v1.4.0

pingcap/autoflowv1.4.0Aug 16, 2019by FiloSottile

AI Summary

Introduces macOS Catalina compatibility, URL and email SANs, and expands OS support to SLES, OpenSUSE, Snapcraft, and CentOS 7.

Key Highlights

  • macOS Catalina compatibility with fixed notBefore date
  • URL and email SAN support
  • Client certificates created with `-client` filename suffix
  • Support for SLES, OpenSUSE, Snapcraft, and CentOS 7
  • Linux release binaries are now fully static

Breaking Changes

  • Certificates generated by previous versions of mkcert after July 1st, 2019 will not work on macOS 10.15 Catalina

New Features

  • URL and email SANs
  • Static Linux binaries
  • New OS support (SLES, OpenSUSE, Snapcraft, CentOS 7)

Full Release Notes

macOS 10.15 Catalina introduced [certificate lifespan limits](https://support.apple.com/en-us/HT210176) which block mkcert certificates. As a temporary measure, mkcert certificates now have a fixed notBefore date of June 1st, 2019. Once the ACME server is implemented, certificate lifespan will be shortened to 3 months. (#174)

**Certificates generated by previous versions of mkcert after July 1st, 2019 will not work on macOS 10.15 Catalina**, and will have to be regenerated. The root CA is unaffected and there is no need to rerun `mkcert -install`.

URL (#166) and email (for S/MIME, #152) SANs are now supported.

Client certificates are now created with a `-client` filename suffix, and they claim the serverAuth EKU as well as the clientAuth one.

The certificate subject now includes the full user name, like `filippo@Bistromath.local (Filippo Valsorda)`.

SLES, OpenSUSE (#162), Snapcraft (#116), and CentOS 7 (#120) are now supported.

Linux release binaries are now fully static, and will work regardless of the system libc. (#169)