<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenDNSSEC</title>
	<atom:link href="http://www.opendnssec.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.opendnssec.org</link>
	<description>OpenDNSSEC News</description>
	<lastBuildDate>Mon, 30 Jan 2012 08:24:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>OpenDNSSEC 1.3.5</title>
		<link>http://www.opendnssec.org/2012/01/23/opendnssec-1-3-5/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-5</link>
		<comments>http://www.opendnssec.org/2012/01/23/opendnssec-1-3-5/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 10:10:20 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=903</guid>
		<description><![CDATA[Version 1.3.5 of OpenDNSSEC has now been released. Auditor: Include the zone name in the log messages. ldns 1.6.12 is required for bugfixes. ods-ksmutil: Suppress database connection information when no -v flag is given. ods-enforcerd: Stop multiple instances of the enforcer running by checking for the pidfile at startup. If you want to run multiple instances then [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.5 of OpenDNSSEC has now been released.</p>
<ul>
<li>Auditor: Include the zone name in the log messages.</li>
<li>ldns 1.6.12 is required for bugfixes.</li>
<li>ods-ksmutil: Suppress database connection information when no -v flag is given.</li>
<li>ods-enforcerd: Stop multiple instances of the enforcer running by checking for the pidfile at startup. If you want to run multiple instances then a different pidfile will need to be specified with the -P flag.</li>
<li>ods-ksmutil: &#8220;zone delete&#8221; renames the signconf file; so that if the zone is put back the signer will not pick up the old file.</li>
<li>Signer Engine: Verbosity can now be set via conf.xml, default is 3.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Bugfix OPENDNSSEC-174: Configure the location for conf.xml with &#8211;config or -c when starting the signer.</li>
<li>Bugfix OPENDNSSEC-192: Signer crashed on deleting NSEC3 for a domain that becomes opt-out.</li>
<li>Bugfix OPENDNSSEC-193: Auditor crashed with certain empty non-terminals.</li>
<li>Signer Engine: A file descriptor for sockets with value zero is allowed.</li>
<li>Signer Engine: Only log messages about a full signing queue in debug mode.</li>
<li>Signer Engine: Fix time issues, make sure that the internal serial does not wander off after a failed audit.</li>
<li>Signer Engine: Upgrade ldns to avoid future problems on 32-bit platforms with extra long signature expiration dates. More information in separate announcement.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.5.tar.gz">opendnssec-1.3.5.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/01/23/opendnssec-1-3-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SoftHSM 1.3.1</title>
		<link>http://www.opendnssec.org/2012/01/17/softhsm-1-3-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=softhsm-1-3-1</link>
		<comments>http://www.opendnssec.org/2012/01/17/softhsm-1-3-1/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 21:18:36 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=892</guid>
		<description><![CDATA[Version 1.3.1 of SoftHSM has now been released. The library is now installed in $libdir/softhsm/ Bugfixes: Do not give a warning about the schema version if the token  has not been initialized yet. The tools now return the correct exit code. Download the tarball from: softhsm-1.3.1.tar.gz]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.1 of SoftHSM has now been released.</p>
<ul>
<li>The library is now installed in $libdir/softhsm/</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Do not give a warning about the schema version if the token  has not been initialized yet.</li>
<li>The tools now return the correct exit code.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/softhsm-1.3.1.tar.gz">softhsm-1.3.1.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/01/17/softhsm-1-3-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security bug: Off-by-one error and new year</title>
		<link>http://www.opendnssec.org/2012/01/17/security-bug-off-by-one-error-and-new-year/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-bug-off-by-one-error-and-new-year</link>
