mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-09-30 05:14:52 +02:00
Improve changelog for 0.9.0-RC2
This commit is contained in:
+29
-9
@@ -2,7 +2,35 @@
|
||||
|
||||
## 0.9.0 RC 2
|
||||
|
||||
Welcome to the Krill 0.9.0 Release Candidate.
|
||||
This release candidate fixes a number of issues introduced in 0.9.0-rc1:
|
||||
|
||||
- Log migration progress and speed up process (#503)
|
||||
- Rename auto-renewal commands in history (#501)
|
||||
- Re-issue objects properly during a key rollover (#509)
|
||||
- Withdraw objects when removing a parent (#508)
|
||||
|
||||
Furthermore we made the following improvements:
|
||||
|
||||
- Report *which* file/dir was involved in case of I/O errors (#495)
|
||||
- Change HTTP access log to 'debug'. Use KRILL_HTTP_LO_INFO_=1 if you want 'info' (#513)
|
||||
- Refine logging command / change logging (#518)
|
||||
- Improve certificate request logic and logging (#514)
|
||||
|
||||
Regarding certificate request logic and logging. Krill CAs will now report *which* new resources
|
||||
were received from, or removed by a parent. As part of this change we also fixed a harmless,
|
||||
but annoying, bug in certificate request logic. Krill would wrongfully report that a parent had
|
||||
reduced the eligible 'not after' time, when in fact it had extended it, and then request the
|
||||
new certificate regardless. Krill will now report correctly, and will only request a new certificate
|
||||
if the new 'not after' time is more than 10% further into the future compared to the current certificate.
|
||||
This is safe and will reduce noise levels where parent CAs use a simple strategy which returns a
|
||||
new 'not after' time for every request.
|
||||
|
||||
The UI also received some fixes:
|
||||
- Show the repository status properly (introduced in 0.9.0-rc1)
|
||||
- Update the link to documentation
|
||||
- Show the alert banner for new versions only for 'production' version
|
||||
|
||||
## 0.9.0 RC 1
|
||||
|
||||
This release introduces a number of breaking API changes as well as new functionality. We invite users
|
||||
to test this release and contact us in case of any issues, comments or questions.
|
||||
@@ -162,14 +190,6 @@ the rather unlikely case that a parent CA temporarily removed one of your resour
|
||||
Let the Publication Server write the notification.xml file to a new file, and then rename it.
|
||||
This prevents that Relying Parties can retrieve a half-written file. (#352)
|
||||
|
||||
Logging is now much less noisy. And Krill CAs will report *which* new resources were received
|
||||
from, or removed by a parent. As part of this change we also fix a harmless, but annoying, bug
|
||||
in certificate request logic. Krill would wrongfully report that a parent had reduced the
|
||||
eligible 'not after' time, when in fact it had extended it. Furthermore Krill will now request
|
||||
a new certificate only if the new 'not after' time is more than 10% further into the future
|
||||
compared to the current certificate - this is safe and will reduce noise levels where parent
|
||||
CAs use a simple strategy which returns a new 'not after' time for every request. (#513, #514)
|
||||
|
||||
## 0.8.2 'Can't touch this'
|
||||
|
||||
As it turned out the previous release (0.8.1) still insisted on cleaning up 'redundant ROAs'
|
||||
|
||||
Reference in New Issue
Block a user