Releases: esig/dss
Releases · esig/dss
Release list
eSignature DSS - Version 5.3.RC1
Bug
- [DSS-1177] - ASiCUtils.isASiCContainer fails when signing a MS Office document (xlsx, docx) with ASiCWithXAdESService
- [DSS-1257] - Remove signature from xades and cades
- [DSS-1267] - Validation - Policy proccesing error
- [DSS-1271] - Wrong/misleading error message when trying to create XAdES_BASELINE_T signature with a self-signed certificate with DSS 5.2.RC1
- [DSS-1290] - Detached XAdES extension fails if no file name is provided in DSSDocument even if it is the only detached document
- [DSS-1304] - dss-service depends on jcl-over-slf4j
- [DSS-1329] - DSS 5.0 - XPointer problem in validation
- [DSS-1332] - XAdES extension to XAdES_BASELINE_T fails with DSS 5.2
- [DSS-1334] - Detached XAdES signing produces broken signatures (or fails) if no file name is provided in DSSDocument
- [DSS-1335] - CAdES: SigningCerficiateV2 attribute is badly DER encoded when using sha256. CAdES signatures are incorrect.
- [DSS-1338] - DSS 5.0 VALIDATION - XADES ENVELOPING problem in output file
- [DSS-1348] - OCSP Response : ArchiveCutOff extension is badly supported
- [DSS-1349] - DSSXMLUtils.serializeNode modifies and invalidates a XML/HTML content with latin1 encoding
- [DSS-1359] - XAdES signature is not correct when adding more than one commitmentTypeIndication
- [DSS-1371] - PAdES : IO issue while extending a signature
- [DSS-1376] - PAdES - difference between the validator.getOriginal and the original doc
- [DSS-1377] - ASiC SOAP (and possible REST) document validation fails with explicit mimetype in request
- [DSS-1381] - Validator getOriginalDocuments problem
- [DSS-1384] - NullPointerException in OnlineTSPSource if server responds with HTTP error
- [DSS-1385] - XMLDocumentValidator should use the MimeType from the document
- [DSS-1391] - Pkcs11SignatureToken returns same keys for different slots
- [DSS-1395] - DSS Demo : startsWith (JS) is not supported in IE11
- [DSS-1397] - CAdES: Incorrect RoleSyntax encoding when adding claimed signer attributes
- [DSS-1398] - NullPointerException with CAdESSignatureExtension (PADES or CADES signature)
Improvement
- [DSS-1202] - Unable to download javadoc
- [DSS-1207] - Allows to validate certificates
- [DSS-1265] - Add SHA3 support
- [DSS-1266] - ECC based on brainpool not supported
- [DSS-1278] - Add a composite TSPSource
- [DSS-1292] - Add optional support of X509SubjectName
- [DSS-1294] - Add javadoc and graphs in the bundle
- [DSS-1295] - Upgrade MOCCA integration
- [DSS-1301] - Ability to programmatically specify an PdfObjFactory instance
- [DSS-1307] - AdvancedSignature.getSignatureForm() returns PAdES for a PKCS#7 signed file
- [DSS-1314] - CAdES : create detached signature with only the digest
- [DSS-1340] - SOAP/REST Services : allows to sign/extend/validate digest documents
- [DSS-1352] - Add the "best signature time" in the simple report
- [DSS-1353] - Support of the swedish design
- [DSS-1357] - Add support for non EU trusted lists
- [DSS-1360] - XAdESSignatureBuilder incorporateXXX methods don't follow XAdES hierarchy of nodes
- [DSS-1370] - XAdES : improve support of AllDataObjectsTimeStamp / IndividualDataObjectsTimeStamp
- [DSS-1380] - Add method to compute content-timestamp
- [DSS-1383] - Validation : add constraint on self-signed
- [DSS-1387] - XAdES : allow to sign more than one object (enveloping)
- [DSS-1394] - Update the cookbook
- [DSS-1401] - CAdES archive timestamp v2
Release 5.2.RC2
Bug
- [DSS-921] - An archive-extended signature with relevant, but missing revocation information still validates OK (as XAdES_BASELINE_LTA)
- [DSS-1174] - XAdES manifest signature creation
- [DSS-1276] - Incorrect TSL processing causes old national TLs to be loaded
- [DSS-1285] - Disable external DTDs
Note : The final release 5.2 should be published around mid-January. We are waiting for pentest results.
