The following lists change logs for all SignServer versions released, sorted by date and listed per release in the table of contents below.
For more information on a specific release, see the respective SignServer Release Notes for details on issues resolved in the release.
SignServer 7.9
Released September 2026
Improvements
DSS-3892 Support WildFly 41.0.1 and upgrade container
DSS-3910 Exclude additional worker templates when replacewithmanaged=true
DSS-3943 Fix AJP with WF 41 & document AJP deprecation
Bug Fixes
DSS-3781 Fixed the “Reload from Database” button on Global Configuration page
DSS-3821 Regression: Inconsistency with public key vs. certificate for key usage counter initialization causes worker to be offline if counter is enabled and certificate uses explicit ECC.
DSS-3824 Fixed inconsistencies in the responses of GET /publickeys and GET /certificates endpoints
DSS-3920 Can not build without using internal repository: Could not find artifact com.keyfactor:cryptotokens:pom:3.10.1 in central
DSS-3954 Made SignServer Helm chart work with NGINX after WF 41 upgrade
DSS-4011 Regression: BC upgrade to 1.85\+ makes re-signing of already signed Authenticode signatures not verify
DSS-4014 Regression: Security hardening measure
SignServer 7.8
SignServer 7.8.1
August 2026
New Features
DSS-3867 Request metadata property SIGNATUREALGORITHM for PlainSigner
Improvements
DSS-3885 Update OIDC logout to use post_logout_redirect_uri for RP-Initiated Logout
Bug Fixes
DSS-3728 Fix failing probes on AJP ports
DSS-3819 Process by Certificate ID does not accept Worker name (String) as path parameter
DSS-3866 Request metadata property SIGNATUREALGORITHM introduced for PlainSigner - without requiring it to be explicitly configured to be allowed
SignServer 7.8.0
Released July 2026
New Features
DSS-3702 Add reload of cluster nodes to the admin interfaces
DSS-3774 Support for PGP signing with AWS Cloud HSM
DSS-3784 Introduce clustering mode where configuration is reloaded periodically
DSS-3785 Improve clustering mode to only reload changed configurations
DSS-3803 Add support to Renew Internal Key Binding Key During Certificate Renewal with AWS Cloud HSM
DSS-3834 Support for Git and Debian debsigs signing with SignWrapper GPG
Improvements
DSS-3657 Container: Set mandatory properties in the container in a default property file so they will not be mandatory in the user's deploy properties
Bug Fixes
DSS-3744 Hibernate error when using MS SQL Server and starting up SignServer with a non-empty database
SignServer 7.7
May 2026
New Features
DSS-3192 Add support for using a key URL to the JWT Authorizer
DSS-3320 Support for handling large input with the new -stdin flag
DSS-3387 Support for “-clientside” flag in SignClient in combination with the new “-stdin” flag
DSS-3475 Support for clientside hashing with PlainSigner and ML-DSA-EXTERNAL-MU
DSS-3535 Support for Composite signature in PlainSigner
DSS-3550 Support Generating SAN values in CSR
DSS-3579 Add support for NGINX as reverse proxy in SignServer Helm Chart
DSS-3633 Delete composite key
DSS-3689 Add get public key endpoint
DSS-3692 Add new Authenticode Signer using Jsign for all formats
Improvements
DSS-3243 OIDC environment variables for container
DSS-3310 Remove bundled selenium from SignServer
DSS-3383 Upgrade JJWT library
DSS-3668 Change loggings in CompositeHelper on each usage of a non-composite key to DEBUG
DSS-3688 Client-side hashing support for composites
DSS-3725 Update base image in container build for 7.7.0 release
DSS-3740 Upgrade log4j libs to version 2.25.4
Bug Fixes
DSS-3644 Can’t set composite key as a default key in CryptoToken.
