Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
144 changes: 3 additions & 141 deletions docs/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -67,12 +67,14 @@ <h1>XML Security Library</h1>
see the Copyright file in the distribution for details.<br><br></p>
<p><b>News</b></p>
<ul>
<li>TODO<br>
<li>October 15, 2025<br>
The <a href="download.html">XML Security Library 1.3.8</a> release includes the following changes:
<ul>
<li>(xmlsec-openssl) Deprecated support for OpenSSL 1.1.1 (<a href="https://openssl-corporation.org/post/2023-09-11-eol-111/">reached its End of Life in September, 2023</a>)</li>
<li>(xmlsec-openssl) Added AWS-LC support</li>
<li>(xmlsec-openssl, xmlsec-gnutls, xmlsec-mscng) Added support for longer than expected DSA and ECDSA sigantures to support broken Java implementations.</li>
<li>(xmlsec command line tool) Added option "--add-id-attr" to add ID attributes by name to all nodes in the document.</li>
<li>(xmlsec-core) Added RSA MGF1 and digest template API</li>
<li>(xmlsec-core) Added example of signing / verifying signature by ID attribute.</li>
<li>Several other small fixes (see <a href="https://github.com/lsh123/xmlsec/commits/master">more details</a>).</li>
</ul>
Expand Down Expand Up @@ -239,146 +241,6 @@ <h1>XML Security Library</h1>
</li>
<br>

<li>
April 12, 2023<br>
The <a href="download.html">XML Security Library 1.3.0</a> release includes the following changes:
<br>
<br>
<ul>
<li>
<b>core xmlsec and all xmlsec-crypto libraries:</b>
<ul>
<li>(<b>ABI breaking change</b>) Added support for the <a href="https://www.w3.org/TR/xmldsig-core1/#sec-KeyInfoReference">KeyInfoReference Element</a>.</li>
<li>(<b>ABI breaking change</b>) Switched xmlSecSize to use size_t by default. Use "--enable-size-t=no" configure option ("size_t=no" on Windows) to
restore the old behaviour (note that support for xmlSecSize being different from size_t will be removed in the future).</li>
<li>(<b>API breaking change</b>) Changed the key search to strict mode: only keys referenced by KeyInfo are used. To restore the old "lax" mode,
set XMLSEC_KEYINFO_FLAGS_LAX_KEY_SEARCH flag on xmlSecKeyInfoCtx or use '--lax-key-search' option for XMLSec command line utility.
</li>
<li>(<b>API breaking change</b>) The KeyName element content is now trimmed before key search is performed.</li>
<li>(<b>API breaking change</b>) Disabled FTP support by default. Use "--enable-ftp" configure option to restore it. Also added
"--enable-http" and "--enable-files" configure options to control support for loading files over HTTP or locally.</li>
<li>(<b>API/ABI breaking change</b>) Disabled MD5 digest method by default. Use "--enable-md5" configure options ("legacy-crypto" option on Windows) to re-enable MD5.</li>
<li>(<b>ABI breaking change</b>) Added "failureReason" file to xmlSecDSigCtx and xmlEncCtx to provide more granular operation failure reason.</li>
<li>(<b>ABI breaking change</b>) Removed deprecated functions.</li>
<li>Added support for loading keys through <a href="https://www.openssl.org/docs/man3.0/man7/ossl_store.html">ossl-store</a> interface (e.g.
for using keys from an HSM). Also see '--privkey-openssl-store' and '--pubkey-openssl-store ' command line options for XMLSec utility.</li>
<li>Added ability to control transforms binary chunk size to improve performance (see '--transform-binary-chunk-size' command line option for XMLSec utility).</li>
<li>Fixed all potentially unsafe integer conversions and all the other warnings.</li>
<li>Added <a href="https://www.w3.org/TR/2012/NOTE-xmldsig-core1-interop-20121113/">XML Signature 1.1 interop (2012)</a>
and <a href="https://www.w3.org/TR/2012/NOTE-xmlenc-core1-interop-20121113/">XML Encryption 1.1 interop (2012)</a> tests.
</li>
</ul>
</li>
<li>
<b>xmlsec-openssl library:</b>
<ul>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#name-sha-3-algorithms">SHA3 digests</a>.</li>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#name-ecdsa-sha-ecdsa-ripemd160-e">ECDSA-SHA3 signatures</a>.</li>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#section-2.3.10">RSA PSS signatures (withtout parameters)</a>.</li>
<li>
Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-ConcatKDF">ConcatKDF key</a> and
<a href="https://www.w3.org/TR/xmlenc-core1/#sec-PBKDF2">PBKDF2</a> derivation algorithms.
