM property for peers/remote key binding initiated signing requests

DSS-2560 - Add global configuration option to not display statuses on the workers page

Improvements

DSS-2512 - Add standalone SNTP tool

DSS-2535 - Create JUnit tests for TSA_URL in PDFSigner

DSS-2536 - Add webtest for the 'not logged in' page of AdminWeb

DSS-2559 - Increase Zone file signers admin performance and options for disabling checks

DSS-2577 - Upgrade library

Bug Fixes

DSS-2521 - Expired hard coded certificate in test code

DSS-2526 - Worker Authorization "Reload from Database" doesn't work properly

DSS-2527 - SignServer changes the uploaded file name if contains special characters like "ä"

DSS-2544 - Some unit tests are failing during the build with Java 11 and 8

DSS-2545 - AdES signer unit tests started to fail as key size 2048 is no longer considered reliable for signature creation

DSS-2547 - PDF signature invalidates the previous one

DSS-2580 - Keys not listed with P11NG Crypto Token after activation until after 2 min or after a new key is generated

SignServer 5.11.1

Released December 2022

Bug Fixes

DSS-2533 - Regression: TSA_URL is not working in PDFSigner

DSS-2534 - Regression: Error page about connecting using certificate displayed blank

SignServer 5.11.0

Internal Release December 2022

New Features

DSS-825 - Implement internal SNTP client instead of executing the NTP commands in TimeMonitor

DSS-1902 - Support for building on Java 11

DSS-2428 - Add support for specifying RSA public exponent also with P11NG crypto token

DSS-2450 - Add option for MSAuthCode signatures to replace existing signatures

DSS-2469 - Support for running the web tests against a remote SignServer (of any packaging type)

DSS-2478 - GCP KMS PKCS#11 support in SignServer based on P11NG

DSS-2491 - Add support for Ed25519 on Utimaco (HSM custom mode)

DSS-2500 - Add support for SHA384withECDSA and SHA512withECDSA in MRTDSODSigner

DSS-2517 - Rebranded SignServer CE UI theme

Improvements

DSS-1942 - Remove WildFly remoting output from when running AdminCLI

DSS-2289 - Include class name in error message for incorrect time source

DSS-2315 - Update BC deprecated reference

DSS-2383 - Remove worker name from error messages from SODProcessServlet

DSS-2492 - Web UI hardening

DSS-2499 - P11NG-tool uses deprecated "which" command

DSS-2501 - Synchronize default P11 library definitions with EJBCA

DSS-2505 - Add parameter to specify self-signed DN when generating key pair with P11NG-tool

DSS-2507 - Add TRUSTANCHORS property to AdES Signer template

DSS-2508 - Clarify input format for PlainSigner in legacy client-side hashing mode with RSASSA-PKCS1_v1.5

DSS-2511 - Move TimeMonitor Manual into the normal documentation

DSS-2514 - Detection of HSM vendor in P11NG

DSS-2516 - Upgrade BC to 1.72

DSS-2525 - Upgrade dependencies

Bug Fixes

DSS-1681 - Confusing error message with alias selector, noauth and key wrapping

DSS-1811 - SignClient can not be run from directory having a space character in its file name

DSS-1815 - SignDocument Command fails with CLIENTWS & WEBSERVICES protocols if host not specified

DSS-2270 - JWT Authorizer: "Unknown issuer" is incorrectly logged

DSS-2342 - Error 500 when you reload audit log page with empty value for "Displaying results" or "Entries per page"

DSS-2397 - NPE when not specifying signature algorithm and using ECDSA

DSS-2399 - NPE in JwtAuthorizer

DSS-2412- Configuring JwtAuthorizer with public key in PEM format instead of Base64 gives IllegalArgumentException instead of being listed as error

DSS-2455 - Failed key test results rendered as success message instead of failure message

DSS-2483 - EMBED_CRL is in wrong place in the PDF Signer document

DSS-2489 - Transitive dependency on older Bouncy Castle (1.64) not excluded/overridden

DSS-2496 - Can not remove global configuration properties with special characters using delete button

DSS-2503 - P11NG tool fails to generate self-signed cert for ECDSA keypair

DSS-2504 - P11NG-tool gives return code 0 with unknown key algorithm

DSS-2509 - Client HTTP interface relays on platform encoding for data submitted in URL encoded form

DSS-2523 - JArchiveSigner worker template missing in CE


SignServer 5.9

SignServer 5.9.1

Released May 2022

New Features

DSS-2380 - Make key generation work with P11NG Tool with AWS CloudHSM

DSS-2381 - Support key entries without certificate with P11NG

Improvements

DSS-2369 - AdESSignerUnitTest fails in the build job

DSS-2451 - Add files that should not be tracked to .gitignore

DSS-2456 - Fix failing webtests

DSS-2457 - Do not fail parsing of PDF documents with negative indirect references