		<comments>http://www.opendnssec.org/2012/01/17/security-bug-off-by-one-error-and-new-year/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 15:29:48 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Deployment]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=894</guid>
		<description><![CDATA[During the end of last year, a bug was uncovered in the library ldns. The bug had an off-by-one error which caused some signatures to have the expiration date set to December 31 2012. 64-bit versions are unaffected. Affected versions: ldns &#60; 1.6.12 (32-bit) Fixed versions: ldns &#62;= 1.6.12 (32-bit) Description: The 32-bit version of [...]]]></description>
			<content:encoded><![CDATA[<p>During the end of last year, a bug was uncovered in the library ldns. The bug had an off-by-one error which caused some signatures to have the expiration date set to December 31 2012. 64-bit versions are unaffected.</p>
<p><strong>Affected versions:</strong> ldns &lt; 1.6.12 (32-bit)<br />
<strong>Fixed versions:</strong> ldns &gt;= 1.6.12 (32-bit)</p>
<p><strong>Description:</strong><br />
The 32-bit version of ldns has code for converting days since epoch to the day of year. That code had a bug which handled the end of the year in the wrong way. The result of the bug was that some signatures got the intended validity period extended by a year. The signature will be reused by the Signer Engine until the key is rolled. However, the Enforcer is not aware that there exist signatures with such a long validity period. Any affected signature will thus have no post-publication of its corresponding DNSKEY, possibly resulting in validation failure. There is also the risk that the affected signature will be used in a replay attack.</p>
<p><strong>Test for affected signatures:</strong><br />
The affected signatures can be spotted by reviewing your signed zone. E.g. by using the following command:<br />
<em>&gt; grep &#8220;20121231[0-9]\{6\} 2011&#8243; signed.zone.file</em></p>
<p><strong>Remove the affected signatures:</strong><br />
If there are signatures in the zone with extra long validity periods, then it is recommended to recreate all of the signatures. This is done by clearing the internal storage of the Signer Engine. You then wait for the next scheduled re-sign, but you can also force an immediate re-sign (the second command below) to speed up the process:<br />
<em>&gt; ods-signer clear &lt;zone&gt;</em><br />
<em> &gt; ods-signer sign &lt;zone&gt;</em></p>
<p><strong>Mitigate replay attacks:</strong><br />
Once the affected signatures are removed from the zone, it may also be advisable to roll your keys. If you have a non-static zone and are changing your zone data, then there is a chance for an attacker to replay old data since the signature is still valid. You need to assess the risk and possible cost of such an attack. If you need to mitigate such an attack, then you need to roll your keys. Rolling keys will invalidate any signatures that an attacker may have stored for later use. If the signature of the DNSKEY RRset was affected, then you also need to roll the KSK:<br />
<em>&gt; ods-ksmutil key rollover &#8211;zone &lt;zone&gt; &#8211;keytype ZSK</em><br />
<em> &gt; ods-ksmutil key rollover &#8211;zone &lt;zone&gt; &#8211;keytype KSK</em></p>
<p><strong>Solution:</strong><br />
The issue has been fixed in ldns 1.6.12. You should upgrade ldns before the end of this year.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/01/17/security-bug-off-by-one-error-and-new-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.4</title>
		<link>http://www.opendnssec.org/2011/12/09/opendnssec-1-3-4/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-4</link>
		<comments>http://www.opendnssec.org/2011/12/09/opendnssec-1-3-4/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 14:00:29 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=887</guid>
		<description><![CDATA[Version 1.3.4 of OpenDNSSEC has now been released. Bugfixes: Signer: Use debug instead of warning for drudgers queue being full, also sleep 10 ms if it is full to not hog CPU. This increased signing speed on single core machines by a factor of 2. Download the tarball from: opendnssec-1.3.4.tar.gz]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.4 of OpenDNSSEC has now been released.</p>
<p>Bugfixes:</p>
<ul>
