Here's a random list of issues that I have had with the client or would like to see, some of which you've probably already fixed:
* About half of my certificate requests fail and must be retried due to "lost connection to MySQL" (running on the same machine as the server) * Would _really_ like to see an EE module one of these days, or some way of securely transporting certificates without having to snail-mail CD's to people * Would like to see additional certificate export formats, such as the CER/PVK format that so many Windows tools expect and the PEM format that my OpenVPN program requires. Also with the option of not specifying a password (PEM only) and the option of not exporting the complete certificate chain. * Will I be able to modify/delete "profiles"? I recognize that this is a complicated subject (if the profile owns any certificates, they must be revoked and advertised as such), but if anything it would be nice to just prune the failed certificate requests. * Is there any way to be informed if a certificate is about to expire, or do I wait for the users to be denied access and then snail-mail another CD to them? * The last server upgrade required me to wipe my certificate store, as the database format had changed and the new version refused to read the older database. It wasn't a big deal then (the PKI was just coming into production and the older data was obsolete), but I would like a version-independant dump of the entire contents of the PKI (something like what Subversion uses?) that is not tied to the MySQL database schema and therefore cannot be rejected by any future version of the program. * I would like this version-independant dump to allow me to individually load/unload modules from the PKI, adding/removing them from the underlying database. This would allow me to unload the root CA from the database (If I so choose to do it) and either load it onto a more secure machine or choose to keep it offline until its needed again. So, is that enough change requests for the next version ;-) Here's hoping to improve what I see is the best PKI administration product out there... ----- Original Message ----- From: "Fr�d�ric Giudicelli" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Sunday, July 25, 2004 3:15 PM Subject: newpki-beta4 I'm about to release newpki-beta4, here is the ChangeLog, if there are any changes you would like to see in the upcoming version please let me know in the next 24 hours. - Removed "Includes/SQL/SQL_CMD.h". - A CA republishes every 12 hours all its certificates, revocation and CRLs. - The repositories are now "purged", meaning when they synchronize they no more send the list all the known requests/responses, which over time would have used way too many resources. - Improved memory usage in PKI_CRL. - Simplified the synchronization code. - The CA now stores the LDAP UID, it allows the publication to be handled a better way when a certificate is generated/revoked for the CA GUI. - Optimized the repository database. - Fixed a problem in LDAP synchronization, when a RA's DN Spec didn't have a default value, and when the field wasn't present in the LDAP result. - Fixed the problems related to bad translations. (Rapha�l Pr�cigout) - Added support for DN access in extensions. ex. subjectAltName=email:<dn>emailAddress:move</dn>. The supported actions are move and copy. - In PKI GUI, disabled "Configure Entity" for entities that had no configuration window. - Moved "Includes/Conf.h" and "Includes/Conf.cpp" to "Server/". - Improved the entities' links verification algorithm. (Wolf) - When creating a PKI User certificate, if the private key is of software kind, it's now generated on server side, and a PKCS#12 is sent back to the user. - Improved the code for PKI Users management on Client Side. - Improved the inter-repositories configuration synchronization algorithm, the number of connections used to be n*(n-1) where n is the number of repositories, now it is much less. - Added the options to specify the path to openssl, in publication_ldap's configure (Paul Freeman). - When the socket server is fully started, It now yields to the rest of the PKI, that it can start working. There is more stupid waiting. - Fixed a few memory leaks in the repositories. - Improved the synchronization algorithm for a firewalled repository. - Removed the global signature for the profiles. - Improved memory usage in SockServerADMIN. - Improved memory usage in PKI_CSR. - If there is an error reading a certificate from the CA GUI, the faulty certificate is displayed. - Optimized SQL::FormatString and SQL::Value. - Fixed a bug where the new users would never show up in the ACL. - Now using SSL sessions cache, to improve performances. - Improved memory usage in the handling of the protocol, to avoid having a list of objects growing up and never being flushed if the repository is temporarly unavailable. - Greatly improved the use of Mutex in AsynchJobs. - When inserting a profile and the owner is a group, validating that the group exists. - Added the possibility to change a profile's LDAP UID. - Added the possibility to change a profile's Owner. - Added the possibility to change a profile's DN. - Added the possibility to delete a profile and all its associated certificates. - Upgraded to openssl 0.9.7d. - Encapsulated all the ASN1 structures used by NewPKI into classes, this will greatly improve the security of NewPKI, and help the code maintenance. - It's no more possible to send two times a request to a repository. - When an entity fails to load it's now displayed into the Server GUI, which will allow it to be removed if necessary. - It's now possible to load/unload an entity from the Server GUI. - Improved speed of PKI_CERT, datas are only loaded/parsed when they're needed. - Removed a deadlock in ReadersWriter. - Added an internalID to NewpkiRequest, this internalID is set by the requester, the repository verifies that it doesn't already know it, this avoids a requester to send two times the same request. - Rewrote the full synchronization algorithm for repositories, the old one wasn't adapted to a large number of data. - Added the possibility to view from the RA the end-user certificate as a PKCS#7. - Added the possibility to view the CA certificate as a PKCS#7. - Saving the inter-repository objects to DB, instead of using a memory list. Regards, -- Fr�d�ric Giudicelli http://www.newpki.org _____________________________________________________________________ NewPKI http://www.newpki.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] _____________________________________________________________________ NewPKI http://www.newpki.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
