Skip to content

Version 1.4.0

Latest

Choose a tag to compare

@github-actions github-actions released this 07 Oct 05:01
f392bda

Release Build (from refs/tags/v1.4.0/f392bdae4120f8a898644056546bfea33eeee783)

Upgrade notes

  • Go 1.24 or later is required to build certstrap from source.
  • New arm64 binaries: this release adds certstrap-darwin-arm64 and certstrap-linux-arm64, plus a SHA256SUMS file for all binaries.
  • CRL requirements: init and revoke now create CRLs with Go's x509.CreateRevocationList. It requires the CA certificate to have a subject key ID and, if the certificate lists key usages, the CRL signing usage. CAs created by certstrap already have both, so this only affects CA certificates added to a depot by another tool.
  • Existing CRLs: revoke still reads the v1 CRLs written by earlier releases. The CRLs it writes are v2, with a CRL number that goes up by one on each revoke.
  • --version now comes from Go build info. go install github.com/square/certstrap@v1.4.0 reports 1.4.0. Builds without git metadata, including the Docker image, report (devel).

What's Changed

New Contributors

Full Changelog: v1.3.0...v1.4.0