DSS-3727 Regression: Container: 1G of memory not enough to deploy in WildFly
SignServer 7.6
February 2026
New Features
DSS-3350 Introduce new role for managed API calls by deploy-time configuration
DSS-3351 Support for read-only workers by deploy-time configuration
DSS-3352 Option to disallow the 'allow-any admin' setting by deploy-time configuration
DSS-3353 Support for making generated worker IDs start at a higher value by deploy-time configuration
DSS-3536 Sign with Extended CMSSigner and composite key
DSS-3635 Add support for the remaining composite algorithms supported by EJBCA and create test suite for all supported composite algorithms
Improvements
DSS-3500 Fix different base image being used for Ant download & Introduce ARG in Dockerfile to use the same everywhere
DSS-3522 Upgrade to BC 1.83
DSS-3526 Upgrade to P11NG 0.27.0
DSS-3559 Update copyright year for 2026
DSS-3565 Managed REST module should not startup if Managed roles are configured incorrectly
DSS-3571 Expose startup probe configuration in values.yaml for the SignServer Helm
DSS-3609 Support WildFly 39.0.1.Final and upgrade container to use it
DSS-3632 Update CloudHSM Docs to demonstrate how to set IDs of existing keys
Bug Fixes
DSS-3317 Make the SignServer Container runnable by other UID than 0 and 10001
DSS-3495 Regression: SoftHSM Clenkins job now broken with older SoftHSM version after fix supporting newer versions
DSS-3507 Regression: Failing timed services can cause excessive log output and increasing heap space usage
DSS-3610 Worker Name property is case sensitive when updating using different interfaces and allows duplicated worker names
SignServer 7.5
December 2025
New Features
DSS-2130 Option in CMS Signer for specifying signature algorithm as rsaEncryption
DSS-3293 Option in CMS Signer to not add NULL for SHA-2
Improvements
DSS-3195 Add option to switch between using own implementation or Jsign for MSI in SignClient with client-side hashing \+ upgrading POI
DSS-3298 Merge epic branch for official java 21 support
DSS-3314 Community: Remove unused method with know race condition
DSS-3347 Support latest WildFly 37 version and upgrade base container image with it for November milestone
DSS-3348 Upgrade JNA to 5.12.1
DSS-3355 Upgrade to container base image with Java 21
DSS-3362 Upgrade to BC 1.82 \+ KFC libraries
DSS-3429 Fix ClientCertAuthorizerRdnTest failures introduced when running Java 21
DSS-3451 Support latest WildFly 38 version and upgrade base container image with it for November milestone
DSS-3476 Do not include SpcSpOpusInfo object in Authenticode signatures if both program name and URL are empty
Bugs
DSS-3158 Fix community/customer build failures due to service-manifest-builder
DSS-3412 Our legacy webtests needs updating to work after the introduction of login page and session
DSS-3430 SignServer Container having double JRE installations and pulls in additional dependencies
DSS-3453 Jenkins jobs P11NG\_with\_DB\_Protection and SunP11\_with\_DB\_Protection are using soft keys
DSS-3454 Regression: Database protection using P11NG or SunPKCS11 gives configuration error and stops deployment
DSS-3492 Regression: SignServer requires the OIDC extension in the application server even if OIDC is not going to be used
SignServer 7.4
Released October 2025
New Features
DSS-3036 Add OIDC support in SignServer container
DSS-3230 Remove requirement for Crypto Workers to have a default key to be active
DSS-3234 Option to remove cmsAlgorithmProtect in ExtendedCMSSigner
DSS-3266 SignClient option for reading input from stdin \(working with rpmsign\)
DSS-3267 Support for RPM signing using SignWrapper-GPG
DSS-3279 Implement REST endpoints for listing workers/certificates supporting Signum MacOS Agent use case
DSS-3280 Add property to choose to use CRL or OCSP as priority in AdESSigner
Improvements
DSS-1814 PlainSigner should not require certificate
DSS-3025 Disable client certificate-based authorization in Admin web when OIDC is enabled \(by adding the oidc.properties file\)
DSS-3026 Error handling - oidc.properties file
DSS-3107 Add tests for OIDC implementation
DSS-3114 Remove EU repository cefdigital not needed anymore from pom.xml
DSS-3123 Issue with different provider rules
DSS-3124 Add visibility of authentication type in UI and style login/logout pages
DSS-3125 Add login/logout for client cert auth
DSS-3126 Add login/logout for OAuth
DSS-3147 Add validation of audience and configuration of it in oidc.properties
DSS-3160 Add support for Client side hashing for CAdES signer
DSS-3176 Add examples to OpenAPI and document the form-data fields
DSS-3202 Improve REST documentation
DSS-3224 Move hard coded callerGroupsClaim to oidc.properties
DSS-3226 Support Fortanix RSA with pre computed hash
DSS-3236 Allow caller to customize what's checked in healthcheck
DSS-3264 Change OpenPGPSigners to use RSA\_GENERAL instead of RSA\_SIGN or make it configurable
DSS-3265 Make OpenPGPSigner generated certificates with ECDSA work for RPM signing
