Releases: secure-device-onboard/release
v1.10.8
Fixed Issues
all-in-one-demo,iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve security vulnerabilities.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
658be5278b9780d24347c6939219aa06786a9d1b64b8df3ef5a377f4f0ce83c2 all-in-one-demo-v1.10.8.tar.gz
2608c177b861671de127c4272fe74c0d79e3c2cf2a257495bdfeeb807f7c8888 iot-platform-sdk-v1.10.8.tar.gz
74f0b563499990b85b2d9fc416505f18c698c7074f50e604907a3e46c68b8656 NOTICES-v1.10.8.tar.gz
2ae2f3764be77e3cf27479f72afe88c6013cc027d15563ff51c0f15414b5f019 pri-v1.10.8.tar.gz
e15c8baa0fe306008f4c68cca7bf3ec906f20583ff1e542396cb71f46d804921 rendezvous-service-v1.10.8.tar.gz
68061ae40bb0133812b382f1dd8ba591eb3139b0200715e5f82fdfeb33e98ada supply-chain-tools-v1.10.8.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.7
Fixed Issues
all-in-one-demo,iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve security vulnerabilities.
client-sdk: Changes to update OpenSSL version.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
41b22ea90ee3e721374fea3f6dc7fd91113b13820c25e8be2c95125e0abf8997 NOTICES-v1.10.7.tar.gz
3d21d0a222a0d389939666dfbed041f071f17d87fa32b9e4f70512c4d861566a all-in-one-demo-v1.10.7.tar.gz
bce2adc693250db4e849099ebab0df8e66944559740fa9aaafd14eb07f8e0749 client-sdk-v1.10.7.tar.gz
61367fedd65c5deaa365b80a74b3eaab83fbbd7e1841453aaa282ea4ec30943a iot-platform-sdk-v1.10.7.tar.gz
07839050310cb380de8cb71b981428672398962ce1825e0e6a585ea820491f6d pri-v1.10.7.tar.gz
fab78061f5be80b2b1fcf1f725ca8f436d1550a2b8778ca03105538245e7b0b4 rendezvous-service-v1.10.7.tar.gz
c5d50375bc9fa16b651dca44ae9aee729d244ec7dc7ae78a99d1c4bf66d12ba5 supply-chain-tools-v1.10.7.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.6
Fixed Issues
all-in-one-demo,iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve CVE-2022-22965 vulnerability.
client-sdk: Changes to update OpenSSL version.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
df9297af5f76d869bb9b0552ef1ebfc41f5d9666314b770ea6e961e5bd0d80d3 NOTICES-v1.10.6.tar.gz
5828fbd9efcb7f8db63ecc1f3f44bd33295e55d6cae7fb10a5f37bef7eb88c93 all-in-one-demo-v1.10.6.tar.gz
10d905c414c844192baab31f9ca8bc05d68f7d4b8f6e36201bec7ee94340a3dc client-sdk-v1.10.6.tar.gz
03d244ca95751cb3f55186dc17b9b7c9e7f6574603f16e7a9f7e6d309ba18d87 iot-platform-sdk-v1.10.6.tar.gz
1736c8ee28b89b4a66258d7c2e21ba2b95d929d580a05e135ecc96a9bdb64cc1 pri-v1.10.6.tar.gz
b3665e8da41c36f7a8888a3b07f0711bdc52603529b524304734d78088c44462 rendezvous-service-v1.10.6.tar.gz
32c5c40563ceb97097079f1c0edfc7f825673cdfb58ade1713b0845b178dcde5 supply-chain-tools-v1.10.6.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.5
Fixed Issues
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve CVE-2021-44832 vulnerability.