<li>Signer: Use debug instead of warning for drudgers queue being full, also sleep 10 ms if it is full to not hog CPU. This increased signing speed on single core machines by a factor of 2.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.4.tar.gz">opendnssec-1.3.4.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/12/09/opendnssec-1-3-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.3</title>
		<link>http://www.opendnssec.org/2011/11/17/opendnssec-1-3-3/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-3</link>
		<comments>http://www.opendnssec.org/2011/11/17/opendnssec-1-3-3/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 18:24:48 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=861</guid>
		<description><![CDATA[Version 1.3.3 of OpenDNSSEC has now been released. Bugfixes: Auditor: Handle ruby 1.9 differences in ods-kaspcheck. Auditor: Require dnsruby 1.53 for bugfixes. Bugfix #262: Drudgers seem to be in a waiting state, but the RRset FIFO queue is full. Do an additional broadcast. Enforcer: Check HSM connection when waking up from sleep, attempt to reconnect if it [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.3 of OpenDNSSEC has now been released.</p>
<p>Bugfixes:</p>
<ul>
<li>Auditor: Handle ruby 1.9 differences in ods-kaspcheck.</li>
<li>Auditor: Require dnsruby 1.53 for bugfixes.</li>
<li>Bugfix #262: Drudgers seem to be in a waiting state, but the RRset FIFO queue is full. Do an additional broadcast.</li>
<li>Enforcer: Check HSM connection when waking up from sleep, attempt to reconnect if it is not valid. (r5511 in trunk, ported into the branch due to issues seen when CKR_DEVICE_ERROR returned by HSM.)</li>
<li>libhsm: Added hsm_check_context() to check if the associated sessions are still alive. (Required for the above.)</li>
<li>ods-ksmutil: key import was not setting the retire time.</li>
<li>Signer Engine: Fix a threading issue, that could leave a zone without a task.</li>
<li>Signer Engine: Update the signed zone file if only the $TTL or explicit TTL has been changed.</li>
<li>Signer Engine: Remove the NSEC3PARAM RR when doing NSEC3 to NSEC rollover.</li>
<li>Signer Engine: Deal with carriage returns (dos format) in zone file.</li>
<li>Signer Engine:  is PT0S means that refresh equals signtime.</li>
<li>Signer Engine: Defense in depth in signer for duplicate keys.</li>
<li>Signer Engine: Make sure that all required zonelist elements exist, otherwise error.</li>
<li>Signer Engine: Warn the user if the serial is b0rk, and you can not use the serial from the signconf.</li>
<li>Signer Engine: Log Auditor exit code.</li>
<li>Fix a similar bug like #257: Error in ods-signerd, where a corrupted backup file results in an invalid pointer free().</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.3.tar.gz">opendnssec-1.3.3.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/11/17/opendnssec-1-3-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enforcer NG alpha-2 snapshot</title>
		<link>http://www.opendnssec.org/2011/10/18/enforcer-ng-alpha-2-snapshot/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=enforcer-ng-alpha-2-snapshot</link>
		<comments>http://www.opendnssec.org/2011/10/18/enforcer-ng-alpha-2-snapshot/#comments</comments>
		<pubDate>Tue, 18 Oct 2011 12:17:13 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=846</guid>
		<description><![CDATA[We have now release a second alpha snapshot of the upcoming version of Enforcer. This version should only be used for testing, but we welcome feedback on it. Changes: Support for RollOverType in kasp.xml Fixed concurrency related crashes. Automatically retract never submitted DS records. Schedule the purging of keys. Automatic introduce keys marked as manual, [...]]]></description>
			<content:encoded><![CDATA[<p>We have now release a second alpha snapshot of the upcoming version of Enforcer. This version should only be used for testing, but we welcome feedback on it.</p>
<p>Changes:</p>
<ul>
<li>Support for RollOverType in kasp.xml</li>
<li>Fixed concurrency related crashes.</li>
<li>Automatically retract never submitted DS records.</li>
<li>Schedule the purging of keys.</li>
<li>Automatic introduce keys marked as manual, like other enforcer.</li>
<li>Do not allow lifetime of key to be shorter than TTL.</li>
<li>CSK is now configurable.</li>
