LogoSignature Service
Risk Management Toolbox

Release Notes

This document provides a high-level view of the changes introduced in Risk Management Toolbox product.

If you have any question about the release note or the product, our support will be pleased to help you.

Support: support.letssign@swisssign.com

1.4.0 (2024-12-29)

TypeChange
AddedIncludes rmt-custom and rmt configuration profiles to support apps and/or environments segregation. Refer to installation guide for more details.
AddedSpring Boot upgraded to version 3.3.x
FixedFixes validation of documents with timestamp signatures

1.3.0 (2024-08-22)

TypeChange
AddedJava Upgraded to version 21
AddedRule etsiValidation: Supports system properties for setting proxy to OSCP/CRL online verification

1.2.1 (2024-10-03)

TypeChange
FixedFixes validation of documents with timestamp signatures

1.2.0 (2022-10-01)

TypeChange
AddedRule signatureContent: Adds validation of the attributes of the signer's certificate and issuer's certificate
AddedRule trustedTimestamp: Validates that the embedded timestamp(s) were issued by a trusted Certificate Authority.
AddedRule etsiValidation: Validates that the digital signatures follow the ETSI standard for Advanced Electronic Signature.

1.1.6 (2022-06-24)

TypeChange
FixedRemoves Log4J 1.2.x library that was packaged in WAR but unused

1.1.5 (2022-04-01)

TypeChange
FixedFixes CVE-2022-22965

1.1.4 (2022-03-30)

TypeChange
AddedRule trustedRootCa: Add new configuration to limit validation on the root certificate only
FixedFixes invalid certificate issuer printed in validation report (Root CA issuer was printed instead of the actual signer's certificate issuer that may be an intermediate CA)
FixedRule trustedRootCa: Fixes regression introduced in 1.1.3 when certificate chain contains more than 2 certificates

1.1.3 (2022-03-28)

TypeChange
FixedFixes parsing issue of PDF digital signatures that include TSA certificates

1.1.2 (2021-12-16)

TypeChange
FixedFixes known CVE issues

1.1.1 (2021-12-14)

TypeChange
FixedUpdates Log4J 2 dependency to address 0-day RCE vulnerability (CVE-2021-44228)

1.1.0 (2021-06-30)

TypeChange
AddedRule signatureIntegrity: Add validation and comparison of existing signatures when the control document is provided to the request object (controlData attribute)
AddedRule signatureIntegrity: Add new configuration to verify the expected number of new signatures applied to the control document
AddedRule visibleSignatureContent: Add new configurations minWidth, maxWidth, minHeight and maxHeight to verify that the signature fields have the expected dimensions.
AddedRule javascriptDetection: Add new rule to detect and compare javascript actions contained in document
AddedAPIs: Request body: controlData attribute is added in the request object and only required when at least one rule require it. It replaces the configuration from visual comparison so the data can be used by multiple rules. controlData argument from visualComparison will be removed in a future release
FixedRule visualComparison: Improves the configuration ignoreAdditionalSignatureFields by verifying that content below an additional field has not been altered

1.0.2 (2021-04-12)

TypeChange
AddedAdd possibility to skip report generation for success validation
FixedRule signatureIntegrity: Fix PDF signature parsing issue when signature field is not correctly referenced in PDF Catalog
FixedRule signatureIntegrity: Add validation of certificate chain consistency
FixedRule signatureIntegrity: Add support for RSASSA-PSS signature algorithm

1.0.1 (2020-09-30)

TypeChange
AddedRule visualComparison: Add new configuration to set the rendering resolution
AddedRule trustedRootCa: Add new configuration to handle X509 certificates
FixedRule signatureContent: Fix parsing issue of the configuration when loaded from YAML configuration
FixedRule visualComparison: Fix Java Heap Space issues when comparing large documents
FixedRule pdfACompliance: Fix false negative result of PDF/A-2 validation

1.0.0 (2020-09-11)

Initial release.

TypeChange
AddedAdd validation API
AddedAdd validation API for a pre-configured profile
AddedGeneration of the PDF validation report
AddedNew rule fileReadable: Validates that a document is a PDF and not corrupted
AddedNew rule pdfACompliance: Validates that a document is compliant with a given PDF/A standard.
AddedNew rule maxFileSize: Validates that a document does not exceed a maximal file size.
AddedNew rule visualComparison: Compares visually a document with a control document to detect differences.
AddedNew rule signatureIntegrity: Validates that signature(s) are valid and document is not altered.
AddedNew rule trustedRootCa: Validates that the certificate(s) used for the signature(s) were issued by a trusted Certificate Authority.
AddedNew rule signatureContent: Validates the signature content (certificate, data, etc.)
AddedNew rule visibleSignatureContent: Validates that a signature field has a visual content

On this page