NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #682 most downloaded on NuGet
The Bouncy Castle Crypto package is a C# implementation of cryptographic algorithms and protocols, it was developed by the Legion of the Bouncy Castle, a registered Australian Charity, with a little help! The Legion, and the latest goings on with this package, can be found at [http://www.bouncycastle.org](http://www.bouncycastle.org). In addition to providing basic cryptography algorithms, the package also provides support for CMS, TSP, X.509 certificate generation and a variety of other standards such as OpenPGP.
Last release 6 years ago
no release in 18 months
Ships unpredictably
gaps range from 4 weeks to 111.4 years
Most releases are documented
notes for 6 of 8 stable releases
2 versions withdrawn
withdrawn after publishing
127 years old
10 releases · first in 1900
Defects Fixed The TimeStampToken generator is now using PkcsObjectIdentifiers.IdAASigningCertificateV2 for the generating SigningCertificateV2. Additi
Defects Fixed The TimeStampToken generator is now using PkcsObjectIdentifiers.IdAASigningCertificateV2 for the generating SigningCertificateV2. Additional Features and Functionality Added CSHAKE digest and KMAC. Added support for PKCS#5 Scheme 2 to Pkcs12Store. Improved performance for GCM.
Defects Fixed EdDSA verifiers now reject overly long signatures. Fixed field reduction for custom secp128r1 curve. ASN.1: Enforce no leading zeroes in
Defects Fixed EdDSA verifiers now reject overly long signatures. Fixed field reduction for custom secp128r1 curve. ASN.1: Enforce no leading zeroes in OID branches (longer than 1 character). Additional Features and Functionality TLS: BasicTlsPskIdentity now reusable (returns cloned array from GetPsk). Improved performance for multiple ECDSA verifications using same public key. Support has been added for ChaCha20-Poly1305 AEAD mode from RFC 7539. PKCS12: Improved support for certificate-only key stores without password.
One column per quarter.
IMPORTANT This is the final feature release with support for legacy .NET platforms. From 1.9.0 we will be targeting more modern .NET frameworks (see h
IMPORTANT This is the final feature release with support for legacy .NET platforms. From 1.9.0 we will be targeting more modern .NET frameworks (see https://github.com/bcgit/bc-csharp/pull/68) and updating our build and packaging systems. The 1.8.x series will continue to receive bug fixes, but limited new functionality.
Additional Features and Functionality:
IMPORTANT This is the final feature release with support for legacy .NET platforms. From 1.9.0 we will be targeting more modern .NET frameworks (see h
IMPORTANT This is the final feature release with support for legacy .NET platforms. From 1.9.0 we will be targeting more modern .NET frameworks (see https://github.com/bcgit/bc-csharp/pull/68) and updating our build and packaging systems. The 1.8.x series will continue to receive bug fixes, but limited new functionality. Defects Fixed Rfc3211WrapEngine would not properly handle messages longer than 127 bytes. This has been fixed. Additional Features and Functionality Restrictions on the output sizes of the Blake2b/s digests have been removed. RFC 7748: Higher-level support for X25519 and X448 has been added. RFC 8032: Higher-level support for Ed25519 and Ed448 has been added. Implementation of the SM4 block cipher has been added. Added support for Plain ECDSA (a.k.a CVC-ECDSA).
IMPORTANT In this release, the TLS library has moved to a whitelisting approach for client-side validation of server-presented Diffie-Hellman (DH) par
IMPORTANT In this release, the TLS library has moved to a whitelisting approach for client-side validation of server-presented Diffie-Hellman (DH) parameters. In the default configuration, if a ciphersuite using ephemeral DH is selected by the server, the client will abort the handshake if the proposed DH group is not one of those specified in RFC 3526 or RFC 7919, or if the DH prime is < 2048 bits. The client therefore no longer offers DH ciphersuites by default.
Additional Features and Functionality Further work has been done on improving SHA-3 performance. EC key generation and signing now use cache-timing resistant table lookups. RFC 7748: Added low-level implementations of X25519 and X448. RFC 8032: Added low-level implementations of Ed25519 and Ed448.
Defects Fixed DTLS now supports records containing multiple handshake messages.
Defects Fixed DTLS now supports records containing multiple handshake messages.
Additional Features and Functionality TLS: support for ClientHello Padding Extension (RFC 7685). TLS: support for ECDH_anon key exchange. BCrypt implementation added. BLAKE2b and BLAKE2s implementations added. GOST R 34.11-2012 implementation added. DSTU-7564 message digest implementation added. SM2 signatures, key exchange, and public key encryption implementations added.
Nothing published for this version
Nothing published for this version
Defects Fixed EdDSA verifiers now reject overly long signatures. Fixed field reduction for custom secp128r1 curve. ASN.1: Enforce no leading zeroes in
Defects Fixed EdDSA verifiers now reject overly long signatures. Fixed field reduction for custom secp128r1 curve. ASN.1: Enforce no leading zeroes in OID branches (longer than 1 character). Additional Features and Functionality TLS: BasicTlsPskIdentity now reusable (returns cloned array from GetPsk). Improved performance for multiple ECDSA verifications using same public key. Support has been added for ChaCha20-Poly1305 AEAD mode from RFC 7539. PKCS12: Improved support for certificate-only key stores without password.
IMPORTANT In this release, the TLS library has moved to a whitelisting approach for client-side validation of server-presented Diffie-Hellman (DH) par
IMPORTANT In this release, the TLS library has moved to a whitelisting approach for client-side validation of server-presented Diffie-Hellman (DH) parameters. In the default configuration, if a ciphersuite using ephemeral DH is selected by the server, the client will abort the handshake if the proposed DH group is not one of those specified in RFC 3526 or RFC 7919, or if the DH prime is < 2048 bits. The client therefore no longer offers DH ciphersuites by default.
Additional Features and Functionality Further work has been done on improving SHA-3 performance. EC key generation and signing now use cache-timing resistant table lookups. RFC 7748: Added low-level implementations of X25519 and X448. RFC 8032: Added low-level implementations of Ed25519 and Ed448.
Your coding agent can read these notes before it upgrades. Set up the MCP server →