Component: certificate
319 changelog entries across 156 version(s)
Releases by channel (stacked)
- added support for multiple "Subject Alt. Names";
- fixed "expires-after" parameter calculation;
- fixed time zone adjustment for SCEP requests;
- properly flush old CRLs when changing store location;
- fixed certificate signing by SCEP client if multiple CA certificates are provided;
- fixed "expires-after" parameter calculation;
- properly flush old CRLs when changing store location;
- added support for multiple "Subject Alt. Names" (CLI only);
- fixed time zone adjustment for SCEP requests;
- fixed time zone adjustment for SCEP requests;
- added "expires-after" parameter;
- do not allow to perform "undo" on certificate changes;
- fixed RA "server-url" setting;
- fixed RA "server-url" setting;
- fixed "add-scep" template existence check when signing certificate;
- do not allow to perform "undo" on certificate changes;
- fixed "add-scep" template existence check when signing certificate;
- added "expires-after" parameter;
- fixed "add-scep" template existence check when signing certificate;
- fixed incorrect SCEP URL after an upgrade;
- add "expires-after" parameter (CLI only);
- added PKCS#10 version check;
- dropped DES support and added AES instead for SCEP;
- dropped MD5 support and require SHA1 as minimum for SCEP;
- fixed incorrect SCEP URL after an upgrade;
- fixed incorrect SCEP URL after an upgrade;
- do not use UTF-8 for SCEP challenge password;
- fixed PKCS#10 version;
- do not use utf8 for SCEP challenge password;
- fixed PKCS#10 version;
- added PKCS#10 version check;
- dropped DES support and added AES instead for SCEP;
- dropped MD5 support and require SHA1 as minimum for SCEP;
- fixed PKCS#10 version;
- do not use utf8 for SCEP challenge password;
- added option to store CRL in RAM (CLI only);
- fixed SCEP "get" request URL encoding;
- improved CRL update after system startup;
- show "Expired" flag when initial CRL fetch fails;
- show invalid flag when local CRL file does not exist;
- added option to store CRL in RAM (CLI only);
- improved CRL update after system startup;
- show invalid flag when local CRL file does not exist;
- fixed import of certificates with empty SKID;
- SCEP client now supports FQDN URL and port;
- allow CRL address to be specified as DNS name;
- added year cap (invalid-after date will not exceed year 2039);
- fixed fail on import from CAPs when both key and name already exist;