Release 5.2.RC1
Bug
- [DSS-921] - An archive-extended signature with relevant, but missing revocation information still validates OK (as XAdES_BASELINE_LTA)
- [DSS-1102] - DSS CRL validation
- [DSS-1149] - Error in the simple report of an invalid XAdES LTA signature with an invalid ArchiveTimestamp
- [DSS-1155] - Missing check for OtherCriteria in critical Qualifications Extension in TSL
- [DSS-1160] - Use of TrustedListsCertificateSource while signing
- [DSS-1212] - Error while retrieving expiredCertsOnCRL date
- [DSS-1219] - Signing certificate validation material and archive-time-stamps
- [DSS-1222] - Validation of time-stamp and archive-time-stamp produced at the same second
- [DSS-1237] - Adding certificates does not work in DSS 5.1.RC1 demo web application and KeyStoreCertificateSource in general when using .p12
- [DSS-1258] - XAdES countersignature verification not working
Improvement
- [DSS-798] - Allowed augmentation of XAdES detached signatures without providing the original file
- [DSS-822] - RSASSA-PSS support
- [DSS-1174] - XAdES manifest signature creation
- [DSS-1211] - Avoid to load complete CRLs
- [DSS-1221] - Simple validation report improvement for signatures with issues in time-stamps
- [DSS-1228] - Add support of ServiceSupplyPoints
- [DSS-1229] - PAdES : add rotation support for visible signatures
- [DSS-1250] - DSS demo : allows to use secure cookies
- [DSS-1251] - DSS demo : custom default error page
Final release 5.1
Bug
- [DSS-1226] - The "Sign a document" page does not generate ASIC containers
- [DSS-1227] - Use of OnlineTSPSource does not shutdown ExecutorService
- [DSS-1235] - Proxy configuration in DSS 5.1.RC1 demo web application does not work
- [DSS-1236] - Detailed report PDF generation in DSS 5.1.RC1 demo web application does not work when there is more than one validated signature
- [DSS-1249] - Improve sanitization of paths
Support
- [DSS-1224] - Proxy configuration
Release 5.1.RC1
Bug
- [DSS-1131] - PADES_BASELINE_LTA creates timestamp signature as visible
- [DSS-1132] - Separate SignatureImageParameters for signature and document time stamp
- [DSS-1135] - Error getting policyId
- [DSS-1145] - Key length used to sign token smaller than in validation policy.
- [DSS-1171] - CMSDocumentValidator created with CMSsignedData leads to exception
- [DSS-1172] - Common Name (CN) wrong
- [DSS-1188] - Wrong Signing Certificate extracted from CMS-NOT-ETSI
- [DSS-1199] - File handle leak in ImageUtils
- [DSS-1200] - Bad scaling of signature images
- [DSS-1147] - ASiC-E containers with CAdES are not baseline containers
- [DSS-1148] - ASiC-E containers with CAdES long term preservation is not correctly achieved
- [DSS-1150] - Error generating ASIC-E with XAdES LT multiple input files
Improvement
- [DSS-1159] - Pades: Line breaks in signature text cannot be rendered
- [DSS-1165] - Validation: upload only MessageDigest rather than original document
- [DSS-1183] - PAdES : Support of signature fields
- [DSS-1184] - PAdES : distinction of PAdES and PKCS7 signatures
- [DSS-1185] - Demo Webapp : migrate from Apache Tiles to Thymeleaf
- [DSS-1186] - Demo bundle : improvements
- [DSS-1201] - Webservices for Server signing REST and SOAP
- [DSS-1206] - DSS demo : use NexU 1.10.5
- [DSS-1208] - DSS demo : migrate Spring xml config to java config
Support
Final release 5.0
Bug
- [DSS-1138] - PDF signature image is displayed on the wrong page
- [DSS-1139] - ASiC : zip comment detection fails in some cases
- [DSS-1144] - OCSP response status unauthorized (6) NPE
- [DSS-1153] - Implementation of TSL PolicySet criterion is incorrect
- [DSS-1156] - Incorrect handling of sub-CriteriaLists in Qualifictaion Extensions in TSLs
- [DSS-1163] - SecureRandomNonceSource uses a static SecureRandom instance
Improvement
- [DSS-1130] - Add support for PNG in visible signature with textParameters
Release 5.0.RC1
This release mainly brings a complete refactoring of the ASiC part (creation, extension and validation) and the compliance to eIDAS regulation.
