/[pdpsoft]/nl.nikhef.pdp.fetchcrl/tags/fetch-crl-3.0.18/CHANGES
ViewVC logotype

Annotation of /nl.nikhef.pdp.fetchcrl/tags/fetch-crl-3.0.18/CHANGES

Parent Directory Parent Directory | Revision Log Revision Log


Revision 2277 - (hide annotations) (download)
Mon Apr 11 06:54:34 2011 UTC (10 years, 7 months ago) by davidg
Original Path: nl.nikhef.pdp.fetchcrl/trunk/CHANGES
File size: 15369 byte(s)
Moved fetch-crl to seprarate repo tree

1 davidg 1758 ==============================================================================
2     CHANGES to fetch-crl - the Certificate Revocation List retrieval tool
3     ==============================================================================
4     The fetch-crl utility will retrieve certificate revocation lists (CRLs) for
5     a set of installed trust anchors, based on crl_url files or IGTF-style info
6     files. It will install these for use with OpenSSL, NSS or third-party tools.
7    
8 davidg 2233 Changes in 3.0.6-1
9     ----------------------
10     * Response parsing disabled to suppress superfluous warning on unexpected
11     UTF-8 respons when retrieving a CRL (solves RedHat Bugzilla 688902)
12    
13 davidg 2188 Changes in 3.0.5-1
14     ----------------------
15     * CRLs for multiple similarly-named trust anchors might not all be downloaded.
16     This is fixed in this release.
17     * Spurious "restoreLogMode" internal errors are no longer raised
18    
19 davidg 2085 Changes in 3.0.4-1
20     ----------------------
21     * Add support for directory based drop-in configuration in /etc/fetch-crl.d/
22     * Only use cached CRL contents if the nextUpdate time of the cached CRL is
23     still in the future. This will ensure that a new download is attempted
24     each and everytime for CRLs that have already expired.
25    
26 davidg 1924 Changes in 3.0.3-1
27     ----------------------
28     * Clean up of man page format macro PU (reported by Mattias Ellert)
29    
30 davidg 1922 Changes in 3.0.2-1
31     ----------------------
32     * Clean up of man page format macro PU (reported by Mattias Ellert)
33    
34 davidg 1901 Changes in 3.0.1-1
35     ----------------------
36     * hunts through more places to find the latest successful CRL download to
37     set the latest local modification time for a CRL
38     (resolves a comparison error in case output and infodir are unset)
39    
40 davidg 1878 Changes in 3.0.0-0.RC4
41     ----------------------
42     * the config file name has changed to fetch-crl.conf, although a
43     fetch-crl.cnf file will also be used when present
44     * symlinked meta-data files can be ignored with the --nosymlinks option
45     (or nosymlinks in the configuration file). This allows fetch-crl to be
46     used effectively with new-format IGTF distribution before 1.37
47     * infinite loop for non-indexed CA file names fixed
48    
49 davidg 1758 Changes in fetch-crl 3.0
50     ------------------------
51     * fetch-crl 3.0 is a complete re-write, and shares no code with the 1.x and
52     2.x series utility of the same name, although the function and some of
53     the syntax is obviously the same
54    
55     * support for multiple output formats: OpenSSL 1 in dual-hash mode, specific
56     DER and PEM outputs, and NSS databases
57     * support for multiple CRLs for a single CA, allowing more than one CA with
58     the same subject name but different CLRs. Review your client software to see
59     if and how these CRLs are used.
60     * stateful retrieval helps reduce bandwidth usage by caching the CRLs locally
61     and respecting the Cache Control headers sent by the web server hosting the
62     CRL. This can reduce the number of downloads
63     * support for HEAD-only requests when state preservation is used (initially
64     only retrieve HTTP headers, and only if the CRL actually changed to a full
65     download)
66     * support for more CRL retrieval protocols (file:// and ftp://)
67     * ability to try site-local URLs first, before relying on the URLs shipped with
68     the trust anchor. This allows building an explicit local caching (web) server.