client-sdk: There are no changes from previous release.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
8b7f4cb94faed258dca9b1390a7ce21e59d92737827d66d3655fd0bfa37d7bb5 all-in-one-demo-v1.10.5.tar.gz
4dbd261d98a8d7ec9df282f8787925cf849b8e09456a01f05312b183f97a5163 client-sdk-v1.10.5.tar.gz
fb61298345e51431ebb11f59b43318f1515c24c16c44177a2cf606e2528b09c5 iot-platform-sdk-v1.10.5.tar.gz
965440fe31e6485e330b57121478bb618f5b238e6f48da9df347f2147118239f pri-v1.10.5.tar.gz
08fc9d6ef8e6328725fd2ec765bb05af736ba89731bec3ce7a33c28ecf620716 rendezvous-service-v1.10.5.tar.gz
dc1d414160ffe62735ddccd9f8fae543f1650a680bd36fd903b292a875e56300 supply-chain-tools-v1.10.5.tar.gz
b4a8c45fef072d59093c15a45fa06fc02d630de119150035e42417f76d233c8e NOTICES-v1.10.5.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.4
Fixed Issues
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve CVE-2021-44228 vulnerability.
client-sdk: There are no changes from previous release.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
22ef2de4166b0286ba9c4ab207a37583e00929a721ab57f4bba749088ca03dbd all-in-one-demo-v1.10.4.tar.gz
976fd2e40b1de54189f2eed91b988b99dab3d11b27435d9bfb9640a3cbdeadef client-sdk-v1.10.4.tar.gz
0d68f81469e72ca102ef8fc4d9617cdae707746e4110a2c10b16d618162bb229 iot-platform-sdk-v1.10.4.tar.gz
dd7fa3e673dac5e1c53630b019a3a78604ad6a13f9db816450a0df1a7587e6d0 pri-v1.10.4.tar.gz
16351660544d8bda45ec8d820df1e88c1aeec037fb57e19bf17de264a5c77a43 rendezvous-service-v1.10.4.tar.gz
6a72bf625dbe408d3a9381016de5f1046257ae111091e39adcb3dd46ee7d7868 supply-chain-tools-v1.10.4.tar.gz
59c1b5f7b70a9d316252254f668a093e9a77fd62f0aeab4dd97edde13c6a8b83 NOTICES-v1.10.4.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.3
Fixed Issues
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve some of the security vulnerabilities.
client-sdk: There are no changes from previous release.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
7fa4393ed759a5dae0e2b0921710a88ebe2e6a8d690a6c0179aaa64a673b6466 all-in-one-demo-v1.10.3.tar.gz
60fac0e6d6f099e17368fa972222b989f21f58e943981863664f9a6742bf1e77 client-sdk-v1.10.3.tar.gz
d36197c732017cd4a746199517b83debae89fa0865e2a9aae2498f4a0cad5fce iot-platform-sdk-v1.10.3.tar.gz
ae2a0a9cbd39ec345691b6b5a13b60f0e06f3d73c1ba3cc6de8324fc508c39d5 pri-v1.10.3.tar.gz
585fa01e713bdd7a9f9d9deb17a2cefb23a7d2dc8c58bcab635f014f45e0c66e rendezvous-service-v1.10.3.tar.gz
b96764743dfc101659459d53a6cc5db0fa6ac200db349d1a6cc94a6f285319e8 supply-chain-tools-v1.10.3.tar.gz
d300ad16e8ef76933c9301db4083291578bdedfa45d2c2596fd2cc4ce76c2da9 NOTICES-v1.10.3.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.2
Fixed Issues
rendezvous-service: The default value of HmacSecret used to sign the JWT tokens has been removed from properties files. This value is now getting generated when the docker container starts.
rendezvous-service: The JWT tokens are now additionally validated to ensure that the valid tokens expire within a pre-defined duration.
client-sdk: Fixed possible buffer overflow issue while parsing proxy information.
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve some of the security vulnerabilities.
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: Runtime Docker containers are updated to include “apt-get -y upgrade” to include latest OS components.
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: Additional comments are added to specify use of test credentials for examples.