DSS-3274 Change default signature algorithms in PlainSigner when client-side hashing is used
DSS-3294 Upgrade commons-lang3 to 3.18 or later due to CVE
DSS-3316 Change naming of managed key to be supported by AKV
DSS-3374 Upgrade commons-lang3 to 3.18 or later due to CVE
DSS-3392 OIDC callback servlet should not process callbacks when already logged in
DSS-3397 Improve list cert Ids test to not assume a specific order is returned
DSS-3400 Improve oidc.properties.sample
DSS-3402 Security hardening of legacy WS redirects
Bugs
DSS-3088 Documentation for enabling OpenAPI endpoint not working with WildFly 32/35 and EAP 8
DSS-3134 Incorrect "-" instead of "\_" in INTERNALLY-DETACHED/INTERNALLY\_DETACHED in template and docs
DSS-3146 cspPolicies cause to OIDC logout doesn't work properly in Chrome
DSS-3250 Admin web changes in the OIDC epic introduced new test failures
DSS-3255 Test keystore dss10\_signer1.p12 certificate expired Sun Jun 01 16:04:41 CEST 2025
DSS-3276 Authorization rule only imported for one worker when adding multiple using AdminCLI setproperties command
DSS-3345 Regression: Signing with PlainSigner always throws NullPointerException when NOCERTIFICATES=true and debug logging enabled
DSS-3361 PlainSigner set with NOCERTIFICATES=true with a Non existing DEFAULTKEY has Active status but throws an error when signing
DSS-3389 Regression: Status of worker is shown as OFFLINE if NOCERTIFICATES is used but key usage counter is not disabled and the key did not exist when the worker was loaded
DSS-3391 Regression: User name missing in top-right area in AdminWeb when client cert is used
DSS-3403 Regression: x509-common-util pom file breaks container build / pipeline that does not use JFrog repository
DSS-3410 Regression: Worker status reports error about missing key even when key has not been specified
SignServer 7.3
Released Internally May 2025
New Features
DSS-2803 Add Support for Thales DPOD for SignServer container
DSS-3014 Support for NONEwithRSAandMGF1 in SignumSigner
DSS-3069 Add support for WildFly 35.0.1.Final
DSS-3094 Contribution: Transaction support for signing and timed service (#111)
DSS-3117 Add support for running SignServer with all existing PKCS11 CryptoTokens instead backed by P11NG
Improvements
DSS-2798 Add support to REST for signing uploaded files
DSS-3077 Upgrade to BC 1.80 + KFC libraries
DSS-3104 Switch container base image to main keyfactor-commons/wildfly (using WF 35)
DSS-3105 Add support for AWS CloudHSM in container
DSS-3135 Implement KFC CryptoToken changes in SignServer for ML-DSA support in Fortanix
DSS-3155 Update container to use upgraded base image for SignServer 7.3.0
DSS-3178 Update documention link on public web to http://docs.keyfactor.com
Bug Fixes
DSS-2879 Can not sign (time-stamp) using Ed25519 with SoftHSM
DSS-3047 Regression: "Issue singing certificate" from EJBCA with peers/keybinding fails with only dummy cert in token
DSS-3119 OneTimeEJBCACAConnector and RenewalWorker etc., relaying on EjbcaWS/mTLS unsupported with P11NG
DSS-3120 OneTimeCryptoToken not working with P11NG
DSS-3139 OCSP required by AdESSigner even if signer certificate only has CRL, when level >= LT
DSS-3152 Make SunPKCS11 wrapper available from unnamed module for SignServer-DatabaseCLI to work with Java 17+
SignServer 7.2
Released February 2025
New Features
DSS-2807 Database Integrity Protection via CryptoTokens that are using their REST APIs
DSS-2847 Support Fortanix ECDSA with pre computed hash
DSS-2968 Add support for h2 database in container
DSS-2972 Add SignServer Dockerfile
Improvements
DSS-2891 Adding CAdES-B/T/LT/LTA to AdES signer
DSS-2892 Upgrade org.eclipse.jetty:jetty-http to version 12.0.12 or later
DSS-3029 Upgrade to P11NG 0.25.4 to enable Java TLS connections with the use of NJI11StaticSessionPrivateKey
DSS-3030 Increase number of threads available for REST based crypto tokens
DSS-3035 Update copyright year for 2025
DSS-3052 Bump up WildFly base image version for next release
Bug Fixes
DSS-2874 Regression: InvalidKeyException: Supplied key ... is not a RSAPrivateKey instance failures for XAdESSigner with SunP11 and P11NG after signing XAdES with AdESSigner
DSS-2878 P11NG: Signing of large files broken with PlainSigner as P11NG puts all data in memory before hashing
DSS-2880 P11NG: Importing certificate chain with duplicated certificate results in key entry without any certificate and the entry disappears
DSS-3050 Regression: Missing labels in container
DSS-3058 Security Issue
SignServer 7.1
Released November 2024
New Features
DSS-2858 Replace ML-DSA to SignServer
DSS-2866 Replace SLH-DSA to SignServer
Improvements
DSS-2790 Extend Support of the AppX Signer to support bundle signing
DSS-2855 Implement BC Beta 1.79
DSS-2856 Remove All Experimental PQ from SignServer
DSS-2857 Implement final BC PQC Production version ~1.79
DSS-2890 Upgrade commons-io:commons-io to 2.14.0 or later
DSS-2893 Refactor checks on top of all REST API methods
