v1.4.0
blackboardsh/electrobunv1.4.0Aug 16, 2019by FiloSottile
AI Summary
Added macOS Catalina compatibility by fixing certificate dates, introduced URL and email SANs, and expanded OS support including CentOS 7 and Snapcraft.
Key Highlights
- macOS 10.15 Catalina compatibility with fixed notBefore dates.
- Support for URL and email SANs.
- Linux release binaries are now fully static.
- Expanded OS support for SLES, OpenSUSE, Snapcraft, and CentOS 7.
Breaking Changes
- Certificates generated by previous versions after July 1st, 2019 will not work on macOS 10.15 Catalina.
New Features
- URL and email SAN support.
- Client certificates created with -client filename suffix.
- Subject includes full username (e.g., filippo@Bistromath.local (Filippo Valsorda)).
- Static Linux binaries for better portability.
Full Release Notes
macOS 10.15 Catalina introduced [certificate lifespan limits](https://support.apple.com/en-us/HT210176) which block mkcert certificates. As a temporary measure, mkcert certificates now have a fixed notBefore date of June 1st, 2019. Once the ACME server is implemented, certificate lifespan will be shortened to 3 months. (#174) **Certificates generated by previous versions of mkcert after July 1st, 2019 will not work on macOS 10.15 Catalina**, and will have to be regenerated. The root CA is unaffected and there is no need to rerun `mkcert -install`. URL (#166) and email (for S/MIME, #152) SANs are now supported. Client certificates are now created with a `-client` filename suffix, and they claim the serverAuth EKU as well as the clientAuth one. The certificate subject now includes the full user name, like `filippo@Bistromath.local (Filippo Valsorda)`. SLES, OpenSUSE (#162), Snapcraft (#116), and CentOS 7 (#120) are now supported. Linux release binaries are now fully static, and will work regardless of the system libc. (#169)