Skip to content

Releases: esig/dss

eSignature DSS - Version 5.3.RC1

Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 05 Apr 09:39

Bug

  • [DSS-1177] - ASiCUtils.isASiCContainer fails when signing a MS Office document (xlsx, docx) with ASiCWithXAdESService
  • [DSS-1257] - Remove signature from xades and cades
  • [DSS-1267] - Validation - Policy proccesing error
  • [DSS-1271] - Wrong/misleading error message when trying to create XAdES_BASELINE_T signature with a self-signed certificate with DSS 5.2.RC1
  • [DSS-1290] - Detached XAdES extension fails if no file name is provided in DSSDocument even if it is the only detached document
  • [DSS-1304] - dss-service depends on jcl-over-slf4j
  • [DSS-1329] - DSS 5.0 - XPointer problem in validation
  • [DSS-1332] - XAdES extension to XAdES_BASELINE_T fails with DSS 5.2
  • [DSS-1334] - Detached XAdES signing produces broken signatures (or fails) if no file name is provided in DSSDocument
  • [DSS-1335] - CAdES: SigningCerficiateV2 attribute is badly DER encoded when using sha256. CAdES signatures are incorrect.
  • [DSS-1338] - DSS 5.0 VALIDATION - XADES ENVELOPING problem in output file
  • [DSS-1348] - OCSP Response : ArchiveCutOff extension is badly supported
  • [DSS-1349] - DSSXMLUtils.serializeNode modifies and invalidates a XML/HTML content with latin1 encoding
  • [DSS-1359] - XAdES signature is not correct when adding more than one commitmentTypeIndication
  • [DSS-1371] - PAdES : IO issue while extending a signature
  • [DSS-1376] - PAdES - difference between the validator.getOriginal and the original doc
  • [DSS-1377] - ASiC SOAP (and possible REST) document validation fails with explicit mimetype in request
  • [DSS-1381] - Validator getOriginalDocuments problem
  • [DSS-1384] - NullPointerException in OnlineTSPSource if server responds with HTTP error
  • [DSS-1385] - XMLDocumentValidator should use the MimeType from the document
  • [DSS-1391] - Pkcs11SignatureToken returns same keys for different slots
  • [DSS-1395] - DSS Demo : startsWith (JS) is not supported in IE11
  • [DSS-1397] - CAdES: Incorrect RoleSyntax encoding when adding claimed signer attributes
  • [DSS-1398] - NullPointerException with CAdESSignatureExtension (PADES or CADES signature)

Improvement

  • [DSS-1202] - Unable to download javadoc
  • [DSS-1207] - Allows to validate certificates
  • [DSS-1265] - Add SHA3 support
  • [DSS-1266] - ECC based on brainpool not supported
  • [DSS-1278] - Add a composite TSPSource
  • [DSS-1292] - Add optional support of X509SubjectName
  • [DSS-1294] - Add javadoc and graphs in the bundle
  • [DSS-1295] - Upgrade MOCCA integration
  • [DSS-1301] - Ability to programmatically specify an PdfObjFactory instance
  • [DSS-1307] - AdvancedSignature.getSignatureForm() returns PAdES for a PKCS#7 signed file
  • [DSS-1314] - CAdES : create detached signature with only the digest
  • [DSS-1340] - SOAP/REST Services : allows to sign/extend/validate digest documents
  • [DSS-1352] - Add the "best signature time" in the simple report
  • [DSS-1353] - Support of the swedish design
  • [DSS-1357] - Add support for non EU trusted lists
  • [DSS-1360] - XAdESSignatureBuilder incorporateXXX methods don't follow XAdES hierarchy of nodes
  • [DSS-1370] - XAdES : improve support of AllDataObjectsTimeStamp / IndividualDataObjectsTimeStamp
  • [DSS-1380] - Add method to compute content-timestamp
  • [DSS-1383] - Validation : add constraint on self-signed
  • [DSS-1387] - XAdES : allow to sign more than one object (enveloping)
  • [DSS-1394] - Update the cookbook
  • [DSS-1401] - CAdES archive timestamp v2

Release 5.2.RC2

Release 5.2.RC2 Pre-release
Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 08 Dec 08:05

Bug

  • [DSS-921] - An archive-extended signature with relevant, but missing revocation information still validates OK (as XAdES_BASELINE_LTA)
  • [DSS-1174] - XAdES manifest signature creation
  • [DSS-1276] - Incorrect TSL processing causes old national TLs to be loaded
  • [DSS-1285] - Disable external DTDs

Note : The final release 5.2 should be published around mid-January. We are waiting for pentest results.