69     * ability to specify additional URLs to try in case the URLs shipped with the
70     trust anchor were not responsive. This allows for automatic fall-back to
71     (local or global) mirror services for CRL downloads
72     * warnings and errors can be suppressed on a per-trust anchor basis, to allow
73     silencing for particularly unstable trust anchors
74     * aging tolerance (the delay time before errors are generated in case downloads
75     consistently fail) can be configured on a per-trust anchor basis
76     * parallel downloading for multiple trust anchors
77     * minimized use of temporary files in the file system (now limited to the
78     invocation of OpenSSL only, and only for brief periods of time)
79     * dependencies on wget, lynx and other unix utilities have been removed
80     * explicit web proxy support (using LWP http proxies)
81     * completely re-written in perl, with some (hopefully minimal) dependencies:
82     LWP, Sys::Syslog, POSIX. And Data::Dumper (when debugging is enabled),
83     and IO::Select (if parallel downloads are enabled).
84    
85     Differences with respect to the previous versions
86    
87     * when downloading CRLs via https, the server certificate is not checked,
88     neither for the correct DNS name nor for being issued by a valid CA. Since
89     the CRL in itself is signed, this is not a security vulnerability. If
90     stricter checking is anyway desired, and the Crypt::SSLeay perl module has
91     been installed, set the HTTPS_CA_FILE environment variable before invoking
92     fetch-crl -- but keep in mind that the DNS name verification is limited
93     and will (incorrectly) reject DNS names if these are listed only in the
94     subjectAlternativeName of the server certificate
95     * Existing files with a name that matches a CRL target name are overwritten,
96     even if they did not originally contain CRL data. In v2 this was configurable
97     via the FORCE_OVERWRITE configuration setting. In version 3, files are
98     overwritten by default, and this can no longer be configured.
99     * fetch-crl3 will no longer check CA certificates for consistency or validity
100     by themselves, only retrieved CRLs are verified
101    
102     Downsides of the new version
103    
104     * it requires perl5 to be installed (tested with perl 5.8.0 and higher) with
105     libwww-perl, whereas version 2 only required a traditional Bourne shell
106     * requires a version of OpenSSL (0.9.5a or better) to be installed. Needs
107     OpenSSL 1.0.0 (at least beta5) for dual-hash support.
108     * when using parallel downloads, it can only run on pure-POSIX systems
109     * parallelism in combination with the NSS database output format is not tested
110     * Even when only the NSS database output format has been selected, OpenSSL is
111     still needed for verification and processing
112    
113    
114     ==============================================================================
115    
116     The change log below applies to the 1.x and 2.x series fetch-crl and is
117     included for historical purposes only. Fetch-crl3, with which this
118     changes file is being shipped, is a complete re-write of the utility.
119     Although a lot of backwards compatibility has been preserves, there have
120     been significant changes and the information below should NOT be used
121     to infer any behaviour of fetch-crl3.
122    
123     Fetch-crl 1.x and 2.x were released under the EU DataGrid License.
124    
125     Changes in version EGP 2.8.5
126     ----------------------------
127     (2010.06.03)
128    
129     * fetch-crl was occasionally leaving behind {hash}.r0.XXXXXX.r0 files
130     This has been fixed in this release (patch thanks to Jason Smith, BNL)
131     * man page was not compliant to Debian guidelines, this has been fixed
132     (patch thanks to Mattias Ellert, Uppsala University)
133    
134     Changes in version EGP 2.8.4
135     ----------------------------
136     (2010.04.04)
137    
138     * Fixes error when randomWait is not set [RH Bug 579488]
139    
140     Changes in version EGP 2.8.3
141     ----------------------------
142     (2010.03.28)
143    
144     * Preserve SELinux context for CRL files if SElinux status program exists
145     and selinux is enabled (RH bug 577403)
146     * Fix argument parsing on syslog facility specification (RH bug 577387)
147     * Increase granularity of the RandomWait and allow for 0 in -r option
148    
149     Changes in version EGP 2.8.2
150     ----------------------------
151     (2010.03.03)
152    
153     * Improved support for multiple CRL URLs by downloading until a success
154     is achieved, instead of downloading all of them
155     * Imported randomwait patch from Steve Traylen
156    
157     Changes in version EGP 2.8.1
158     ----------------------------
159     (2010.01.26)
160    
161     * The installed CRL file is re-checked for validity to catch file system
162     errors and local disk corruption. When possible, it will try to restore
163     a backup copy. Failures are not subject to aging tolerance.