<li>Remove some scheduling when waiting for user input.</li>
</ul>
<p>Read more information about the Enforcer NG:<br />
<a href="http://svn.opendnssec.org/tags/OpenDNSSEC-enforcer-ng-20111018/README.enforcer_testers">README.enforcer_testers</a></p>
<p>Download the snapshot from our SVN:<br />
<a href="http://svn.opendnssec.org/tags/OpenDNSSEC-enforcer-ng-20111018">OpenDNSSEC-enforcer-ng-20111018</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/10/18/enforcer-ng-alpha-2-snapshot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enforcer NG alpha snapshot</title>
		<link>http://www.opendnssec.org/2011/09/23/enforcer-ng/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=enforcer-ng</link>
		<comments>http://www.opendnssec.org/2011/09/23/enforcer-ng/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 10:16:13 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=816</guid>
		<description><![CDATA[We have now release an alpha snapshot of the upcoming version of Enforcer. This software should only be used for testing, but we welcome feedback on it. HIGH-LEVEL DESIGN GOALS Support for a large number of zones. The enforcer should reasonably be useable with many zones. Think order of magnitude 50.000 concurrent zones. Allow for future [...]]]></description>
			<content:encoded><![CDATA[<p>We have now release an alpha snapshot of the upcoming version of Enforcer. This software should only be used for testing, but we welcome feedback on it.</p>
<p>HIGH-LEVEL DESIGN GOALS</p>
<ul>
<li>Support for a large number of zones.<br />
The enforcer should reasonably be useable with many zones. Think order of magnitude 50.000 concurrent zones.</li>
<li>Allow for future rollover strategies.<br />
Provide a generic framework to implement other kinds of rollovers in the future.</li>
<li>Drop in replacement.<br />
Should replace the current enforcer but keep the same interface and provide migration scripts from earlier installs.</li>
</ul>
<p>Read more information about the Enforcer NG:<br />
<a href="http://svn.opendnssec.org/tags/OpenDNSSEC-enforcer-ng-20110922/README.enforcer_testers">README.enforcer_testers</a></p>
<p>Download the snapshot from our SVN:<br />
<a href="http://svn.opendnssec.org/tags/OpenDNSSEC-enforcer-ng-20110922">OpenDNSSEC-enforcer-ng-20110922</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/09/23/enforcer-ng/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.2</title>
		<link>http://www.opendnssec.org/2011/09/13/opendnssec-1-3-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-2</link>
		<comments>http://www.opendnssec.org/2011/09/13/opendnssec-1-3-2/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 11:43:40 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=812</guid>
		<description><![CDATA[Version 1.3.2 of OpenDNSSEC has now been released. Bugfixes: Bugfix #257: Error in ods-signerd, where a corrupted backup file results in an invalid pointer free(). Signer Engine: Mark that a zone has a valid signer configuration, after recovering the zone from the backup files. Download the tarball from: opendnssec-1.3.2.tar.gz]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.2 of OpenDNSSEC has now been released.</p>
<p>Bugfixes:</p>
<ul>
<li>Bugfix #257: Error in ods-signerd, where a corrupted backup file results in an invalid pointer free().</li>
<li>Signer Engine: Mark that a zone has a valid signer configuration, after recovering the zone from the backup files.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.2.tar.gz">opendnssec-1.3.2.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/09/13/opendnssec-1-3-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.1</title>
		<link>http://www.opendnssec.org/2011/09/07/opendnssec-1-3-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-1</link>
		<comments>http://www.opendnssec.org/2011/09/07/opendnssec-1-3-1/#comments</comments>
		<pubDate>Wed, 07 Sep 2011 09:54:32 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=806</guid>
		<description><![CDATA[Version 1.3.1 of OpenDNSSEC has now been released. Bugfixes: Auditor: Fix &#8216;ZSK in use too long&#8217; message to handle new signer behaviour. Bugfix #255: RHEL6 patch to contrib/opendnssec.spec. (Rick van Rein) Bugfix #256: Make sure argument in &#8220;ods-control signer&#8221; is not stripped off. Bugfix #259: ods-ksmutil: Prevent MySQL username or password being interpreted by the [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.1 of OpenDNSSEC has now been released.</p>
