Skip to content

Release v1.3.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 21:33
· 5 commits to main since this release
Immutable release. Only release title and notes can be modified.

Full Changelog: v1.2.0...v1.3.0

Cryptare v1.3.0

This release moves the key store out of the current folder, makes passwords independent of how their characters were typed, and ships licence files with every download. Read "Upgrading" before you install it on one machine and not the others.

Highlights

  • The key store has a fixed home. Without CRYPTARE_DB_PATH, keys are stored in cryptare/cryptare.db in your user data folder: ~/.local/share (or $XDG_DATA_HOME) on Linux, ~/Library/Application Support on macOS, %LocalAppData% on Windows. The folder is created readable only by you. Running a command in a different folder no longer gives you a different, or someone else's, key store.
  • cryptare keys path prints which key store is in use, without creating anything.
  • Passwords are normalised. An accented letter typed as one character or as a letter plus a combining accent, full-width letters, ligatures and similar variants now give the same key (Unicode NFKC, as NIST SP 800-63B recommends). A byte order mark that an editor put at the start of a --password-file is ignored. The 15-character minimum counts the normalised password.
  • Licences in every archive: each download now holds LICENSE, NOTICE and THIRD_PARTY_LICENSES.txt, with the licences of the Go standard library and every Go module built into the binary.

Security fixes

  • The default key store no longer depends on the current folder, so a cryptare.db planted in a shared folder, a cloned repository or an extracted archive is never used unless you point CRYPTARE_DB_PATH at it.
  • CI now fails if a key database or key export is ever committed to the repository.

Upgrading from v1.2.0 or earlier

  • Key store: your existing keys stay in cryptare.db in whichever folder you ran Cryptare from. When a keys command or the TUI finds one in the current folder, it prints a notice with the command to move it to the new location (or tells you to set CRYPTARE_DB_PATH if the new store already exists). Cryptare never opens or moves that file itself. To keep the old behaviour, set CRYPTARE_DB_PATH=./cryptare.db. The Docker image already sets CRYPTARE_DB_PATH and is unaffected.
  • Format: data protected with a password that normalisation changes (accents typed as combining characters, full-width letters, a password file starting with a byte order mark) is marked in its header, and v1.2.0 and earlier refuse it with "unsupported encrypted data: key derivation 2". Upgrade every machine that needs to read it. Data protected with any other password is written exactly as before, and v1.2.0 reads it.
  • Files and keys that v1.2.0 or earlier protected with a password typed with combining accents still need the password typed that way.
  • If HOME (or %LocalAppData% on Windows) isn't set, the keys commands and the TUI ask you to set CRYPTARE_DB_PATH instead of using the current folder.

Install

Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.