7.8.1 7.8 7.7 7.6 7.5 7.4 7.3.2
7.8.1 7.8 7.7 7.6 7.5 7.4 7.3.2

SignServer Community 7.7.1 Release Notes

COMMUNITY EDITION SEPTEMBER 2026

The SignServer team is pleased to announce the newest release of our open-source signing software SignServer Community Edition with version 7.7.1.

These release notes cover new SignServer Community features and improvements implemented between SignServer Community 7.3.2 and SignServer Community 7.7.1.

This community release of SignServer This latest community release includes new features such as composite certificate support. Several CVEs and bugs have also been addressed.

Highlights

Use of HSM Crypto Tokens requires SignServer Enterprise Edition

SignServer enables migration to post-quantum cryptography (PQC) for PKI. To support the use of HSM crypto tokens with PQC, the SignServer HSM integration architecture has been enhanced and continues to evolve for both PKCS#11-based and REST API-based HSM integrations.

As of SignServer 7.7.1, all use of HSM Crypto Tokens requires SignServer Enterprise Edition.

If you are using an earlier version of SignServer Community Edition with HSM Crypto Tokens configured, you need to either migrate to SignServer Enterprise Edition or deactivate any HSM Crypto Tokens before upgrading to SignServer 7.7.1 Community Edition.

ML-DSA Composite Certificate Support

SignServer 7.6 introduced support for creating composite keys. A composite consists of both a classical-cryptography key (RSA, ECDSA, or EdDSA) and a post-quantum key (ML-DSA-44, ML-DSA-65, or ML-DSA-87). For more information, see SignServer Composite Certificates.

Added Support for SAN Values in CSR

Certain signing tools, such as cosign, require that the certificate include a Subject Alternative Name (SAN). SignServer has added support to provide an email address as SAN value during the CSR generation. The support has been added for the interfaces Admin CLI and Admin Web.

For Admin Web information, see Workers CSR Page.

Added Support for OAuth

This release adds support for OAuth to configure and access the Administration Web of your deployment. A new login page has been added for choosing OAuth to access the Administration Web. See Set up OpenID Connect (OIDC) using Auth0.

Technology Upgrades

Added support for Java 21

SignServer 7.7.1 now supports running on Java 21, in addition to Java 17. Certain limitations have been identified using Legacy XAdES under Java 21.

The recommended Application server for SignServer 7.7.1 is WildFly 39.0.1.

For more information on software requirements, see Installation Prerequisites.

Announcements

New Login Page

SignServer 7.4 introduced a new login page across all deployments. See Login and Logout.

Bouncy Castle 1.84 Upgrade

Bouncy Castle has been upgraded to version 1.84. For information about the latest Bouncy Castle releases, refer to the Bouncy Castle Release Notes.

Security Issues

SignServer 7.6.0 resolves a security issue affecting file writing

Keyfactor rates the severity as medium with a CVSS score of CVSS 6.9. Once 7.6.0 has been generally available across all platforms for at least two weeks, a CVE with the identifier CVE-2026-25825 will be published.

SignServer 7.6.0 resolves a security issue affecting information disclosure

Keyfactor rates the severity as medium with a CVSS score of CVSS 4.6. Once 7.6.0 has been generally available across all platforms for at least two weeks, a CVE with the identifier CVE-2026-25826 will be published.

SignServer 7.6.0 resolves a security issue affecting file enumeration

Keyfactor rates the severity as medium with a CVSS score of CVSS 5.1. Once 7.6.0 has been generally available across all platforms for at least two weeks, a CVE with the identifier CVE-2026-25827 will be published.

Upgrade Information

Review the SignServer Upgrade Notes for important information about this release. For upgrade instructions, see Upgrade SignServer.

Downloads and Resources

There are several options available for downloading the latest SignServer Community:

  • SignServer Community is available for download from GitHub.

  • SignServer Community container is available for download from Docker Hub.

  • SignServer Community container is available for download from the AWS marketplace.

  • SignServer Community is available for download from SourceForge.

Get the latest news about SignServer Community initiatives and open-source products - sign up for our community newsletter.

Find links to downloads, how-to guides, video tutorials, and documentation at signserver.org.

Want to learn more about our open source software? Get in touch over at SignServer Discussions on GitHub, a collective space where you can share feedback and contribute ideas to future releases. Thank you for your continued support and contributions to the SignServer community.