Skip to content

Releases: rustls/rustls-platform-verifier

0.7.0

Choose a tag to compare

@djc djc released this 12 Apr 09:30
v/0.7.0

The reason this release is semver-incompatible is the upgrade from jni 0.21 to 0.22, which should only affect Android targets (and substantially reuse dependency duplication). Additionally there are several fixes for behavior on Windows.

What's Changed

0.6.2

Choose a tag to compare

@djc djc released this 22 Oct 11:45
v/0.6.2

What's Changed

0.6.1

Choose a tag to compare

@ctz ctz released this 03 Aug 18:01

This version should fix the docs.rs build -- see #181.

What's Changed

Full Changelog: v/0.6.0...v/0.6.1

0.6.0

Choose a tag to compare

@djc djc released this 01 Jun 20:20
v/0.6.0
  • Avoid implicit reliance on the default crypto provider
  • Eagerly create the verifier on miscellaneous Unix platforms (including Linux) to avoid swallowing errors

What's Changed

  • Update real world test certificates by @djc in #177
  • Eagerly build root store on miscellaneous Unix platforms by @djc in #171
  • Upgrade to webpki-root-certs 1 by @djc in #176

0.5.3

Choose a tag to compare

@djc djc released this 05 May 20:42
v/0.5.3
  • Adapt to changes in rustls error API.

What's Changed

  • Fix typo in Verifier::{with_provider, get_provider} docs by @paolobarbolini in #173
  • Refine CI workflow triggers by @djc in #174
  • Adapt to changing rustls error API by @djc in #168

0.5.2

Choose a tag to compare

@complexspaces complexspaces released this 25 Apr 17:23

The headline of this release is server compatibility improvements.

It removes an edge case where a failure to load any certificates on Linux/BSD platforms would result in silently turning the lack of certificate roots into "no signature algorithms". During the initialization of a TLS session with a server this caused rustls to send an empty supported signature list in the ClientHello.

What's Changed

Full Changelog: v/0.5.1...v/0.5.2

0.5.1

Choose a tag to compare

@djc djc released this 17 Mar 15:01
v/0.5.1

Change the way we interact with the rustls API to avoid semver hazards: unfortunately changes in rustls 0.23.24 broke older rustls-platform-verifier releases due to downcasting of a no-longer compatible error wrapper. rustls 0.23.25 now exposes the required variant directly, which should avoid similar issues in the future. (For more details, see #163.)

What's Changed

0.5.0

Choose a tag to compare

@djc djc released this 18 Dec 09:10
v/0.5.0

The upgrade to jni 0.21 contained some Android-only breaking changes -- API changes should not affect other platforms.

What's Changed

  • Update jni to 0.21 by @Cyannide in #151
  • Bump MSRV & update dependencies by @djc in #152
  • ci: add some missing persist-credentials by @cpu in #154

0.4.0

Choose a tag to compare

@complexspaces complexspaces released this 02 Nov 01:51
  • Improved support for "extra" roots - the ability to specify additional root certificates beyond the platform's own roots has been extended to all supported platforms with the exception of Android (TBD). This can be used for additive configuration, for example to support all system roots and additionally some internal, or company specific, roots. The existing Linux/UNIX verifier's new_with_extra_roots() fn now accepts impl IntoIterator<Item = pki_types::TrustAnchor<'static>> in place of Vec<pki_types::CertificateDer<'static>> to better harmonize with the other platforms.
  • Replace winapi with windows-sys - the latter is a 1st party Microsoft crate with better on-going support.
  • Improved documentation - the README has been updated to better describe the differences between this crate and other available options.
  • Added new BuilderVerifierExt and ConfigVerifierExt traits which provide with_platform_verifier() methods for easier rustls client configuration. These intend to replace tls_config and tls_config_with_provider, which are now deprecated.

What's Changed

New Contributors

Full Changelog: v/0.3.4...v/0.4.0

v/0.3.4

Choose a tag to compare

@ctz ctz released this 23 Aug 16:00
  • Fix an error in the handling of allowed EKUs on Windows; see #126

What's Changed

  • small chores by @cpu in #116
  • tests: regenerate verification_mock data by @cpu in #121
  • Update deny config & bump base64 to 0.22 by @djc in #119
  • build(deps): bump EmbarkStudios/cargo-deny-action from 1 to 2 by @dependabot in #118
  • Fix UB in Windows verifier EKU handling by @complexspaces in #127
  • Prepare 0.3.4 by @ctz in #129

Full Changelog: v/0.3.3...v/0.3.4