DSS-2895 Upgrade BC Beta version for 7.1 Beta release \(BC release October 25th, 2024\)
DSS-2901 Add tests and documentation for APPX bundle signing
DSS-2934 Add default signature algorithm for SLH-DSA and ML-DSA when signing
SignServer 7.0
Released October 2024
New Features
DSS-2786 Add Support for Thales DPOD when using P11NG
DSS-2800 Support for JBoss EAP 8 - Support for Jakarta EE 10
Improvements
DSS-1748 Test and Support SignServer with PostgreSQL 10+
DSS-2695 Upgrade to OpenPDF 1.3.34
DSS-2811 Drop support for DSA
DSS-2812 Upgrade x509-common-util and P11NG for 7.0
DSS-2814 PR #92 Update links in README etc
DSS-2815 Upgrade to Jakarta EE 10
DSS-2816 Upgrade sd-dss to 6.0
DSS-2817 Upgrade cesecore with support for Jakarta EE 10
DSS-2819 Patch commons-fileupload 1.5 to support Jakarta EE 10
DSS-2820 Upgrade REST Assured to 5.5.0
DSS-2821 Upgrade xmlsec to version 3.0.3
DSS-2822 Patch xades4j 2.2.1 to support Jakarta EE 10
DSS-2823 Upgrade guide to 7.0.0
DSS-2824 Upgrade apache cxf to version 4.0.4
DSS-2825 Upgrade jackson.core and jackson.module to 2.17.0
DSS-2826 Upgrade DeployTools to 2.3
DSS-2828 Upgrade to jakarta.jakartaee-api 10.0.0
DSS-2829 Upgrade jetty-util, jetty-io, jetty-http, and jetty-server to the same version and to work with Jakarta EE 10.
DSS-2833 Make SELFSIGNED_VALIDITY more robust
DSS-2834 Removed patched class after upgrade of OpenPDF
DSS-2836 Upgrade jacoco-maven-plugin to work with Java 17
DSS-2860 Drop support for Java 11
DSS-2867 Upgrade dependencies with reported vulnerable versions for 7.0
DSS-2869 Documentation: Clarify regarding masking of property value output in Admin CLI
DSS-2870 Add support for masking the output for getproperty and getconfig Admin CLI commands
DSS-2862 Changed the behavior of the SignServer Admin CLI when using the setproperty command to mask the PIN value
DSS-2791 Changed the behavior of the SignServer Admin CLI when using the setproperties command to mask the PIN value
Bug Fixes
DSS-2641 Authentication configuration not parsed properly when importing 2 or more workers
DSS-2773 JAR signature verification can fail after signing a jar file already signed by another tool
DSS-2780 Running admin CLI getstatus on a ZoneFileServerSideSigner gives exception
DSS-2784 Using large validity dates for self signed certificate is giving date in the past.
DSS-2796 JAR signature verification fails after signing a jar file already signed by another tool
DSS-2805 AdESSigner always checks revocation status of signer cert, even when NOCERTIFICATES=true is set
DSS-2808 Regression: P11NG: Key objects created when generating a wrapped key not explicitly removed
DSS-2818 Change in Java 17 breaks RenewalUtils.getRequestSignatureAlgorithm for EdDSA if a JCE cert is used
DSS-2830 Regression: Can not call RenewSignerBulkBean via JSF
DSS-2831 AdES Signer template can not be applied in AdminWeb
DSS-2832 Favicon not loading properly after JEE10 migration
DSS-2841 Regression: Can't add properties by clicking add in GUI
DSS-2850 Fix output of path to shortcut icon
DSS-2868 JSP error pages not loading different resources properly
DSS-2871 Regression: P11NG CryptoToken in web “RSA” shows as null
DSS-2872 Regression: "Missing key encoding" exception signing with XAdES Signer using PKCS#11
SignServer 6.3
Released May 2024
New Features
DSS-2658 - JUnit test - Support for SignServer REST interface in SignClient
DSS-2693 - MS SQL Support Part 2
DSS-2713 - Support of Signed Audit Logs on SignServer Container
DSS-2727 - Support for TimeMonitor in SignServer Container
DSS-2730 - Add environment variable support to enable (signed) audit logging
DSS-2735 - As an administrator I would like to use the REST API to be able to List and Get Workers and configuration
DSS-2747 - JUnit test - Support for SignServer HTTP interface in SignClient
DSS-2753 - Create a container for TimeMonitor
DSS-2755 - Documentation for SignServer Container Deployment
DSS-2770 - SBOM for SignServer Container
Improvements
DSS-2575 - Add list/table of deprecated and dropped features to the documentation
DSS-2576 - Upgrade the pending Maven plugin versions
DSS-2586 - Upgrade dnsjava to 3.5.2 and remove dnssecjava
DSS-2596 - Remove dependency: dom4j
DSS-2598 - Add tests for zone file signing using P11NG
DSS-2678 - Reduce overhead for listing keys with P11NG Crypto token
DSS-2702 - Move /openapi to /signserver/openapi
DSS-2703 - Document authorization/role needed for each REST call
DSS-2708 - Add systemtests for SignClient+REST+cert
DSS-2712 - Status Code Messages Mismatches on OpenAPI
DSS-2723 - Upgrade to P11NG 0.5.15
DSS-2750 - Upgrade org.eclipse.jetty:jetty-http to 9.4.52 or later
DSS-2751 - Upgrade org.apache.santuario:xmlsec to 2.2.6 or later
DSS-2764 - Upgrade Bouncy Castle to 1.78
Bug Fixes
DSS-2340 - Signature scheme RSASSA-PSS not working with XAdES-Baseline-T and higher profiles
DSS-2556 - Signature output tests fails on Windows (line-ending issue?)
