Release v1.3.0
·
5 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Full Changelog: v1.2.0...v1.3.0
Cryptare v1.3.0
This release moves the key store out of the current folder, makes passwords independent of how their characters were typed, and ships licence files with every download. Read "Upgrading" before you install it on one machine and not the others.
Highlights
- The key store has a fixed home. Without
CRYPTARE_DB_PATH, keys are stored incryptare/cryptare.dbin your user data folder:~/.local/share(or$XDG_DATA_HOME) on Linux,~/Library/Application Supporton macOS,%LocalAppData%on Windows. The folder is created readable only by you. Running a command in a different folder no longer gives you a different, or someone else's, key store. cryptare keys pathprints which key store is in use, without creating anything.- Passwords are normalised. An accented letter typed as one character or as a letter plus a combining accent, full-width letters, ligatures and similar variants now give the same key (Unicode NFKC, as NIST SP 800-63B recommends). A byte order mark that an editor put at the start of a
--password-fileis ignored. The 15-character minimum counts the normalised password. - Licences in every archive: each download now holds
LICENSE,NOTICEandTHIRD_PARTY_LICENSES.txt, with the licences of the Go standard library and every Go module built into the binary.
Security fixes
- The default key store no longer depends on the current folder, so a
cryptare.dbplanted in a shared folder, a cloned repository or an extracted archive is never used unless you pointCRYPTARE_DB_PATHat it. - CI now fails if a key database or key export is ever committed to the repository.
Upgrading from v1.2.0 or earlier
- Key store: your existing keys stay in
cryptare.dbin whichever folder you ran Cryptare from. When akeyscommand or the TUI finds one in the current folder, it prints a notice with the command to move it to the new location (or tells you to setCRYPTARE_DB_PATHif the new store already exists). Cryptare never opens or moves that file itself. To keep the old behaviour, setCRYPTARE_DB_PATH=./cryptare.db. The Docker image already setsCRYPTARE_DB_PATHand is unaffected. - Format: data protected with a password that normalisation changes (accents typed as combining characters, full-width letters, a password file starting with a byte order mark) is marked in its header, and v1.2.0 and earlier refuse it with "unsupported encrypted data: key derivation 2". Upgrade every machine that needs to read it. Data protected with any other password is written exactly as before, and v1.2.0 reads it.
- Files and keys that v1.2.0 or earlier protected with a password typed with combining accents still need the password typed that way.
- If
HOME(or%LocalAppData%on Windows) isn't set, thekeyscommands and the TUI ask you to setCRYPTARE_DB_PATHinstead of using the current folder.
Install
Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.