From 507a3558c5385a0e8cac670ca0b0aae7bbe35cbb Mon Sep 17 00:00:00 2001 From: Tim Bruijnzeels Date: Wed, 12 May 2021 10:30:05 +0200 Subject: [PATCH] Improve changelog for 0.9.0-RC2 --- Changelog.md | 38 +++++++++++++++++++++++++++++--------- 1 file changed, 29 insertions(+), 9 deletions(-) diff --git a/Changelog.md b/Changelog.md index 62c38f9f..e870d0d7 100644 --- a/Changelog.md +++ b/Changelog.md @@ -2,7 +2,35 @@ ## 0.9.0 RC 2 -Welcome to the Krill 0.9.0 Release Candidate. +This release candidate fixes a number of issues introduced in 0.9.0-rc1: + +- Log migration progress and speed up process (#503) +- Rename auto-renewal commands in history (#501) +- Re-issue objects properly during a key rollover (#509) +- Withdraw objects when removing a parent (#508) + +Furthermore we made the following improvements: + +- Report *which* file/dir was involved in case of I/O errors (#495) +- Change HTTP access log to 'debug'. Use KRILL_HTTP_LO_INFO_=1 if you want 'info' (#513) +- Refine logging command / change logging (#518) +- Improve certificate request logic and logging (#514) + +Regarding certificate request logic and logging. Krill CAs will now report *which* new resources +were received from, or removed by a parent. As part of this change we also fixed a harmless, +but annoying, bug in certificate request logic. Krill would wrongfully report that a parent had +reduced the eligible 'not after' time, when in fact it had extended it, and then request the +new certificate regardless. Krill will now report correctly, and will only request a new certificate +if the new 'not after' time is more than 10% further into the future compared to the current certificate. +This is safe and will reduce noise levels where parent CAs use a simple strategy which returns a +new 'not after' time for every request. + +The UI also received some fixes: +- Show the repository status properly (introduced in 0.9.0-rc1) +- Update the link to documentation +- Show the alert banner for new versions only for 'production' version + +## 0.9.0 RC 1 This release introduces a number of breaking API changes as well as new functionality. We invite users to test this release and contact us in case of any issues, comments or questions. @@ -162,14 +190,6 @@ the rather unlikely case that a parent CA temporarily removed one of your resour Let the Publication Server write the notification.xml file to a new file, and then rename it. This prevents that Relying Parties can retrieve a half-written file. (#352) -Logging is now much less noisy. And Krill CAs will report *which* new resources were received -from, or removed by a parent. As part of this change we also fix a harmless, but annoying, bug -in certificate request logic. Krill would wrongfully report that a parent had reduced the -eligible 'not after' time, when in fact it had extended it. Furthermore Krill will now request -a new certificate only if the new 'not after' time is more than 10% further into the future -compared to the current certificate - this is safe and will reduce noise levels where parent -CAs use a simple strategy which returns a new 'not after' time for every request. (#513, #514) - ## 0.8.2 'Can't touch this' As it turned out the previous release (0.8.1) still insisted on cleaning up 'redundant ROAs'