v0.16.11
anomalyco/opentuiv0.16.11Jun 25, 2026by github-actions[bot]
AI Summary
Introduces significant security and storage enhancements, including support for advanced encryption standards, flexible S3 certificate handling, and Redis Sentinel support for cluster coordination.
Key Highlights
- Added Encryption-at-rest support for AES-256-GCM and ChaCha20-Poly1305
- Added Redis Sentinel support as an in-memory store and cluster coordinator
- Added S3 support for allowInvalidCerts option to connect with invalid TLS certificates
- Fixed JMAP Principal/query returning broad results when name or email filters cannot be resolved
- Fixed DANE to verify DNSSEC is supported before attempting TLSA validation
New Features
- Encryption-at-rest support for AES-256-GCM and ChaCha20-Poly1305
- Redis Sentinel support
- S3 allowInvalidCerts option
Full Release Notes
## [0.16.11] - 2026-06-25 If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions. ## Added - Encryption-at-rest: Support for `AES-256-GCM` and `ChaCha20-Poly1305` for S/MIME (#161). - S3: Support for `allowInvalidCerts` option to allow connecting to S3 endpoints with invalid TLS certificates. - Redis Sentinel support as an in-memory store and cluster coordinator backend (#2430). ## Changed ## Fixed - DANE: Verify DNSSEC is supported by the resolver before attempting to validate TLSA records. - TLS: Update search index when file-backed certificates are refreshed. - JMAP: `Principal/query` returns broad results when a `name` or `email` filter cannot be resolved. - Webhooks: event IDs collide for same event type emitted in the same second. <hr /> ### Check binary attestation [here](https://github.com/stalwartlabs/stalwart/attestations/32653276)