Vault v0.1.1 Release Notes

Release Date: 2015-05-02 // almost 9 years ago
  • ๐Ÿ”’ SECURITY CHANGES:

    • physical/file: create the storge with 0600 permissions [GH-102]
    • token/disk: write the token to disk with 0600 perms

    ๐Ÿ‘Œ IMPROVEMENTS:

    • core: Very verbose error if mlock fails [GH-59]
    • command/*: On error with TLS oversized record, show more human-friendly error message. [GH-123]
    • command/read: lease_renewable is now outputted along with the secret to show whether it is renewable or not
    • command/server: Add configuration option to disable mlock
    • command/server: Disable mlock for dev mode so it works on more systems

    ๐Ÿ› BUG FIXES:

    • core: if token helper isn't absolute, prepend with path to Vault executable, not "vault" (which requires PATH) [GH-60]
    • core: Any "mapping" routes allow hyphens in keys [GH-119]
    • core: Validate advertise_addr is a valid URL with scheme [GH-106]
    • command/auth: Using an invalid token won't crash [GH-75]
    • credential/app-id: app and user IDs can have hyphens in keys [GH-119]
    • helper/password: import proper DLL for Windows to ask password [GH-83]