Bug
- [DSS-924] - extractCNName return bad name if no CN
- [DSS-932] - Validating ASiC-E/XAdES without manifest.xml succeeds
- [DSS-939] - dss-pades depends on jcl-over-slf4j
- [DSS-943] - Enforce the NotQualified SIE qualifier
- [DSS-967] - NPE when attempting to load an absent TL
- [DSS-1110] - XADES DSA ASN1 signature not properly converted to DSIG
- [DSS-1113] - Failed OCSP request causes NPE upon signature validation
- [DSS-1114] - Incorrect encoding of OCSP nonce in OCSP request
- [DSS-1115] - OnlineOCSPSource does not support changing nonces
- [DSS-1116] - Visible signature image metadata stream is not closed
- [DSS-1124] - XAdES : Incorrect SigningCertificateV2 content
- [DSS-1125] - No exception is thrown when LOTL Signature is not valid
Improvement
- [DSS-716] - DSS support for Android
- [DSS-769] - PNG support
- [DSS-824] - It would be nice to be able to zoom on PAdES signature images
- [DSS-848] - Update PDFBox dependency to new 2.0.0 version
- [DSS-864] - Scale signature image
- [DSS-881] - Error handling in KeyStoreCertificateSource could be improved
- [DSS-882] - NullPointerException when DSSUtils.loadCertificate is called with an input stream which is not a certficate
- [DSS-891] - Remove annotation @PostConstruct on TSLValidator job
- [DSS-894] - Support of expiredCertsRevocationInfo tag from the TL
- [DSS-902] - Time-dependent Service information extensions
- [DSS-908] - Support of additionalServiceInformation from the TL
- [DSS-920] - Validating XAdES signature using precalculated data file hash
- [DSS-935] - Retrieve token by alias in keystore
- [DSS-958] - Very high memory usage when validating some signatures
- [DSS-962] - Bogus warnings: XMLSignatureException: Signature length not correct: got 256 but was expecting 512 for some successfully validated signatures
- [DSS-974] - PAdES visual signature, JPEG too big
- [DSS-1103] - ASiC Plugtests
- [DSS-1104] - Split ASiC with XAdES/CAdES
- [DSS-1105] - Remove getNextValidator from DocumentValidator
- [DSS-1106] - Remove get/setNextDocument from DSSDocument
- [DSS-1107] - Add information about ASiC container in the validation report
- [DSS-1108] - Allow to sign more than one document with the demo/webservices
- [DSS-1109] - Remove setNextReport from Reports
- [DSS-1111] - ASiC-E + CAdES : incorrect ASiCManifest.xml structure
- [DSS-1118] - ASiC-E with CAdES : Validation of the manifest files
- [DSS-1119] - ASiC-S : multi documents signature
- [DSS-1112] - Allow to set _signatureCards in MOCCASignatureTokenConnection
- [DSS-1120] - PAdES : upgrade pdfbox dependency
- [DSS-1122] - Upgrade BouncyCastle dependency
- [DSS-1123] - Add support for PNGs in PdfBoxSignatureService
- [DSS-1128] - eIDAS compliance
- [DSS-1129] - Split framework and demos
Task
- [DSS-955] - License should be added to github readme.md and to validation-policy project
Release 4.7
Bug
- [DSS-947] - Validation sub indication issue (NO_CERTIFICATE_CHAIN_FOUND)
- [DSS-949] - Empty unsigned attributes in PAdES-B-B generation
- [DSS-950] - DSS/VRI entry invalid digest
- [DSS-951] - Validation report error in CAdES detached signature wihout uploading the original file
- [DSS-965] - KeyStoreCertificateSource does not load keystore certificates automatically
Task
- [DSS-956] - SimpleReport of a PAdES_BASELINE_T signature
Improvement
- [DSS-936] - Bogus check in PastCertificateValidationAcceptableCheck
Release 4.7.RC2
Release Notes - DSS - Version 4.7.RC2
Bug
- [DSS-806] - CommonsDataLoader.java doesnt call httpClient.close();
- [DSS-883] - TSLValidationJob refresh method does not revalidate country TSLs if only the LOTL changed
- [DSS-890] - SimpleReport.isSignatureValid(String) fails to handle the new {{TOTAL_PASSED}} indication in 4.7.RC1
- [DSS-893] - The pre-defined EU TSL signers from the EU TSL signers trust store in the DSS Demo Web Application (keystore.p12) cannot be deleted
- [DSS-895] - Validation of a signature can influence the validation result of another signature