Release 5.2.RC1

Release 5.2.RC1 Pre-release
Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 29 Sep 08:35

Bug

  • [DSS-921] - An archive-extended signature with relevant, but missing revocation information still validates OK (as XAdES_BASELINE_LTA)
  • [DSS-1102] - DSS CRL validation
  • [DSS-1149] - Error in the simple report of an invalid XAdES LTA signature with an invalid ArchiveTimestamp
  • [DSS-1155] - Missing check for OtherCriteria in critical Qualifications Extension in TSL
  • [DSS-1160] - Use of TrustedListsCertificateSource while signing
  • [DSS-1212] - Error while retrieving expiredCertsOnCRL date
  • [DSS-1219] - Signing certificate validation material and archive-time-stamps
  • [DSS-1222] - Validation of time-stamp and archive-time-stamp produced at the same second
  • [DSS-1237] - Adding certificates does not work in DSS 5.1.RC1 demo web application and KeyStoreCertificateSource in general when using .p12
  • [DSS-1258] - XAdES countersignature verification not working

Improvement

  • [DSS-798] - Allowed augmentation of XAdES detached signatures without providing the original file
  • [DSS-822] - RSASSA-PSS support
  • [DSS-1174] - XAdES manifest signature creation
  • [DSS-1211] - Avoid to load complete CRLs
  • [DSS-1221] - Simple validation report improvement for signatures with issues in time-stamps
  • [DSS-1228] - Add support of ServiceSupplyPoints
  • [DSS-1229] - PAdES : add rotation support for visible signatures
  • [DSS-1250] - DSS demo : allows to use secure cookies
  • [DSS-1251] - DSS demo : custom default error page

Final release 5.1

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 08 Sep 08:03

Bug

  • [DSS-1226] - The "Sign a document" page does not generate ASIC containers
  • [DSS-1227] - Use of OnlineTSPSource does not shutdown ExecutorService
  • [DSS-1235] - Proxy configuration in DSS 5.1.RC1 demo web application does not work
  • [DSS-1236] - Detailed report PDF generation in DSS 5.1.RC1 demo web application does not work when there is more than one validated signature
  • [DSS-1249] - Improve sanitization of paths

Support

Release 5.1.RC1

Release 5.1.RC1 Pre-release
Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 28 Jun 11:15

Bug

  • [DSS-1131] - PADES_BASELINE_LTA creates timestamp signature as visible
  • [DSS-1132] - Separate SignatureImageParameters for signature and document time stamp
  • [DSS-1135] - Error getting policyId
  • [DSS-1145] - Key length used to sign token smaller than in validation policy.
  • [DSS-1171] - CMSDocumentValidator created with CMSsignedData leads to exception
  • [DSS-1172] - Common Name (CN) wrong
  • [DSS-1188] - Wrong Signing Certificate extracted from CMS-NOT-ETSI
  • [DSS-1199] - File handle leak in ImageUtils
  • [DSS-1200] - Bad scaling of signature images
  • [DSS-1147] - ASiC-E containers with CAdES are not baseline containers
  • [DSS-1148] - ASiC-E containers with CAdES long term preservation is not correctly achieved
  • [DSS-1150] - Error generating ASIC-E with XAdES LT multiple input files

Improvement

  • [DSS-1159] - Pades: Line breaks in signature text cannot be rendered
  • [DSS-1165] - Validation: upload only MessageDigest rather than original document
  • [DSS-1183] - PAdES : Support of signature fields
  • [DSS-1184] - PAdES : distinction of PAdES and PKCS7 signatures
  • [DSS-1185] - Demo Webapp : migrate from Apache Tiles to Thymeleaf
  • [DSS-1186] - Demo bundle : improvements
  • [DSS-1201] - Webservices for Server signing REST and SOAP
  • [DSS-1206] - DSS demo : use NexU 1.10.5
  • [DSS-1208] - DSS demo : migrate Spring xml config to java config

Support

  • [DSS-1193] - Documentation for DSS Rest interface
  • [DSS-1203] - NoClassDefFoundError Could not initialize class eu.europa.esig.dss.utils.Utils

Final release 5.0

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 10 Apr 11:28

Bug

  • [DSS-1138] - PDF signature image is displayed on the wrong page
  • [DSS-1139] - ASiC : zip comment detection fails in some cases
  • [DSS-1144] - OCSP response status unauthorized (6) NPE
  • [DSS-1153] - Implementation of TSL PolicySet criterion is incorrect
  • [DSS-1156] - Incorrect handling of sub-CriteriaLists in Qualifictaion Extensions in TSLs
  • [DSS-1163] - SecureRandomNonceSource uses a static SecureRandom instance

Improvement

  • [DSS-1130] - Add support for PNG in visible signature with textParameters

Release 5.0.RC1

Release 5.0.RC1 Pre-release
Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 27 Jan 14:58

This release mainly brings a complete refactoring of the ASiC part (creation, extension and validation) and the compliance to eIDAS regulation.

