Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[Unreleased]
[0.1.0] - 2026-09-28
Added
- Sort
CryptographicKeyContextand implementPartialOrdandOrd - [breaking] Introduce a crate-level error type for signstar-common
- (deps) [breaking] Update crate nethsm-sdk-rs to 4.0.0
- (deps) Update rustcrypto crates
- (deps) Upgrade crate
yubihsm2to 0.45.0 - Use better defaults for
OpenPgpKeyUsageFlags - [breaking] Extend
CryptographicKeyContext::OpenPgpwithnotations - Derive
CloneforOpenPgpKeyUsageFlags - (deps) Upgrade crate
yubihsm2to 0.44.0 - Return
Result<Option<usize>, Error>for certificate size estimation - Add size validation of
YubiHsm2UserMappinginstances in aYubiHsm2Config - Add
EmptyEd25519Signerfor easy certificate size estimation - Append Signer’s UID to issued signatures
- Implement
TryFrom<yubihsm::Algorithm>forKeyType - Add support for P-256, P-384 and (partially) P-512 Brainpool
- Add support for ECC K-256 (Koblitz)
- Add back NIST P-224 support
- Add
Passphrase::check_against_policy - Add
Passphrase::new_with_policy - Add
PassphrasePolicyto describePassphrasepolicies - Add
lenandis_emptymethods forPassphrase - Implement creating
Passphrasefrom a file path - [breaking] Drop MD5 from supported algorithms and dependencies
- Publicly expose default values for Shamir’s Secret Sharing (SSS)
- Derive
AsRefStrforNonAdministrativeSecretHandling - Add
AdministrativeSecretHandlingenum - Add reading and writing of non-administrative secrets
- Derive
OrdandPartialOrdforOpenPgpUserIdList - Derive
OrdandPartialOrdforOpenPgpUserId - Implement
OrdandPartialOrdforOpenPgpUserIdType - Implement
DisplayforOpenPgpUserIdType - Derive
OrdandPartialOrdforOpenPgpVersion - Derive
OrdandPartialOrdforCryptographicKeyContext - Skip serializing
SigningKeySetup::key_lengthif it isNone - Derive
OrdandPartialOrdforSigningKeySetup - Move OpenPGP related logic out of
nethsmintosignstar-crypto - Add
Passphrase::generateto generate new passphrases - Add the
UserWithPassphrasetrait - Add
SigningKeySetupto describe environments for signing keys - Make
PrivateKeyDatapublicly accessible - Add
Passphrasetype to handle passphrases - Add types for cryptographic key ingestion and import
- Add
keymodule providing various types for cryptographic keys - Add an
openpgpmodule for simple OpenPGP related types - Initialize bare
signstar-cryptocrate
Fixed
- [breaking] Diversify the logger setup for journald and terminal
- (deps) More strictly lock the version ranges for custom dependencies
- [breaking] Correctly generate certificates with multiple User IDs
- (deps) Update Rust crate pgp to 0.20
- remove unused import
- Replace returning errors to direct
panics to avoid clippy lints
Other
- Rely on coverage collection functionality in change-user-run
- Enforce
_containerized-integration-testfeature for test module - Enforce binary ID for
_containerized-integration-testtests - Improve
CryptographicKeyContext::openpgp_cert_sizedocumentation - [breaking] Move
Error::UnsupportedNetHsmKeyMechanismtokeymodule - [breaking] Expose all signstar_crypto errors over top-level Error type
- (README) Improve information about available features
- (deps) Update Rust crate pgp to 0.19
- Use serde
Deserialize/Serializetop-level inopenpgpmodule - Feature-guard unit tests that require the
nethsmfeature - Expose
SignedSecretKeythroughnethsm