</li>
<li>(<b>ABI breaking change</b>) Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-ECDH-ES">ECDH-ES Key Agreement algorithm</a>.</li>
<li>(<b>ABI breaking change</b>) Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-DHKeyAgreementExplicitKDF">DH-ES Key Agreement algorithm</a> with explicit KDF.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP">MGF1 algorithm to RSA OAEP key transport</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-X509Data">X509Digest</a> element and ability to lookup keys using other X509Data elements.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-DEREncodedKeyValue">DEREncodedKeyValue</a> element.</li>
<li>Automatically set key name from PKCS12 key name.</li>
<li>Removed support for OpenSSL 1.0.0 and LibreSSL before 2.7.0.</li>
</ul>
</li>
<li>
<b>xmlsec-nss library:</b>
<ul>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#section-2.3.10">RSA PSS signatures (withtout parameters)</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP">RSA OAEP key transport including MGF1 algorithms</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-AES-GCM">AES GCM ciphers</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-PBKDF2">PBKDF2</a> derivation algorithm.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-X509Data">X509Digest</a> element and ability to lookup keys using other X509Data elements.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-DEREncodedKeyValue">DEREncodedKeyValue</a> element.</li>
<li>Automatically set key name from PKCS12 key name.</li>
</ul>
</li>
<li>
<b>xmlsec-gnutls library:</b>
<ul>
<li>(<b>API/ABI breaking change</b>) Removed dependency on xmlsec-gcrypt and libgcrypt libraries (including API functions) to enable support for different GnuTLS backends.</li>
<li>Bumped minimal GnuTLS version to 3.6.13.</li>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#name-sha-3-algorithms">SHA3 digests</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-ECDSA">ECDSA signatures</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP">DSA-SHA256 signatures</a>.</li>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#section-2.3.10">RSA PSS signatures (withtout parameters)</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-1_5">RSA PKCS 1.5 key transport</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-AES-GCM">AES GCM ciphers</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-PBKDF2">PBKDF2</a> derivation algorithm.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-X509Data">X509Digest</a> element and ability to lookup keys using other X509Data elements.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-DEREncodedKeyValue">DEREncodedKeyValue</a> element.</li>
<li>Automatically set key name from PKCS12 key name.</li>
</ul>
</li>
<li>
<b>xmlsec-mscng library:</b>
<ul>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#section-2.3.10">RSA PSS signatures (withtout parameters)</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP">MGF1 algorithm to RSA OAEP key transport</a>.</li>
<li>(<b>ABI breaking change</b>) Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-ECDH-ES">ECDH-ES Key Agreement algorithm</a>.</li>
<li>
Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-ConcatKDF">ConcatKDF key</a> and
<a href="https://www.w3.org/TR/xmlenc-core1/#sec-PBKDF2">PBKDF2</a> derivation algorithms.
</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-X509Data">X509Digest</a> element for keys and certificates lookup from the system stores (only SHA1 is supported).</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-DEREncodedKeyValue">DEREncodedKeyValue</a> element.</li>
<li>Automatically set key name from PKCS12 key name.</li>
</ul>
</li>
<li>
<b>xmlsec-mscrypto library:</b>
<ul>
<li>In maintenance mode starting from this release.</li>
<li>Disabled by default support for NT4. Use "nt4=yes" configure option on Windows to re-enable it.</li>
</ul>
</li>
<li>
<b>xmlsec-gcrypt library:</b>
<ul>
<li>In maintenance mode starting from this release.</li>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#name-sha-3-algorithms">SHA3 digests</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmldsig-core1/#sec-ECDSA">ECDSA signatures</a>.</li>
<li>Added support for <a href="https://www.ietf.org/rfc/rfc9231.html#section-2.3.10">RSA PSS signatures (withtout parameters)</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-1_5">RSA PKCS 1.5 key transport</a>.</li>
<li>Added support for <a href="https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP">RSA OAEP key transport including MGF1 algorithms</a>.</li>
</ul>
</li>
<li>
<b>xmlsec command line utility:</b>
<ul>
<li>(<b>API breaking change</b>) The XMLSec command line utility is using 'strict' key search mode by default. To restore the old 'lax'
key search mode, use the new '--lax-key-search' option.</li>
<li>(<b>API breaking change</b>) The XMLSec command line utility is no longer prints detailed errors by default. To restore the detailed
errors, use the new '--verbose' option.</li>
<li>Added '--transform-binary-chunk-size' option to control transforms binary chunk size (increasing the chunk size should improve performance
at the expense of memory usage.
</li>
<li>Added support for loading keys through <a href="https://www.openssl.org/docs/man3.0/man7/ossl_store.html">ossl-store</a> interface (e.g.
for using keys from an HSM). Also see '--privkey-openssl-store' and '--pubkey-openssl-store ' command line options for XMLSec utility.</li>
<li>Added '--enabled-key-info-reference-uris' option to control processing of the
the <a href="https://www.w3.org/TR/xmldsig-core1/#sec-KeyInfoReference">KeyInfoReference Element</a>.