DSS-2631 - Reproducible build (-DfixedTime) fails with Java 11
DSS-2633 - Performance/stresstest client does not print the results after SignServer 5.8.1
DSS-2670 - Can not install certificates with explicit ECC parameters
DSS-2701 - Dead code outside of source folder
DSS-2706 - SignClient gives full JSON response instead of just response data with protocol REST
SignServer 6.0
Released June 2023
New Features
DSS-2458 - Support for WildFly 26
DSS-2522 - Option to choose hash algorithm and to request certificate in performance test client
DSS-2529 - Use of other signature algorithm than SIGNATUREALGORITHM property for peers/remote key binding initiated signing requests
DSS-2538 - Dilithium algorithm support in CMS Signer
DSS-2539 - Support for CRYSTALS-Dilithium in Post Quantum verifier app
DSS-2560 - Add global configuration option to not display statuses on the workers page
DSS-2562 - CMS Signer re-signing support
DSS-2568 - Support for running on Java 17
DSS-2615 - Implement REST interface
Improvements
DSS-1921 - Switch default time-stamp format for MSAuthCodeSigner to RFC3161
DSS-2104 - Remove AdminGUI standalone application
DSS-2552 - Upgrade to Jakarta EE 8 API
DSS-2553 - Switch Java source level to 11
DSS-2555 - Upgrade BC to 1.73
DSS-2559 - Increase Zone file signers admin performance and options for disabling checks
DSS-2561 - Rename JackNJI11CryptoToken to P11NGCryptoToken
DSS-2564 - Update documentation after dropping Java 8 support
DSS-2565 - Drop support for older application servers
DSS-2566 - Drop support for OOXML signer
DSS-2567 - Drop support for ODF signer
DSS-2574 - First preliminary import of P11NG build from KFC
DSS-2577 - Upgrade library
DSS-2579 - Add script for manually installing dependencies that are not yet in Central repo
DSS-2581 - Upgrade to Jakarta XML Web Services (still using javax namespace)
DSS-2582 - Upgrade OpenPDF to 1.3.30
DSS-2587 - Upgrade jjwt to 0.11.5 and jackson to 2.12.6.1
DSS-2592 - Upgrade cxf to 3.5.5 and httpcomponents and jetty etc.
