github lsh123/xmlsec xmlsec_1_3_10-rc1
XMLSec 1.3.10 (rc1)

pre-release15 hours ago

Please test the release candidate 1.3.10-rc1 (signature) and let me know if you see any issues:

  • The minimum supported versions for dependencies are now: LibXML2 >= 2.9.13 (February 19, 2022), LibXSLT >= 1.1.35 (February 16, 2022), OpenSSL >= 3.0.13 (January 30, 2024), LibreSSL >= 3.9.0 (March 9, 2024), NSS >= 3.91 (June 26, 2023), NSPR >= 4.34.1 (June 26, 2023), GnuTLS >= 3.8.3 (January 1, 2024).
  • (xmlsec-core) Disabled all key value data for all key types by default (use '--enabled-key-data' flag to re-enable if needed).
  • (xmlsec-core) Added '--enable-asn1-signatures-hack' option to allow generation / verification of ASN1 signature values.
  • (xmlsec-core) Added '--verify-crls' option to verify CRLs when loading from command line.
  • (xmlsec-openssl) Added support for EdDSA signature algorithm; XDH (X25519 and X448) key agreement algorithms; HKDF key derivation algorithm; Camellia block cipher and key wrap algorithms; ChaCha20 and ChaCha20-Poly1305 encryption algorithms; and experimental ML-DSA and SLH-DSA-SHA2 signature algorithms.
  • (xmlsec-gnutls) Added support for EdDSA signature algorithms; ECDH and XDH (X25519 and X448) key agreement algorithms; ConcatKDF, PBKDF2, and HKDF key derivation algorithms; ChaCha20 and ChaCha20-Poly1305 encryption algorithms; SHA2-224 and SHA3-224 digest algorithms; and experimental support for ML-DSA signature algorithms.
  • (xmlsec-nss) Added support for EdDSA (Ed25519) signature algorithms; ECDH and XDH (X25519) key agreement algorithms; ConcatKDF and HKDF key derivation algorithms; and ChaCha20-Poly1305 encryption algorithm. Camellia block cipher and key wrap algorithms.
  • (xmlsec-mscng) Added support for DSA-SHA256 signature algorithm; XDH (X25519) and DH (X9.42 DHX) key agreement algorithms; HKDF key derivation algorithm; and SHA3 digest algorithms.
  • (xmlsec-mscng) Added support for loading CRLs from command line.
  • (xmlsec-test) Created scripts to generate keys, regenerated all keys with standard names, and updated tests accordingly.
  • Several other small fixes (see more details).

Don't miss a new xmlsec release

NewReleases is sending notifications on new releases.