v1.4.0
NVlabs/Sanav1.4.0Aug 16, 2019by FiloSottile
AI Summary
This release addresses macOS Catalina compatibility by fixing certificate lifespans and introduces support for URL and email SANs. It also adds support for new Linux distributions and makes Linux binaries static. A breaking change is noted regarding existing certificates on macOS Catalina.
Key Highlights
- macOS Catalina compatibility fix
- URL and email SAN support
- Support for SLES, OpenSUSE, Snapcraft, and CentOS 7
- Static Linux binaries
Breaking Changes
- Certificates generated by previous versions after July 1st, 2019 will not work on macOS 10.15 Catalina
New Features
- URL SANs
- Email SANs
- Client certificate EKU updates
- Full username in subject
- SLES/OpenSUSE/Snapcraft/CentOS 7 support
- Static Linux binaries
Full Release Notes
macOS 10.15 Catalina introduced [certificate lifespan limits](https://support.apple.com/en-us/HT210176) which block mkcert certificates. As a temporary measure, mkcert certificates now have a fixed notBefore date of June 1st, 2019. Once the ACME server is implemented, certificate lifespan will be shortened to 3 months. (#174) **Certificates generated by previous versions of mkcert after July 1st, 2019 will not work on macOS 10.15 Catalina**, and will have to be regenerated. The root CA is unaffected and there is no need to rerun `mkcert -install`. URL (#166) and email (for S/MIME, #152) SANs are now supported. Client certificates are now created with a `-client` filename suffix, and they claim the serverAuth EKU as well as the clientAuth one. The certificate subject now includes the full user name, like `filippo@Bistromath.local (Filippo Valsorda)`. SLES, OpenSUSE (#162), Snapcraft (#116), and CentOS 7 (#120) are now supported. Linux release binaries are now fully static, and will work regardless of the system libc. (#169)