diff options
Diffstat (limited to 'Changelog')
| -rw-r--r-- | Changelog | 16 |
1 files changed, 14 insertions, 2 deletions
@@ -1,10 +1,22 @@ +lacme (0.8.4) upstream; + + + accountd: Use PKCS#1 v1.5 signatures, as it's what JWT RS256 uses. + This change is needed for compatibility with Crypt::OpenSSL::RSA 0.38 + and later. + + Fix 'drop-privileges' test. + + Update test suite to match staging server behavior. + + Drop OCSP must-staple extension test which is no longer available on + Let's Encrypt's ACME server. + + -- Guilhem Moulin <guilhem@fripost.org> Mon, 20 Jul 2026 19:52:28 +0200 + lacme (0.8.3) upstream; - + Fix post-issuance validation logic. We avoid pining the + + Fix post-issuance validation logic. We avoid pinning the intermediate certificates in the bundle and instead validate the leaf certificate with intermediates supplied during issuance as untrusted (used for chain building only). Only the root - certificates are used as trust anchor. Not pining intermediate + certificates are used as trust anchor. Not pinning intermediate certificates is in line with Let's Encrypt's latest recommendations. + Pass `-in /dev/stdin` option to openssl(1) to avoid warning with OpenSSL 3.2 or later. |