- [DSS-915] - Fix detecting signature qualification level based on TL information (QSCD/SSCD check)
- [DSS-918] - Validation fails for document with revoked signing certificate when ValidationLevel is set to LONG_TERM_DATA, but succeeds when ValidationLevel is ARCHIVAL_DATA
- [DSS-922] - OCSP revocation errors are not included in simple report
Improvement
Release 4.7.RC1
Sub-task
- [DSS-719] - Expose validation method as REST service
- [DSS-833] - Remove xpath expressions in the validation
- [DSS-834] - Update the HTML/PDF reports
- [DSS-835] - Review the validation policy
- [DSS-836] - Test the new validation with the PlugTests
Bug
- [DSS-650] - ASiC-e with CAdES extension fails
- [DSS-666] - ASiC and CertificatePool sharing
- [DSS-747] - PAdES visual signature is distorted while using both text and image
- [DSS-752] - NullPointerException extending XAdES-B to LTA when <xades:SignedDataObjectProperties> not present
- [DSS-780] - DSS webapp validates only first asice xades signature
- [DSS-787] - DSS/VRI does not include indirect references to already added objects
- [DSS-789] - Missing TS revocation data in PAdES LTA generated with the Standalone App
- [DSS-790] - Missing TS revocation data in PAdES augmentation to LT/LTA-Level from B-Level
- [DSS-792] - Singing certificate included twice in ds:KeyInfo
- [DSS-799] - Augmentation from ASiC-E to ASiC-S and vice versa allowed
- [DSS-814] - Temporaries files are not deleted in PAdES signature
- [DSS-817] - Error parsing tag IssuerSerial
- [DSS-819] - Validation reports ignore some ArchiveTimestamp validation errors
- [DSS-820] - Cannot sign multiple files using XAdES enveloped
- [DSS-823] - Visual PAdES signature image file not closed
- [DSS-825] - 4.6.0 DSS ASIC, DSS XAdES could not resolve reference URI if it contains "+" symbol
- [DSS-827] - Constructor for CommonTrustedCertificateSource is bogus
- [DSS-828] - OCSP requests should not have nonce extension set as critical
- [DSS-829] - OnlineOCSPSource contains bad error handling
- [DSS-830] - DSS cookbook example won't work
- [DSS-839] - Error validating signature with timestamp when time zone configured
- [DSS-841] - PAdES-LTA signed pdf validated as indeterminate after signed certificate expiration
- [DSS-843] - Unused SOAP validation service in development 4.7 branch
- [DSS-845] - OfflineCRLSource is rejecting some CRL
- [DSS-846] - NPE while extending a signature with remote services
- [DSS-850] - https (with mutal authentication) timestamping not supported in CommonsDataLoader
- [DSS-851] - CAdESSignature.checkSignatureIntegrity accepts invalid signature
- [DSS-852] - XAdES : ordering of tags in SignatureProductionPlaceV2
- [DSS-855] - close() method of Pkcs12SignatureTokenConnection should be empty
- [DSS-861] - dss-service 4.6.0, OCSP unit test failure.
- [DSS-863] - FileCacheDataLoader never expires entries
- [DSS-869] - TSLRepository, NullPointerException
- [DSS-870] - CommonsDataLoader, client authentication
- [DSS-871] - Timestamp server, HTTP-400 response
- [DSS-873] - Pkcs11SignatureToken class is not thread-safe
- [DSS-874] - xades:SigPolicyHash DigestValue check
Task
- [DSS-773] - RemoveSignature for Cades
Improvement
- [DSS-700] - Support for WebServices SOAP and REST
- [DSS-763] - Improve checking of signer certificate's QC compliance based on TSL
- [DSS-778] - Enveloping XAdES should add all documents to the references
- [DSS-801] - Error with DSA / ECDSA signature during signing
- [DSS-805] - XML Policy Constraint is not validated against XSD
- [DSS-832] - Support new standard ETSI EN 319 102
- [DSS-837] - Remove Java applets
- [DSS-840] - CommonDataLoader : allows to disable redirects
- [DSS-842] - ASIC-E XAdES should contain manifest.xml
- [DSS-853] - Support of the CRL extension expiredCertsOnCRL
- [DSS-857] - Support of OCSP extension ArchiveCutoff
- [DSS-875] - Fix of LDAP URL parsing and querying attributes