COMMUNITY EDITION SEPTEMBER 2026
The SignServer team is pleased to announce the newest release of our open-source signing software SignServer Community Edition with version 7.7.1.
These release notes cover new SignServer Community features and improvements implemented between SignServer Community 7.3.2 and SignServer Community 7.7.1.
This community release of SignServer This latest community release includes new features such as composite certificate support. Several CVEs and bugs have also been addressed.
Highlights
Use of HSM Crypto Tokens requires SignServer Enterprise Edition
SignServer enables migration to post-quantum cryptography (PQC) for PKI. To support the use of HSM crypto tokens with PQC, the SignServer HSM integration architecture has been enhanced and continues to evolve for both PKCS#11-based and REST API-based HSM integrations.
As of SignServer 7.7.1, all use of HSM Crypto Tokens requires SignServer Enterprise Edition.
If you are using an earlier version of SignServer Community Edition with HSM Crypto Tokens configured, you need to either migrate to SignServer Enterprise Edition or deactivate any HSM Crypto Tokens before upgrading to SignServer 7.7.1 Community Edition.
ML-DSA Composite Certificate Support
SignServer 7.6 introduced support for creating composite keys. A composite consists of both a classical-cryptography key (RSA, ECDSA, or EdDSA) and a post-quantum key (ML-DSA-44, ML-DSA-65, or ML-DSA-87). For more information, see SignServer Composite Certificates.
Added Support for SAN Values in CSR
Certain signing tools, such as cosign, require that the certificate include a Subject Alternative Name (SAN). SignServer has added support to provide an email address as SAN value during the CSR generation. The support has been added for the interfaces Admin CLI and Admin Web.
For Admin Web information, see Workers CSR Page.
Added Support for OAuth
This release adds support for OAuth to configure and access the Administration Web of your deployment. A new login page has been added for choosing OAuth to access the Administration Web. See Set up OpenID Connect (OIDC) using Auth0.
Technology Upgrades
Added support for Java 21
SignServer 7.7.1 now supports running on Java 21, in addition to Java 17. Certain limitations have been identified using Legacy XAdES under Java 21.
WildFly 39 recommended Application Server
The recommended Application server for SignServer 7.7.1 is WildFly 39.0.1.
For more information on software requirements, see Installation Prerequisites.
Announcements
New Login Page
SignServer 7.4 introduced a new login page across all deployments. See Login and Logout.
Bouncy Castle 1.84 Upgrade
Bouncy Castle has been upgraded to version 1.84. For information about the latest Bouncy Castle releases, refer to the Bouncy Castle Release Notes.
Security Issues
SignServer 7.6.0 resolves a security issue affecting file writing
Keyfactor rates the severity as medium with a CVSS score of CVSS 6.9. Once 7.6.0 has been generally available across all platforms for at least two weeks, a CVE with the identifier CVE-2026-25825 will be published.
SignServer 7.6.0 resolves a security issue affecting information disclosure
Keyfactor rates the severity as medium with a CVSS score of CVSS 4.6. Once 7.6.0 has been generally available across all platforms for at least two weeks, a CVE with the identifier CVE-2026-25826 will be published.
SignServer 7.6.0 resolves a security issue affecting file enumeration
Keyfactor rates the severity as medium with a CVSS score of CVSS 5.1. Once 7.6.0 has been generally available across all platforms for at least two weeks, a CVE with the identifier CVE-2026-25827 will be published.
Upgrade Information
Review the SignServer Upgrade Notes for important information about this release. For upgrade instructions, see Upgrade SignServer.
Downloads and Resources
There are several options available for downloading the latest SignServer Community:
-
SignServer Community is available for download from GitHub.
-
SignServer Community container is available for download from Docker Hub.
-
SignServer Community container is available for download from the AWS marketplace.
-
SignServer Community is available for download from SourceForge.
Get the latest news about SignServer Community initiatives and open-source products - sign up for our community newsletter.
Find links to downloads, how-to guides, video tutorials, and documentation at signserver.org.
Want to learn more about our open source software? Get in touch over at SignServer Discussions on GitHub, a collective space where you can share feedback and contribute ideas to future releases. Thank you for your continued support and contributions to the SignServer community.