DSS-2594 - Upgrade xmlsec to 2.2.3
DSS-2597 - Contribution: Fix typo in error message of SignClient
DSS-2603 - Second preliminary import of P11NG build from EJBCA/KFC
DSS-2609 - Updated SignServer logo based on Keyfactor rebranding
DSS-2611 - UI dropdowns for PQ algorithms
DSS-2616 - Upgrade Xalan to 2.7.3
DSS-2617 - EJBCA Peer connection support for TLS 1.3
DSS-2621 - Exclude SignServer release notes from release package
Bug Fixes
DSS-2527 - SignServer changes the uploaded file name if contains special characters like "ä"
DSS-2550 - Drop support for patched JRE/SunPKCS11 and re-enable Javadoc building in Java 11
DSS-2551 - Remove SHA1 and DSA from JArchive Unit tests and enable ECDSA tests
DSS-2554 - Split tests for Debian Dpkg-sig signer to fix CE failures in jenkins
DSS-2573 - Regression: BC version number not updated in jboss-deployment-structure.xml
DSS-2580 - Keys not listed with P11NG Crypto Token after activation until after 2 min or after a new key is generated
DSS-2602 - Regression: Webtest DssQa97_SelectAllCheckbox fails on generate CSR page
DSS-2607 - Regression on running SignServer 6.0.0.Alpha3 from container - KFC issue
DSS-2624 - Regression: SunP11 broken with Java 17 also in EE after P11NG 0.1.1 upgrade (Part of DSS-2614)
DSS-2627 - Generating CSR using Dilithium not working
SignServer 5.11
SignServer 5.11.3
Internal Release
New Features
DSS-2522 - Option to choose hash algorithm and to request certificate in performance test client
DSS-2529 - Use of other signature algorithm than SIGNATUREALGORITHM property for peers/remote key binding initiated signing requests
DSS-2560 - Add global configuration option to not display statuses on the workers page
Improvements
DSS-2512 - Add standalone SNTP tool
DSS-2535 - Create JUnit tests for TSA_URL in PDFSigner
DSS-2536 - Add webtest for the 'not logged in' page of AdminWeb
DSS-2559 - Increase Zone file signers admin performance and options for disabling checks
DSS-2577 - Upgrade library
Bug Fixes
DSS-2521 - Expired hard coded certificate in test code
DSS-2526 - Worker Authorization "Reload from Database" doesn't work properly
DSS-2527 - SignServer changes the uploaded file name if contains special characters like "ä"
DSS-2544 - Some unit tests are failing during the build with Java 11 and 8
DSS-2545 - AdES signer unit tests started to fail as key size 2048 is no longer considered reliable for signature creation
DSS-2547 - PDF signature invalidates the previous one
DSS-2580 - Keys not listed with P11NG Crypto Token after activation until after 2 min or after a new key is generated
SignServer 5.11.1
Released December 2022
Bug Fixes
DSS-2533 - Regression: TSA_URL is not working in PDFSigner
DSS-2534 - Regression: Error page about connecting using certificate displayed blank
SignServer 5.11.0
Internal Release December 2022
New Features
DSS-825 - Implement internal SNTP client instead of executing the NTP commands in TimeMonitor
DSS-1902 - Support for building on Java 11
DSS-2428 - Add support for specifying RSA public exponent also with P11NG crypto token
DSS-2450 - Add option for MSAuthCode signatures to replace existing signatures
DSS-2469 - Support for running the web tests against a remote SignServer (of any packaging type)
DSS-2478 - GCP KMS PKCS#11 support in SignServer based on P11NG
DSS-2491 - Add support for Ed25519 on Utimaco (HSM custom mode)
DSS-2500 - Add support for SHA384withECDSA and SHA512withECDSA in MRTDSODSigner
DSS-2517 - Rebranded SignServer CE UI theme
Improvements
DSS-1942 - Remove WildFly remoting output from when running AdminCLI
DSS-2289 - Include class name in error message for incorrect time source
DSS-2315 - Update BC deprecated reference
DSS-2383 - Remove worker name from error messages from SODProcessServlet
DSS-2492 - Web UI hardening
DSS-2499 - P11NG-tool uses deprecated "which" command
DSS-2501 - Synchronize default P11 library definitions with EJBCA
DSS-2505 - Add parameter to specify self-signed DN when generating key pair with P11NG-tool
DSS-2507 - Add TRUSTANCHORS property to AdES Signer template
DSS-2508 - Clarify input format for PlainSigner in legacy client-side hashing mode with RSASSA-PKCS1_v1.5
DSS-2511 - Move TimeMonitor Manual into the normal documentation
DSS-2514 - Detection of HSM vendor in P11NG
DSS-2516 - Upgrade BC to 1.72
DSS-2525 - Upgrade dependencies
Bug Fixes
DSS-1681 - Confusing error message with alias selector, noauth and key wrapping
DSS-1811 - SignClient can not be run from directory having a space character in its file name
DSS-1815 - SignDocument Command fails with CLIENTWS & WEBSERVICES protocols if host not specified
DSS-2270 - JWT Authorizer: "Unknown issuer" is incorrectly logged