<p>Bugfixes:</p>
<ul>
<li>Auditor: Fix &#8216;ZSK in use too long&#8217; message to handle new signer behaviour.</li>
<li>Bugfix #255: RHEL6 patch to contrib/opendnssec.spec. (Rick van Rein)</li>
<li>Bugfix #256: Make sure argument in &#8220;ods-control signer&#8221; is not stripped off.</li>
<li>Bugfix #259: ods-ksmutil: Prevent MySQL username or password being interpreted by the shell when running &#8220;ods-ksmutil setup&#8221;.</li>
<li>Bugfix #260: &#8220;ods-ksmutil zone list&#8221; now handles empty zonelists.</li>
<li>Enforcer: Unsigned comparison resulting in wrong error message.</li>
<li>ods-ksmutil: fixed issue where first ds-seen command run on a zone would work, but return an error code and not send a HUP to the enforcerd.</li>
<li>Signer Engine: A threading issue occasionally puts the default validity on NSEC(3) RRs and the denial validity on other RRs.</li>
<li>Signer Engine: An update command could interrupt the signing process and the zone would get missing signatures.</li>
<li>Signer Engine: Fix an issue where some systems could not copy the zone file.</li>
<li>Zonefetcher: Check inbound serial in transferred file, to prevent redundant zone transfers.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.1.tar.gz">opendnssec-1.3.1.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/09/07/opendnssec-1-3-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SoftHSM 1.3.0</title>
		<link>http://www.opendnssec.org/2011/08/12/softhsm-1-3-0/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=softhsm-1-3-0</link>
		<comments>http://www.opendnssec.org/2011/08/12/softhsm-1-3-0/#comments</comments>
		<pubDate>Fri, 12 Aug 2011 14:10:24 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=793</guid>
		<description><![CDATA[Version 1.3.0 of SoftHSM has now been released. Can now read CKA_ALWAYS_AUTHENTICATE but does not use it. Encryption and decryption using CKM_RSA_PKCS. Support X.509 certificates. (Patch from Thomas Calderon) Updated backup instructions. Only a Security Officer can set CKA_TRUSTED to true. The softhsm tool can set the value of CKA_TRUSTED. Support Botan 1.10.0. Better signing [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.0 of SoftHSM has now been released.</p>
<ul>
<li>Can now read CKA_ALWAYS_AUTHENTICATE but does not use it.</li>
<li>Encryption and decryption using CKM_RSA_PKCS.</li>
<li>Support X.509 certificates. (Patch from Thomas Calderon)</li>
<li>Updated backup instructions.</li>
<li>Only a Security Officer can set CKA_TRUSTED to true.</li>
<li>The softhsm tool can set the value of CKA_TRUSTED.</li>
<li>Support Botan 1.10.0.</li>
<li>Better signing performance with a single element cache for the PK_Signer object.</li>
<li>Document README.MinGW describes how to build on Windows. (Text and patches contributed by Jaroslav Imrich)</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>API changes in Botan created a namespace collision.</li>
<li>API changes in Botan&#8217;s state handling.</li>
<li>BigInt::to_u32bit was accidently dropped in Botan. Adding it as a compatibility function to SoftHSM.</li>
<li>Better exception handling.</li>
<li>CKF_USER_PIN_COUNT_LOW and CKF_SO_PIN_COUNT_LOW must be set if an incorrect PIN has been entered at least once.</li>
<li>Windows: Detect LoadLibrary.</li>
<li>Windows: Set CRYPTOKI_EXPORTS.</li>
<li>Windows: Load library correctly in softhsm.</li>
<li>Windows: Compatibility function for getpass.</li>
<li>Windows: Use _putenv and not setenv.</li>
<li>Windows: Generate the DLL file.</li>
<li>Windows: The softhsm tool will use the DLL file by default.</li>
<li>Windows: Log to EventLog.</li>
<li>Windows: Fix parsing of configuration file.</li>
<li>Windows: The check program now links with a shared libgcc in order to make the exceptions work.</li>
</ul>
<p>Known issue:</p>
<ul>
<li>Firefox does improper setting of CKA_DERIVE attribute during PKCS#12 import. See https://bugzilla.mozilla.org/show_bug.cgi?id=515663</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/softhsm-1.3.0.tar.gz">softhsm-1.3.0.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2011/08/12/softhsm-1-3-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

