It looks to me that v1.4.0 has introduced a breaking change (for a minor version) to the Client Builder API for setting pinned certificates:
|
public Builder setCACerts(String[] userCaCerts) { |
SetCACerts used to accept public key pins in the String list, and now requires PEM-encoded certifcates?
So this can fail at runtime when supplied the old style pins.
If you agree, I am not sure if you'd want to revert that, add a new method for the new trust store mechanism, or document the migration in the release notes.
It looks to me that v1.4.0 has introduced a breaking change (for a minor version) to the Client Builder API for setting pinned certificates:
duo_universal_java/duo-universal-sdk/src/main/java/com/duosecurity/Client.java
Line 270 in dcde123
SetCACerts used to accept public key pins in the String list, and now requires PEM-encoded certifcates?
So this can fail at runtime when supplied the old style pins.
If you agree, I am not sure if you'd want to revert that, add a new method for the new trust store mechanism, or document the migration in the release notes.