DSS-2342 - Error 500 when you reload audit log page with empty value for "Displaying results" or "Entries per page"
DSS-2397 - NPE when not specifying signature algorithm and using ECDSA
DSS-2399 - NPE in JwtAuthorizer
DSS-2412- Configuring JwtAuthorizer with public key in PEM format instead of Base64 gives IllegalArgumentException instead of being listed as error
DSS-2455 - Failed key test results rendered as success message instead of failure message
DSS-2483 - EMBED_CRL is in wrong place in the PDF Signer document
DSS-2489 - Transitive dependency on older Bouncy Castle (1.64) not excluded/overridden
DSS-2496 - Can not remove global configuration properties with special characters using delete button
DSS-2503 - P11NG tool fails to generate self-signed cert for ECDSA keypair
DSS-2504 - P11NG-tool gives return code 0 with unknown key algorithm
DSS-2509 - Client HTTP interface relays on platform encoding for data submitted in URL encoded form
DSS-2523 - JArchiveSigner worker template missing in CE
SignServer 5.9
SignServer 5.9.1
Released May 2022
New Features
DSS-2380 - Make key generation work with P11NG Tool with AWS CloudHSM
DSS-2381 - Support key entries without certificate with P11NG
Improvements
DSS-2369 - AdESSignerUnitTest fails in the build job
DSS-2451 - Add files that should not be tracked to .gitignore
DSS-2456 - Fix failing webtests
DSS-2457 - Do not fail parsing of PDF documents with negative indirect references
DSS-2459 - Upgrade BC to 1.71
DSS-2462 - Support for include certificate levels in APKHashSigner
DSS-2465 - Support in APK signers for certificate in config instead of import it into the token not only for other signers
DSS-2466 - Upgrade to OpenPDF 1.3.28
Bug Fixes
DSS-2453 - Keywrapping is not working with PostgreSQL
DSS-2463 - Regression: P11NG tool not included in P11NG CLI dist
DSS-2467 - Fail to verify the MSIX file signed with SignServer
SignServer 5.9.0
Released April 2022
New Features
DSS-2405 - Support for JBoss EAP 7.4
DSS-2438 - Support for switching web theme
Improvements
DSS-1498 - Support in PlainSigner for client-side hashing with PKCS1 v1.5 with encoding on server-side
DSS-2192 - Use the new worker properties bulk editing method in system tests
DSS-2352 - Support in APK signers for certificate in config instead of import it into the token
DSS-2390 - Upgrade JackNJI11 to a version with upstreams and our changes - 1.2-pk2
DSS-2415 - Support DER-reencode also for client-side hashing mode in CMSSigner
DSS-2423 - MasterListSigner support for files larger than 1 MB
DSS-2425 - Add support for signing a protected PDF without supplying owner password
DSS-2426 - Upgrade/migrate to OpenPDF in PDFSigner
DSS-2435 - Documentation note regarding SoftHSM2 and key wrapping mechnisms
DSS-2436 - Do not fail for directories and clarify in documentation that -indir does not go into directories
DSS-2437 - Remove custom security manager used in some junit tests
DSS-2439 - Improve the test coverage for P11NG
DSS-2442 - Initialize signing closer to the actual signing in PDFSigner
DSS-2443 - Update copyright year for 2022
DSS-2444 - Upgrade JackNJI11 to 1.2-pk3
Bug Fixes
DSS-1985 - UsernamePasswordAuthorizer uses platform encoding
DSS-2440 - Failing or aborting in the middle of a multi-part signing can lead to CKR_OPERATION_ACTIVE errors when that session is later being reused
SignServer 5.8
SignServer 5.8.1
Released December 2021
New Features
DSS-2279 - EC support with P11NG
DSS-2367 - Signed Signature Request through Web Service API based on format specification
DSS-2375 - Support for WildFly 24
Improvements
DSS-2278 - Merge updated P11NG from EJBCA 7.8.0.1
DSS-2353 - Key removal operation consistency between P11NG and SunPKCS11
DSS-2379 - Document supported algorithms
DSS-2384 - Add demo client certificate issued by a sub CA
DSS-2394 - P11NG signature provider implementation should throw JCA exceptions instead of P11NG-specific runtime exceptions
DSS-2402 - Upgrade BC to 1.70
Bug Fixes
DSS-2382 - Issue with overriding DIGESTALGORITHM in PDF
DSS-2385 - JUnit test MRTDSODSignerTest signer certificate expired
DSS-2389 - Security Issue
DSS-2391 - Regression: Client-side hashing on Windows fails with "used by another process"
DSS-2396 - Certain recent JRE versions breaks PKCS11CryptoToken
DSS-2401 - Security Issue
SignServer 5.8.0
Released October 2021
New Features
DSS-2285 - Extend validity of already PAdES signed document (PAdES-LTA)
DSS-2306 - Extend validity of already signed XAdES file for XAdES-LTA profile
DSS-2331 - Certificate User Data Mapping from JWT
DSS-2332 - Peers Connection where SignServer acts as RA: Implementing Peers "RA mode"
DSS-2333 - EJBCA Peers CA Connector for use with OneTimeCryptoWorker
DSS-2359 - Signed signature requests (Server Authorization)