Bug

  • [DSS-924] - extractCNName return bad name if no CN
  • [DSS-932] - Validating ASiC-E/XAdES without manifest.xml succeeds
  • [DSS-939] - dss-pades depends on jcl-over-slf4j
  • [DSS-943] - Enforce the NotQualified SIE qualifier
  • [DSS-967] - NPE when attempting to load an absent TL
  • [DSS-1110] - XADES DSA ASN1 signature not properly converted to DSIG
  • [DSS-1113] - Failed OCSP request causes NPE upon signature validation
  • [DSS-1114] - Incorrect encoding of OCSP nonce in OCSP request
  • [DSS-1115] - OnlineOCSPSource does not support changing nonces
  • [DSS-1116] - Visible signature image metadata stream is not closed
  • [DSS-1124] - XAdES : Incorrect SigningCertificateV2 content
  • [DSS-1125] - No exception is thrown when LOTL Signature is not valid

Improvement

  • [DSS-716] - DSS support for Android
  • [DSS-769] - PNG support
  • [DSS-824] - It would be nice to be able to zoom on PAdES signature images
  • [DSS-848] - Update PDFBox dependency to new 2.0.0 version
  • [DSS-864] - Scale signature image
  • [DSS-881] - Error handling in KeyStoreCertificateSource could be improved
  • [DSS-882] - NullPointerException when DSSUtils.loadCertificate is called with an input stream which is not a certficate
  • [DSS-891] - Remove annotation @PostConstruct on TSLValidator job
  • [DSS-894] - Support of expiredCertsRevocationInfo tag from the TL
  • [DSS-902] - Time-dependent Service information extensions
  • [DSS-908] - Support of additionalServiceInformation from the TL
  • [DSS-920] - Validating XAdES signature using precalculated data file hash
  • [DSS-935] - Retrieve token by alias in keystore
  • [DSS-958] - Very high memory usage when validating some signatures
  • [DSS-962] - Bogus warnings: XMLSignatureException: Signature length not correct: got 256 but was expecting 512 for some successfully validated signatures
  • [DSS-974] - PAdES visual signature, JPEG too big
  • [DSS-1103] - ASiC Plugtests
    • [DSS-1104] - Split ASiC with XAdES/CAdES
    • [DSS-1105] - Remove getNextValidator from DocumentValidator
    • [DSS-1106] - Remove get/setNextDocument from DSSDocument
    • [DSS-1107] - Add information about ASiC container in the validation report
    • [DSS-1108] - Allow to sign more than one document with the demo/webservices
    • [DSS-1109] - Remove setNextReport from Reports
    • [DSS-1111] - ASiC-E + CAdES : incorrect ASiCManifest.xml structure
    • [DSS-1118] - ASiC-E with CAdES : Validation of the manifest files
    • [DSS-1119] - ASiC-S : multi documents signature
  • [DSS-1112] - Allow to set _signatureCards in MOCCASignatureTokenConnection
  • [DSS-1120] - PAdES : upgrade pdfbox dependency
  • [DSS-1122] - Upgrade BouncyCastle dependency
  • [DSS-1123] - Add support for PNGs in PdfBoxSignatureService
  • [DSS-1128] - eIDAS compliance
  • [DSS-1129] - Split framework and demos

Task

  • [DSS-955] - License should be added to github readme.md and to validation-policy project

Release 4.7

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 25 Oct 07:43

Bug

  • [DSS-947] - Validation sub indication issue (NO_CERTIFICATE_CHAIN_FOUND)
  • [DSS-949] - Empty unsigned attributes in PAdES-B-B generation
  • [DSS-950] - DSS/VRI entry invalid digest
  • [DSS-951] - Validation report error in CAdES detached signature wihout uploading the original file
  • [DSS-965] - KeyStoreCertificateSource does not load keystore certificates automatically

Task

  • [DSS-956] - SimpleReport of a PAdES_BASELINE_T signature

Improvement

  • [DSS-936] - Bogus check in PastCertificateValidationAcceptableCheck

Release 4.7.RC2

Release 4.7.RC2 Pre-release
Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 10 Sep 13:37
    Release Notes - DSS - Version 4.7.RC2

Bug

  • [DSS-806] - CommonsDataLoader.java doesnt call httpClient.close();
  • [DSS-883] - TSLValidationJob refresh method does not revalidate country TSLs if only the LOTL changed
  • [DSS-890] - SimpleReport.isSignatureValid(String) fails to handle the new {{TOTAL_PASSED}} indication in 4.7.RC1
  • [DSS-893] - The pre-defined EU TSL signers from the EU TSL signers trust store in the DSS Demo Web Application (keystore.p12) cannot be deleted
  • [DSS-895] - Validation of a signature can influence the validation result of another signature
  • [DSS-915] - Fix detecting signature qualification level based on TL information (QSCD/SSCD check)
  • [DSS-918] - Validation fails for document with revoked signing certificate when ValidationLevel is set to LONG_TERM_DATA, but succeeds when ValidationLevel is ARCHIVAL_DATA
  • [DSS-922] - OCSP revocation errors are not included in simple report