</li>
<li>Added '--pbkdf2-key' option for loading PBKDF2 keys.</li>
<li>Added '--concatkdf-key' option for loading ConcatKDF keys.</li>
<li>Added '--hmac-min-out-len' option to control the min accepted HMAC Output length.</li>
<li>Added '--pubkey-openssl-engine' option to load public keys from OpenSSL engine.</li>
<li>Added '--crl-pem' and '--crl-der' options to load CRLs.</li>
<li>Added '--verify-keys' option to verify key's certificate before loading into Keys Manager (only supported for OpenSSL currently).</li>
<li>Enabled templatized output filenames to facilitate batch operations on multiple input files.</li>
</ul>
</li>
</ul>
<p>Detailed information about supported algorithms can be found here: <a href="xmldsig.html">XMLDsig</a> and <a href="xmlenc.html">XMLEnc</a>
interoperability reports.</p>
</li>
<br>
</ul>
<br><br><a href="news.html">News page</a>
</td></tr></table></td>
Expand Down
9 changes: 7 additions & 2 deletions docs/news.html
Original file line number Diff line number Diff line change
Expand Up @@ -48,10 +48,15 @@
<h1>XML Security Library News</h1>
</div>
<ul>
<li>TODO<br>
<li>October 15, 2025<br>
The <a href="download.html">XML Security Library 1.3.8</a> release includes the following changes:
<ul>
<li>TODO: copy from index.html</li>
<li>(xmlsec-openssl) Deprecated support for OpenSSL 1.1.1 (<a href="https://openssl-corporation.org/post/2023-09-11-eol-111/">reached its End of Life in September, 2023</a>)</li>
<li>(xmlsec-openssl) Added AWS-LC support</li>
<li>(xmlsec-openssl, xmlsec-gnutls, xmlsec-mscng) Added support for longer than expected DSA and ECDSA sigantures to support broken Java implementations.</li>
<li>(xmlsec command line tool) Added option "--add-id-attr" to add ID attributes by name to all nodes in the document.</li>
<li>(xmlsec-core) Added RSA MGF1 and digest template API</li>
<li>(xmlsec-core) Added example of signing / verifying signature by ID attribute.</li>
<li>Several other small fixes (see <a href="https://github.com/lsh123/xmlsec/commits/master">more details</a>).</li>
</ul>
</li>
Expand Down
2 changes: 1 addition & 1 deletion man/xmlsec1-config.1
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH XMLSEC1-CONFIG "1" "August 2025" "xmlsec1-config 1.3.8" "User Commands"
.TH XMLSEC1-CONFIG "1" "October 2025" "xmlsec1-config 1.3.8" "User Commands"
.SH NAME
xmlsec1-config \- detail installed version of xmlsec library
.SH SYNOPSIS
Expand Down
12 changes: 8 additions & 4 deletions man/xmlsec1.1
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH XMLSEC1 "1" "August 2025" "xmlsec1 1.3.8 (openssl)" "User Commands"
.TH XMLSEC1 "1" "October 2025" "xmlsec1 1.3.8 (openssl)" "User Commands"
.SH NAME
xmlsec1 \- sign, verify, encrypt and decrypt XML documents
.SH SYNOPSIS
Expand Down Expand Up @@ -128,9 +128,13 @@ selected by the specified XPath expression
adds attributes <attr\-name> (default value "id") from all nodes
with<node\-name> and namespace <node\-namespace\-uri> to the list of
known ID attributes; this is a hack and if you can use DTD or schema
to declare ID attributes instead (see "\-\-dtd\-file" option),
I don't know what else might be broken in your application when
you use this hack
to declare ID attributes instead (see "\-\-dtd\-file" option)
.HP
\fB\-\-add\-id\-attr\fR <id\-attribute\-name>
.IP
adds attribute <id\-attribute\-name> to all nodes in the document;
this is a hack and if you can use DTD or schema to declare ID attributes
instead (see "\-\-dtd\-file" option)
.HP
\fB\-\-enabled\-key\-data\fR <list>
.IP
Expand Down
3 changes: 1 addition & 2 deletions scripts/build_docs.sh
Original file line number Diff line number Diff line change
Expand Up @@ -15,5 +15,4 @@ make

echo "============== Cleanup"
cd "$cur_pwd"


make distclean
4 changes: 2 additions & 2 deletions scripts/build_windows.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@
#
# $ c:\cygwin64\bin\bash build_windows.sh
#
libxml2_version="2.14.3"
libxml2_version="2.15.0"
libxslt_version="1.1.43"
openssl_version="3.5.0"
openssl_version="3.6.0"
xmlsec_version="1.3.8-rc1"

pwd=`pwd`
Expand Down
Loading