DSS-2360 - SignClient support for signed signature requests
DSS-2371 - Support for one-time keys using peers and P11NG
Improvements
DSS-2275 - Respond with failure for incorrectly formatted time-stamp requests
DSS-2277 - Upgrade BC to 1.69 (when available) with stricter TS request checks
DSS-2329 - Handle larger signatures in PAdES Signer
DSS-2354 - Worker template for AdESSigner is missing properties
DSS-2361 - Document that AdES Signer TRUSTANCHOR property could be needed if PDF is already signed
DSS-2362 - Better error handling for unexpected AdES Signer failures
DSS-2368 - Improved SignClient support for signed signature requests
Bug Fixes
DSS-2357 - Some JAR verification test failures since a later Java 8 version
DSS-2358 - AdES Signer gives error when used with OneTimeCryptoWorker
SignServer 5.7
Released July 2021
New Features
DSS-2248 - Per-request option for page and signature placement in PDF
DSS-2272 - Signing of Microsoft catalog files
DSS-2281 - PAdES-B baseline profile signature support
DSS-2282 - PAdES-T baseline profile signature support
DSS-2283 - PAdES-LT baseline profile signature support
DSS-2284 - PAdES-LTA baseline profile signature support
DSS-2286 - XAdES-LT baseline profile signature support
DSS-2288 - Add support for the NONEwithRSAandMGF1 (raw RSASSA-PSS) signature algorithm in P11NG
DSS-2290 - Support for overriding properties in the PDF Signer
DSS-2303 - XAdES-B baseline profile signature support
DSS-2304 - XAdES-T baseline profile signature support
DSS-2305 - XAdES-LTA baseline profile signature support
DSS-2337 - Worker property to configure extra/adjust signature size in PAdES
Improvements
DSS-2291 - Document getPKCS10CertificateRequestForAlias2 WS operation
DSS-2295 - Introduce git ignore files and add some IDE specific ignores to SVN
DSS-2298 - Upgrade external dependencies
DSS-2346 - Previous worker name not removed from cache after rename
DSS-2347 - Workers removed from AdminWeb kept in cache
Tasks
DSS-2299 - Add DSS library as dependency
DSS-2300 - Document differences between old PDF Signer and PAdES Signer
DSS-2301 - Create AdES module
DSS-2302 - First Signer implementation (hard coded config)
DSS-2311 - Remove any unneeded DSS dependencies and update JARs/project lists
DSS-2323 - Add support for CRL in PAdES-LT and higher levels
DSS-2327 - Switch from PDFBox to OpenPDF in AdES signer
Bug Fixes
DSS-2197 - Regression: RSASSA-PSS / SHA256withRSAandMGF1 etc. broken with P11NG
DSS-2271 - PDF Signer worker property visible signature resize/scaling naming inconsistency
DSS-2321 - Time-stamp signer test certificate expired
DSS-2325 - Test certificate in dss10_signer3.p12 expired
DSS-2326 - Hardcoded certificate in XMLValidatorTestData expired
SignServer 5.6
SignServer 5.6.1
Released April 2021
Improvements
DSS-2255 - Upgrade BC to 1.68
DSS-2261 - Give error for WS requests at high priority not configured for such
DSS-2287 - Support both old and new algorithm names for SHAxWithRSAandMGF1 / SHAxWithRSASSA-PSS in Plain Signer
DSS-2294 - Web filter that can be overriden
DSS-2295 - Introduce git ignore files and add some IDE specific ignores to SVN
Bug Fixes
DSS-2257 - Setting debug logging in SignClient Windows batch file is broken
DSS-2268 - Algorithms such as SHAxWithRSAandMGF1 not working with OpenJDK 8u.x even though they should be supported
DSS-2269 - Request metadata value passed through SignClient can not contain equals sign
DSS-2293 - Regression: Duplicated WSDL files and file names only different by casing may cause issues if building from source in Windows
DSS-2296 - AdminWS call getPKCS10CertificateRequestForAlias is broken on newer SignServer
SignServer 5.6.0
Released February 2021
New Features
DSS-934 - Add support in MSAuthCodeSigner for signing already signed PE files
DSS-1834 - Add support in MSAuthCodeSigner for signing already signed MSI files
DSS-2264 - Request Prioritization
Improvements
DSS-2120 - Add "Reload from database" button for authorizations
DSS-2259 - Improve flexibility for PDF signer CryptoToken access
DSS-2263 - Increase performance for key generation when P11NG is used
Tasks
DSS-2208 - Creation of new Web Filter : Implementation based on Jetty QoSFilter
DSS-2209 - Add global configuration for web filter
DSS-2210 - Use correct priority based on config and worker
DSS-2211 - Create a SleepWorker (for testing)
DSS-2214 - SignClient to use new URLs: Allow to use /worker/WORKERNAME
DSS-2238 - Filter SOAP Web Services
DSS-2256 - Update copyright year for 2021
Bug Fixes
DSS-2223 - Producer field corrupted in signed PDF
DSS-2224 - Stresstest tool lockups at exit with QoS Filter
DSS-2226 - Some tests in SignClientP11AuthTest fails with QoSFilter enabled
DSS-2229 - NPE if V1_SIGNATURE_NAME not specified and certificate is not in token