Known Issues
all-in-one-demo, rendezvous-service: While building the source code, maven reports reflective access as ERROR even though the build is successful. See this GitHub issue for more details.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
379abd890eb58aafabe5bdad04146bf71a053924b33f884e5abd129cdca0f577 - all-in-one-demo-v1.10.2.tar.gz
f4c95a3934b5bda6b425d64efd79812c11a9256a93181d932388aa2c6c24a7fe - client-sdk-v1.10.2.tar.gz
708cde9daea13c4bebbcb11906d363f705d84b598000ed311cd415415757dc36 - iot-platform-sdk-v1.10.2.tar.gz
9d55c015130802f37dc0ce76be07ef7635f2e7e7545c31cb2331301edafa9a78 - pri-v1.10.2.tar.gz
8494d2be27c5c696a4c15d231d98c3b66537bad562b7453d9adb8c70c66eeb35 - rendezvous-service-v1.10.2.tar.gz
9bd98cc519f5e008efeaf84d4cf2f376e3b49c6c10d92ad61378bbc13ebb7bee - supply-chain-tools-v1.10.2.tar.gz
dfe998be9a3cb1ba880557e68a72f77aa5b4031a6a1ff66f22337dfd4c41eae6 - NOTICES-v1.10.2.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.10.1
Fixed Issues
all-in-one-demo, iot-platform-sdk, pri, rendezvous-service, supply-chain-tools: The version of third-party dependencies have been updated to resolve some of the security vulnerabilities.
pri, supply-chain-tools: The URL for downloading On-Die ECDSA certificate and CRLs has been changed. The related download script has been updated to use the new URLs.
all-in-one-demo: The REST APIs now support HTTPS protocol.
SHA256 checksum for release binaries
Following SHA256 checksum is calculated using sha256sum tool
34b74d0cba87c37f67188dcc4a25f39a4bbd302cb4dd92bd09678193c8a85c05 - all-in-one-demo-v1.10.1.tar.gz
c7d0e3b0b036c8e3fcccebb00ed838bf4f2b3e056ee04dfffaba36db8b27b3a2 - iot-platform-sdk-v1.10.1.tar.gz
f4451fbf46a2fef03f6259fe7f47639b8587f94d2800ceefbc5c2995c79b990e - rendezvous-service-v1.10.1.tar.gz
72e1854b11c07cc1eecc3d994334704f1a73bce3c4c776dff8d516fd78613633 - pri-v1.10.1.tar.gz
a501f0b453213adb2e1d6bcf2a71410a01ef0e40d04046f336d233ca1b19ac14 - supply-chain-tools-v1.10.1.tar.gz
6df2ab7efb2ebde8f78caf5fd97bb20795fb9949281cdb7f17e9be8f7b5aa9b9 - NOTICES-v1.10.1.tar.gz
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.9.1
Fixed Issues
client-sdk: The link for the TPM2_TSS_ENGINE component specified in SDO 1.9.0 release no longer exists. The issue was fixed by updating the link to latest stable release. See this Github issue for details.
iot-platform-sdk: In SDO 1.9.0 release, the TO0Scheduler was not able to complete TO0 operations against hosted Rendezvous service if it was executed in an open network (not behind a proxy). The issue was fixed by specifying HTTP version as 1.1 for all HTTP clients. See this Github issue for details.
pri: In SDO 1.9.0 release, the PRI TO0Client and Device implementations were not able to complete TO0/TO1 operations against hosted Rendezvous service if they were executed in an open network (not behind a proxy). The issue was fixed by specifying HTTP version as 1.1 for all HTTP clients. See this Github issue for details.
Supported hardware platforms
client-sdk: X86, ARM-SE (source only)
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.
v1.8.1
Fixed Issues
client-sdk: The link for the TPM2_TSS_ENGINE component specified in SDO 1.8.0 release no longer exists. The issue was fixed by updating the link to latest stable release. See this Github issue for details.
pri: In SDO 1.8.0 release, the PRI TO0Client and Device implementations were not able to complete TO0/TO1 operations against hosted Rendezvous service if they were executed in an open network (not behind a proxy). The issue was fixed by specifying HTTP version as 1.1 for all HTTP clients. See this Github issue for details.
Supported hardware platforms
client-sdk: X86, ARM-SE (source only)
Documentation
https://secure-device-onboard.github.io/docs/
Please ignore Source code zip/tar.gz files. These are default artifacts generated during GitHub Release process.