Risk Management Toolbox
Release Notes
This document provides a high-level view of the changes introduced in Risk Management Toolbox product.
If you have any question about the release note or the product, our support will be pleased to help you.
Support: support.letssign@swisssign.com
| Type | Change |
|---|
| Added | Includes rmt-custom and rmt configuration profiles to support apps and/or environments segregation. Refer to installation guide for more details. |
| Added | Spring Boot upgraded to version 3.3.x |
| Fixed | Fixes validation of documents with timestamp signatures |
| Type | Change |
|---|
| Added | Java Upgraded to version 21 |
| Added | Rule etsiValidation: Supports system properties for setting proxy to OSCP/CRL online verification |
| Type | Change |
|---|
| Fixed | Fixes validation of documents with timestamp signatures |
| Type | Change |
|---|
| Added | Rule signatureContent: Adds validation of the attributes of the signer's certificate and issuer's certificate |
| Added | Rule trustedTimestamp: Validates that the embedded timestamp(s) were issued by a trusted Certificate Authority. |
| Added | Rule etsiValidation: Validates that the digital signatures follow the ETSI standard for Advanced Electronic Signature. |
| Type | Change |
|---|
| Fixed | Removes Log4J 1.2.x library that was packaged in WAR but unused |
| Type | Change |
|---|
| Fixed | Fixes CVE-2022-22965 |
| Type | Change |
|---|
| Added | Rule trustedRootCa: Add new configuration to limit validation on the root certificate only |
| Fixed | Fixes invalid certificate issuer printed in validation report (Root CA issuer was printed instead of the actual signer's certificate issuer that may be an intermediate CA) |
| Fixed | Rule trustedRootCa: Fixes regression introduced in 1.1.3 when certificate chain contains more than 2 certificates |
| Type | Change |
|---|
| Fixed | Fixes parsing issue of PDF digital signatures that include TSA certificates |
| Type | Change |
|---|
| Fixed | Fixes known CVE issues |
| Type | Change |
|---|
| Fixed | Updates Log4J 2 dependency to address 0-day RCE vulnerability (CVE-2021-44228) |
| Type | Change |
|---|
| Added | Rule signatureIntegrity: Add validation and comparison of existing signatures when the control document is provided to the request object (controlData attribute) |
| Added | Rule signatureIntegrity: Add new configuration to verify the expected number of new signatures applied to the control document |
| Added | Rule visibleSignatureContent: Add new configurations minWidth, maxWidth, minHeight and maxHeight to verify that the signature fields have the expected dimensions. |
| Added | Rule javascriptDetection: Add new rule to detect and compare javascript actions contained in document |
| Added | APIs: Request body: controlData attribute is added in the request object and only required when at least one rule require it. It replaces the configuration from visual comparison so the data can be used by multiple rules. controlData argument from visualComparison will be removed in a future release |
| Fixed | Rule visualComparison: Improves the configuration ignoreAdditionalSignatureFields by verifying that content below an additional field has not been altered |
| Type | Change |
|---|
| Added | Add possibility to skip report generation for success validation |
| Fixed | Rule signatureIntegrity: Fix PDF signature parsing issue when signature field is not correctly referenced in PDF Catalog |
| Fixed | Rule signatureIntegrity: Add validation of certificate chain consistency |
| Fixed | Rule signatureIntegrity: Add support for RSASSA-PSS signature algorithm |
| Type | Change |
|---|
| Added | Rule visualComparison: Add new configuration to set the rendering resolution |
| Added | Rule trustedRootCa: Add new configuration to handle X509 certificates |
| Fixed | Rule signatureContent: Fix parsing issue of the configuration when loaded from YAML configuration |
| Fixed | Rule visualComparison: Fix Java Heap Space issues when comparing large documents |
| Fixed | Rule pdfACompliance: Fix false negative result of PDF/A-2 validation |
Initial release.
| Type | Change |
|---|
| Added | Add validation API |
| Added | Add validation API for a pre-configured profile |
| Added | Generation of the PDF validation report |
| Added | New rule fileReadable: Validates that a document is a PDF and not corrupted |
| Added | New rule pdfACompliance: Validates that a document is compliant with a given PDF/A standard. |
| Added | New rule maxFileSize: Validates that a document does not exceed a maximal file size. |
| Added | New rule visualComparison: Compares visually a document with a control document to detect differences. |
| Added | New rule signatureIntegrity: Validates that signature(s) are valid and document is not altered. |
| Added | New rule trustedRootCa: Validates that the certificate(s) used for the signature(s) were issued by a trusted Certificate Authority. |
| Added | New rule signatureContent: Validates the signature content (certificate, data, etc.) |
| Added | New rule visibleSignatureContent: Validates that a signature field has a visual content |