DSS-2459 - Upgrade BC to 1.71

DSS-2462 - Support for include certificate levels in APKHashSigner

DSS-2465 - Support in APK signers for certificate in config instead of import it into the token not only for other signers

DSS-2466 - Upgrade to OpenPDF 1.3.28

Bug Fixes

DSS-2453 - Keywrapping is not working with PostgreSQL

DSS-2463 - Regression: P11NG tool not included in P11NG CLI dist

DSS-2467 - Fail to verify the MSIX file signed with SignServer

SignServer 5.9.0

Released April 2022

New Features

DSS-2405 - Support for JBoss EAP 7.4

DSS-2438 - Support for switching web theme

Improvements

DSS-1498 - Support in PlainSigner for client-side hashing with PKCS1 v1.5 with encoding on server-side

DSS-2192 - Use the new worker properties bulk editing method in system tests

DSS-2352 - Support in APK signers for certificate in config instead of import it into the token

DSS-2390 - Upgrade JackNJI11 to a version with upstreams and our changes - 1.2-pk2

DSS-2415 - Support DER-reencode also for client-side hashing mode in CMSSigner

DSS-2423 - MasterListSigner support for files larger than 1 MB

DSS-2425 - Add support for signing a protected PDF without supplying owner password

DSS-2426 - Upgrade/migrate to OpenPDF in PDFSigner

DSS-2435 - Documentation note regarding SoftHSM2 and key wrapping mechnisms

DSS-2436 - Do not fail for directories and clarify in documentation that -indir does not go into directories

DSS-2437 - Remove custom security manager used in some junit tests

DSS-2439 - Improve the test coverage for P11NG

DSS-2442 - Initialize signing closer to the actual signing in PDFSigner

DSS-2443 - Update copyright year for 2022

DSS-2444 - Upgrade JackNJI11 to 1.2-pk3

Bug Fixes

DSS-1985 - UsernamePasswordAuthorizer uses platform encoding

DSS-2440 - Failing or aborting in the middle of a multi-part signing can lead to CKR_OPERATION_ACTIVE errors when that session is later being reused


SignServer 5.8

SignServer 5.8.1

Released December 2021

New Features

DSS-2279 - EC support with P11NG

DSS-2367 - Signed Signature Request through Web Service API based on format specification

DSS-2375 - Support for WildFly 24

Improvements

DSS-2278 - Merge updated P11NG from EJBCA 7.8.0.1

DSS-2353 - Key removal operation consistency between P11NG and SunPKCS11

DSS-2379 - Document supported algorithms

DSS-2384 - Add demo client certificate issued by a sub CA

DSS-2394 - P11NG signature provider implementation should throw JCA exceptions instead of P11NG-specific runtime exceptions

DSS-2402 - Upgrade BC to 1.70

Bug Fixes

DSS-2382 - Issue with overriding DIGESTALGORITHM in PDF

DSS-2385 - JUnit test MRTDSODSignerTest signer certificate expired

DSS-2389 - Security Issue

DSS-2391 - Regression: Client-side hashing on Windows fails with "used by another process"

DSS-2396 - Certain recent JRE versions breaks PKCS11CryptoToken

DSS-2401 - Security Issue

SignServer 5.8.0

Released October 2021

New Features

DSS-2285 - Extend validity of already PAdES signed document (PAdES-LTA)

DSS-2306 - Extend validity of already signed XAdES file for XAdES-LTA profile

DSS-2331 - Certificate User Data Mapping from JWT

DSS-2332 - Peers Connection where SignServer acts as RA: Implementing Peers "RA mode"

DSS-2333 - EJBCA Peers CA Connector for use with OneTimeCryptoWorker

DSS-2359 - Signed signature requests (Server Authorization)

DSS-2360 - SignClient support for signed signature requests

DSS-2371 - Support for one-time keys using peers and P11NG

Improvements

DSS-2275 - Respond with failure for incorrectly formatted time-stamp requests

DSS-2277 - Upgrade BC to 1.69 (when available) with stricter TS request checks

DSS-2329 - Handle larger signatures in PAdES Signer

DSS-2354 - Worker template for AdESSigner is missing properties

DSS-2361 - Document that AdES Signer TRUSTANCHOR property could be needed if PDF is already signed