164    
165     Changes in version EGP 2.8.0
166     ----------------------------
167     (2009.09.22)
168    
169     * The RPM packaging has been overhauled and is now sufficiently conformant
170     to EPEL and FedoraProject guidelines.
171     * New init scripts and a cron job entry have been added to allow management
172     of fetch-crl via the chkconfig mechanism
173    
174     These changes were contributed by Steve Traylen (CERN, Geneva, CH).
175    
176     Changes in version EGP 2.7.0
177     ----------------------------
178     (2009.01.25)
179    
180     * Warnings and errors are now counted. If there are errors in the download
181     or verification process for one or more CRLs, the exit status will be 1;
182     if there are errors in the local setup or in the script invocation, the
183     exit status will be 2.
184     * The installed CRLs no longer have the textual representation of the CRL,
185     but only the PEM data blob, thus reducing IO and memory requirements.
186     * the CRL aging threshold is now set by default to 24 hours. The previous
187     default was 0. The CRL aging threshold is set in the config file using
188     CRL_AGING_THRESHOLD=<xx>, or with the "-a" command-line argument.
189     * Default network timeouts reduced to 10 seconds (was 30) and retries to 2
190     * Added caching and conditional downloading. When CACHEDIR is set, the
191     original downloads are preserved and wget timestamping mode enabled.
192     When the content did not change, only the timestamp on the installed
193     CRL is updated. If SLOPPYCRLHASHES is set, the has is calculated based
194     on the name of the crl_url file, otherwise it is taken from the CRL itself.
195     - The CACHEDIR must be exclusively writable by the user running fetch-crl
196     - Setting CACHEDIR significantly reduced the bandwidth used by fetch-crl
197     * Added RESETPATHMODE setting in sysconfig. It defines whether or not to
198     set re-set $PATH to "/bin:/usr/bin" before start. The search for OpenSSL
199     may be done based on the old path.
200     yes=always replace; searchopenssl=search for openssl first and then reset;
201     no=keep original path, whatever that me be (may be empty if called from cron)
202     Default="yes". This replaces the hard-coded path in the tool!
203     * Hidden "FORCE_OVERWRITE" option now has a regular name. This is backwards-
204     compatible. Set FORCE_OVERWRITE=yes if you want files overwritten that
205     have a CRL-like name and ought to have CRL content, but currently do not.
206     * Addresses gLite Savannah bugs 28418 and 29559. Bug 27023 is partially
207     addressed. Bug 20062 can be remedied with WGET_OPTS arguments.
208     Addresses OSG ticket 4673.
209    
210     Changes in version EGP 2.6.6
211     ----------------------------
212     (2007.09.16)
213     (version 2.5.5 is invalid and was not publicly released)
214    
215     * Added obscure configuration parameter to allow overwriting of
216     arbitrary data files with a downloaded CRL (on request of
217     CERN, see https://savannah.cern.ch/bugs/index.php?29559)
218    
219     Changes in version EGP 2.6.4
220     ----------------------------
221     (2007.08.15)
222    
223     * Expired CA issuer certificate now gives a warning instead of an error
224     with the full verification result message
225     * additional logfile output target can be selected via the configuration file
226     * CRL aging threshold documented in manual page. Errors will now also be
227     generated in the CRL download failed consistently and the current CRL
228     has already expired
229    
230     Changes in version EGP 2.6.3
231     ----------------------------
232     (2006.11.13)
233    
234     * cron job example: fetch-crl invocation syntax error corrected
235    
236     Changes in version EGP 2.6.2
237     ----------------------------
238     (2006.10.27)
239    
240     * fixed bug: older wget versions do not recognise --no-check-certificate
241    
242     Changes in version EGP 2.6.1
243     ----------------------------
244     (2006.10.25)
245    
246     * fixed local timezone vs UTC error in LastUpdate CRL validation comparison
247     * fixed time comparison is the one-hour LastUpdate/download tolerance
248     (both fixes thanks to Alain Roy)
249     * added support for directory names containing whitespace
250     * added support for syslog reporting (via -f option or SYSLOGFACILITY directive)
251     * SERVERCERTCHECK=no is now the default. It can be reset via the configuration
252     file, or using the "--check-server-certificate" commandline option
253     * the main configuration file location (formerly fixed to be
254     /etc/sysconfig/fetch-crl) can now be set via the variable $FETCH_CRL_SYSCONFIG
255     * logfile format timestamp and tag have been normalised
256    
257     Changes in version EGP 2.6
258     --------------------------
259     (2006.05.20)
260    
261     * if the current local CRL has a lastUpdate time in the future, and the
262     newly downloaded CRL is older that the current one, allow the installation
263     of the newly downloaded CRL and issue a warning.