Improvement

  • [DSS-912] - DSS 4.7.RC1 does not build with JDK 7
  • [DSS-931] - Detection of out-dated dss keystore

Release 4.7.RC1

Release 4.7.RC1 Pre-release
Pre-release

Choose a tag to compare

@pvandenbroucke pvandenbroucke released this 08 Jun 15:11

Sub-task

  • [DSS-719] - Expose validation method as REST service
  • [DSS-833] - Remove xpath expressions in the validation
  • [DSS-834] - Update the HTML/PDF reports
  • [DSS-835] - Review the validation policy
  • [DSS-836] - Test the new validation with the PlugTests

Bug

  • [DSS-650] - ASiC-e with CAdES extension fails
  • [DSS-666] - ASiC and CertificatePool sharing
  • [DSS-747] - PAdES visual signature is distorted while using both text and image
  • [DSS-752] - NullPointerException extending XAdES-B to LTA when <xades:SignedDataObjectProperties> not present
  • [DSS-780] - DSS webapp validates only first asice xades signature
  • [DSS-787] - DSS/VRI does not include indirect references to already added objects
  • [DSS-789] - Missing TS revocation data in PAdES LTA generated with the Standalone App
  • [DSS-790] - Missing TS revocation data in PAdES augmentation to LT/LTA-Level from B-Level
  • [DSS-792] - Singing certificate included twice in ds:KeyInfo
  • [DSS-799] - Augmentation from ASiC-E to ASiC-S and vice versa allowed
  • [DSS-814] - Temporaries files are not deleted in PAdES signature
  • [DSS-817] - Error parsing tag IssuerSerial
  • [DSS-819] - Validation reports ignore some ArchiveTimestamp validation errors
  • [DSS-820] - Cannot sign multiple files using XAdES enveloped
  • [DSS-823] - Visual PAdES signature image file not closed
  • [DSS-825] - 4.6.0 DSS ASIC, DSS XAdES could not resolve reference URI if it contains "+" symbol
  • [DSS-827] - Constructor for CommonTrustedCertificateSource is bogus
  • [DSS-828] - OCSP requests should not have nonce extension set as critical
  • [DSS-829] - OnlineOCSPSource contains bad error handling
  • [DSS-830] - DSS cookbook example won't work
  • [DSS-839] - Error validating signature with timestamp when time zone configured
  • [DSS-841] - PAdES-LTA signed pdf validated as indeterminate after signed certificate expiration
  • [DSS-843] - Unused SOAP validation service in development 4.7 branch
  • [DSS-845] - OfflineCRLSource is rejecting some CRL
  • [DSS-846] - NPE while extending a signature with remote services
  • [DSS-850] - https (with mutal authentication) timestamping not supported in CommonsDataLoader
  • [DSS-851] - CAdESSignature.checkSignatureIntegrity accepts invalid signature
  • [DSS-852] - XAdES : ordering of tags in SignatureProductionPlaceV2
  • [DSS-855] - close() method of Pkcs12SignatureTokenConnection should be empty
  • [DSS-861] - dss-service 4.6.0, OCSP unit test failure.
  • [DSS-863] - FileCacheDataLoader never expires entries
  • [DSS-869] - TSLRepository, NullPointerException
  • [DSS-870] - CommonsDataLoader, client authentication
  • [DSS-871] - Timestamp server, HTTP-400 response
  • [DSS-873] - Pkcs11SignatureToken class is not thread-safe
  • [DSS-874] - xades:SigPolicyHash DigestValue check

Task

  • [DSS-773] - RemoveSignature for Cades

Improvement

  • [DSS-700] - Support for WebServices SOAP and REST
  • [DSS-763] - Improve checking of signer certificate's QC compliance based on TSL
  • [DSS-778] - Enveloping XAdES should add all documents to the references
  • [DSS-801] - Error with DSA / ECDSA signature during signing
  • [DSS-805] - XML Policy Constraint is not validated against XSD
  • [DSS-832] - Support new standard ETSI EN 319 102
  • [DSS-837] - Remove Java applets
  • [DSS-840] - CommonDataLoader : allows to disable redirects
  • [DSS-842] - ASIC-E XAdES should contain manifest.xml
  • [DSS-853] - Support of the CRL extension expiredCertsOnCRL
  • [DSS-857] - Support of OCSP extension ArchiveCutoff
  • [DSS-875] - Fix of LDAP URL parsing and querying attributes