DSS-2362 - Better error handling for unexpected AdES Signer failures

DSS-2368 - Improved SignClient support for signed signature requests

Bug Fixes

DSS-2357 - Some JAR verification test failures since a later Java 8 version

DSS-2358 - AdES Signer gives error when used with OneTimeCryptoWorker


SignServer 5.7

Released July 2021

New Features

DSS-2248 - Per-request option for page and signature placement in PDF

DSS-2272 - Signing of Microsoft catalog files

DSS-2281 - PAdES-B baseline profile signature support

DSS-2282 - PAdES-T baseline profile signature support

DSS-2283 - PAdES-LT baseline profile signature support

DSS-2284 - PAdES-LTA baseline profile signature support

DSS-2286 - XAdES-LT baseline profile signature support

DSS-2288 - Add support for the NONEwithRSAandMGF1 (raw RSASSA-PSS) signature algorithm in P11NG

DSS-2290 - Support for overriding properties in the PDF Signer

DSS-2303 - XAdES-B baseline profile signature support

DSS-2304 - XAdES-T baseline profile signature support

DSS-2305 - XAdES-LTA baseline profile signature support

DSS-2337 - Worker property to configure extra/adjust signature size in PAdES

Improvements

DSS-2291 - Document getPKCS10CertificateRequestForAlias2 WS operation

DSS-2295 - Introduce git ignore files and add some IDE specific ignores to SVN

DSS-2298 - Upgrade external dependencies

DSS-2346 - Previous worker name not removed from cache after rename

DSS-2347 - Workers removed from AdminWeb kept in cache

Tasks

DSS-2299 - Add DSS library as dependency

DSS-2300 - Document differences between old PDF Signer and PAdES Signer

DSS-2301 - Create AdES module

DSS-2302 - First Signer implementation (hard coded config)

DSS-2311 - Remove any unneeded DSS dependencies and update JARs/project lists

DSS-2323 - Add support for CRL in PAdES-LT and higher levels

DSS-2327 - Switch from PDFBox to OpenPDF in AdES signer

Bug Fixes

DSS-2197 - Regression: RSASSA-PSS / SHA256withRSAandMGF1 etc. broken with P11NG

DSS-2271 - PDF Signer worker property visible signature resize/scaling naming inconsistency

DSS-2321 - Time-stamp signer test certificate expired

DSS-2325 - Test certificate in dss10_signer3.p12 expired

DSS-2326 - Hardcoded certificate in XMLValidatorTestData expired


SignServer 5.6

SignServer 5.6.1

Released April 2021

Improvements

DSS-2255 - Upgrade BC to 1.68

DSS-2261 - Give error for WS requests at high priority not configured for such

DSS-2287 - Support both old and new algorithm names for SHAxWithRSAandMGF1 / SHAxWithRSASSA-PSS in Plain Signer

DSS-2294 - Web filter that can be overriden

DSS-2295 - Introduce git ignore files and add some IDE specific ignores to SVN

Bug Fixes

DSS-2257 - Setting debug logging in SignClient Windows batch file is broken

DSS-2268 - Algorithms such as SHAxWithRSAandMGF1 not working with OpenJDK 8u.x even though they should be supported

DSS-2269 - Request metadata value passed through SignClient can not contain equals sign

DSS-2293 - Regression: Duplicated WSDL files and file names only different by casing may cause issues if building from source in Windows

DSS-2296 - AdminWS call getPKCS10CertificateRequestForAlias is broken on newer SignServer

SignServer 5.6.0

Released February 2021

New Features

DSS-934 - Add support in MSAuthCodeSigner for signing already signed PE files

DSS-1834 - Add support in MSAuthCodeSigner for signing already signed MSI files

DSS-2264 - Request Prioritization

Improvements

DSS-2120 - Add "Reload from database" button for authorizations

DSS-2259 - Improve flexibility for PDF signer CryptoToken access

DSS-2263 - Increase performance for key generation when P11NG is used

Tasks

DSS-2208 - Creation of new Web Filter : Implementation based on Jetty QoSFilter

DSS-2209 - Add global configuration for web filter

DSS-2210 - Use correct priority based on config and worker

DSS-2211 - Create a SleepWorker (for testing)

DSS-2214 - SignClient to use new URLs: Allow to use /worker/WORKERNAME

DSS-2238 - Filter SOAP Web Services

DSS-2256 - Update copyright year for 2021

Bug Fixes

DSS-2223 - Producer field corrupted in signed PDF

DSS-2224 - Stresstest tool lockups at exit with QoS Filter

DSS-2226 - Some tests in SignClientP11AuthTest fails with QoSFilter enabled

DSS-2229 - NPE if V1_SIGNATURE_NAME not specified and certificate is not in token