264     * added non-suppressable warning in case the newly downloaded CRL has a
265     lastUpdate time in the future, but install that CRL anyway (as the local
266     clock might have been wrong).
267    
268     Changes in version EGP 2.5
269     --------------------------
270     (2006.01.16)
271    
272     * added additional configuration arguments and configuration variables
273     to skip the server certificate check in wget
274     (to support https:// URLs where the server is authenticated with
275     a certificate that is not part of it's own trusted domain, such as
276     the KISTI URL)
277    
278     Changes in version EGP 2.4
279     --------------------------
280     (2005.11.15)
281    
282     * for those platforms that support the stat(1) command, and in case the
283     .crl_url file is named after the hash of the crl subject name to download,
284     error eporting for individual download errors can be suppressed for
285     a configurable amount of time as set via the "-a" option (unit: hours).
286    
287     Changes in version EGP 2.3
288     --------------------------
289     (2005.11.05)
290    
291     * do not replace recent CRLs with ones that have an older lastUpdate
292     timestamp (prevents ARP/DNS DoS attacks)
293    
294     Changes in version EGP 2.2
295     --------------------------
296     (2005.10.27)
297    
298     * secure http download by wget recognise the CAs in the trusted directory.
299     solves the issue described in the LCG bug tracking system
300     https://savannah.cern.ch/bugs/index.php?func=detailitem&item_id=12182
301    
302     Changes in version EGP 2.1
303     --------------------------
304     (2005.08.12)
305     * specifically look for the most recent version of OpenSSL. The
306     one in GLOBUS_LOCATION (which used to take precedence in the
307     previous releases) is outdated in many cases and caused
308     troubles on the LCG production systems in validating v2 CRLs
309     * added manual page fetch-crl(8)
310    
311     Changes in version EGP 2.0
312     --------------------------
313     (2005.02.28)
314     * name of the installed script changed to "fetch-crl"
315     * the cronjob script is no longer installed by default, but supplied
316     as an example in the %doc directory
317     * RPM is now relocatable (default install in /usr)
318     * READMA and CHANGES file now inclued in %doc tree
319     * make install now installs
320     * version increased to 2.0
321    
322     Changes in version EGP 1.9
323     --------------------------
324     (2005.02.24)
325     * the content of the final target CRL file is now checked for
326     containing a valid CRL if it already exists. If it does not
327     contain a CRL, an error is displayed and the file left untouched
328     So making the final ".r0" file in ${outdir} a link to something else
329     will not work, preventing an escalation in the final stage.
330    
331     Changes in version EGP 1.8
332     --------------------------
333     (changes from Fabio's version 1.7, 2005.02.24)
334    
335     * All temporary files (the initial CRL download using wget
336     and the PEM-converted version of that file) are now created using
337     mktemp
338     * the RetrieveFileByURL function will not overwrite files that
339     have any data in them
340     * Note that the script can be run by a non-priviledged user, but
341     that the output directory must be made writable by that user
342     in an out-of-band way.
343    
344     EDG version 1.7
345     ---------------
346     Imported with consent of Fabio Hernandez and Steve Traylen from
347     the original EDG repository.
348     The EU DataGrid License applies, see http://www.eu-datagrid.org/

grid.support@nikhef.nl
ViewVC Help
Powered by ViewVC 1.1.28