Here's a random list of issues that I have had with the client or would like
to see, some of which you've probably already fixed:

 * About half of my certificate requests fail and must be retried due to
"lost connection to MySQL" (running on the same machine as the server)
 * Would _really_ like to see an EE module one of these days, or some way of
securely transporting certificates without having to snail-mail CD's to
people
 * Would like to see additional certificate export formats, such as the
CER/PVK format that so many Windows tools expect and the PEM format that my
OpenVPN program requires.  Also with the option of not specifying a password
(PEM only) and the option of not exporting the complete certificate chain.
 * Will I be able to modify/delete "profiles"?  I recognize that this is a
complicated subject (if the profile owns any certificates, they must be
revoked and advertised as such), but if anything it would be nice to just
prune the failed certificate requests.
 * Is there any way to be informed if a certificate is about to expire, or
do I wait for the users to be denied access and then snail-mail another CD
to them?
 * The last server upgrade required me to wipe my certificate store, as the
database format had changed and the new version refused to read the older
database.  It wasn't a big deal then (the PKI was just coming into
production and the older data was obsolete), but I would like a
version-independant dump of the entire contents of the PKI (something like
what Subversion uses?) that is not tied to the MySQL database schema and
therefore cannot be rejected by any future version of the program.
 * I would like this version-independant dump to allow me to individually
load/unload modules from the PKI, adding/removing them from the underlying
database.  This would allow me to unload the root CA from the database (If I
so choose to do it) and either load it onto a more secure machine or choose
to keep it offline until its needed again.

So, is that enough change requests for the next version ;-)

Here's hoping to improve what I see is the best PKI administration product
out there...

----- Original Message ----- 
From: "Fr�d�ric Giudicelli" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Sunday, July 25, 2004 3:15 PM
Subject: newpki-beta4


I'm about to release newpki-beta4, here is the ChangeLog, if there are
any changes you would like to see in the upcoming version please let me
know in the next 24 hours.

- Removed "Includes/SQL/SQL_CMD.h".
- A CA republishes every 12 hours all its certificates, revocation and CRLs.
- The repositories are now "purged", meaning when they synchronize they
no more send the list all the known requests/responses, which over time
would have used way too many resources.
- Improved memory usage in PKI_CRL.
- Simplified the synchronization code.
- The CA now stores the LDAP UID, it allows the publication to be
handled a better way when a certificate is generated/revoked for the CA GUI.
- Optimized the repository database.
- Fixed a problem in LDAP synchronization, when a RA's DN Spec didn't
have a default value, and when the field wasn't present in the LDAP result.
- Fixed the problems related to bad translations. (Rapha�l Pr�cigout)
- Added support for DN access in extensions.
ex. subjectAltName=email:<dn>emailAddress:move</dn>.
The supported actions are move and copy.
- In PKI GUI, disabled "Configure Entity" for entities that had no
configuration window.
- Moved "Includes/Conf.h" and "Includes/Conf.cpp" to "Server/".
- Improved the entities' links verification algorithm. (Wolf)
- When creating a PKI User certificate, if the private key is of
software kind, it's now generated on server side, and a PKCS#12 is sent
back to the user.
- Improved the code for PKI Users management on Client Side.
- Improved the inter-repositories configuration synchronization
algorithm, the number of connections used to be n*(n-1) where n is the
number of repositories, now it is much less.
- Added the options to specify the path to openssl, in
publication_ldap's configure (Paul Freeman).
- When the socket server is fully started, It now yields to the rest of
the PKI, that it can start working. There is more stupid waiting.
- Fixed a few memory leaks in the repositories.
- Improved the synchronization algorithm for a firewalled repository.
- Removed the global signature for the profiles.
- Improved memory usage in SockServerADMIN.
- Improved memory usage in PKI_CSR.
- If there is an error reading a certificate from the CA GUI, the faulty
certificate is displayed.
- Optimized SQL::FormatString and SQL::Value.
- Fixed a bug where the new users would never show up in the ACL.
- Now using SSL sessions cache, to improve performances.
- Improved memory usage in the handling of the protocol, to avoid having
a list of objects growing up and never being flushed if the repository
is temporarly unavailable.
- Greatly improved the use of Mutex in AsynchJobs.
- When inserting a profile and the owner is a group, validating that the
group exists.
- Added the possibility to change a profile's LDAP UID.
- Added the possibility to change a profile's Owner.
- Added the possibility to change a profile's DN.
- Added the possibility to delete a profile and all its associated
certificates.
- Upgraded to openssl 0.9.7d.
- Encapsulated all the ASN1 structures used by NewPKI into classes, this
will greatly improve the security of NewPKI, and help the code maintenance.
- It's no more possible to send two times a request to a repository.
- When an entity fails to load it's now displayed into the Server GUI,
which will allow it to be removed if necessary.
- It's now possible to load/unload an entity from the Server GUI.
- Improved speed of PKI_CERT, datas are only loaded/parsed when they're
needed.
- Removed a deadlock in ReadersWriter.
- Added an internalID to NewpkiRequest, this internalID is set by the
requester, the repository verifies that it doesn't already know it, this
avoids a requester
to send two times the same request.
- Rewrote the full synchronization algorithm for repositories, the old
one wasn't adapted to a large number of data.
- Added the possibility to view from the RA the end-user certificate as
a PKCS#7.
- Added the possibility to view the CA certificate as a PKCS#7.
- Saving the inter-repository objects to DB, instead of using a memory list.

Regards,
-- 
Fr�d�ric Giudicelli
http://www.newpki.org
_____________________________________________________________________
NewPKI                                          http://www.newpki.org
User Support Mailing List                     [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

_____________________________________________________________________
NewPKI                                          http://www.newpki.org
User Support Mailing List                     [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to