September 8th, 2011Major changes:
· Updated to Apache Subversion 1.7.0-rc3 For further details please see Apache Subversion 1.7 Release Notes.
· Enable SVNPathAuthz short_circuit option to improve performance on authorization intensive operations (e.g. svn log).
· Add support for IPv6 protocol: VisualSVN Server now may be configured to listen on IPv6 interfaces.
· VisualSVN Server Manager now attempts to use delegation impersonation level when connecting to a remote server.
· Being installed for the first time, VisualSVN Server makes the pre-configured self-signed server certificate trusted on a local machine.
· Never trigger Subversion hooks when managing repositories in VisualSVN Server Manager.
· Adjust Apache HTTP Server settings for better compatibility with Subversion 1.7 clients.
VisualSVN Server Manager improvements:
· Restart VisualSVN Server service gracefully when applying new configurations settings.
· Allow to configure repository access permissions for accounts from trusted Active Directory domains.
· New self-signed server certificates are generated to be valid for 10 years.
· New self-signed server certificates are generated to be valid for server authentication only.
· Add option to view current server certificate details.
· Several performance and usablity improvements.
· Fixed: unable to import certificate with expiration date later than 2049 year.
Other changes:
· Rename authentication realm to "VisualSVN Server".
· Move server.pid file to a local temporary directory.
· Set default maximum size of VisualSVN Server log to 20mb.
· Fixed: unable to create or remove folder in VisualSVN Server Manager if commit log message contains line breaks.
· Fixed: web browsers do not invalidate cache and manual page refresh is required to view recent repository changes.
September 8th, 2011· Updated to Apache HTTP Server 2.2.20 with fix for the critical vulnerability: CVE-2011-3192.
· Negotiate authentication method is disabled for Subversion clients built against Neon (reverting the corresponding change from the version 2.1.9).
June 2nd, 2011· Updated to Subversion 1.6.17 with fixes for the following vulnerabilities: CVE-2011-1752, CVE-2011-1783, CVE-2011-1921.
· Updated to Apache HTTP Server 2.1.17.
· Updated to Neon 0.29.6.
· Negotiate authentication method is enabled for Subversion clients built against Neon 0.29.5 (and newer).
· Fixed: an attempt to change repository root settings fails with the "The remote procedure call failed. (0x800706be)" error message.
· Fixed: upgrade fails with the "Custom action CreateInitialAuthFilesExecute failed" error message when repositories are stored on network share.
March 25th, 2011· Updated to OpenSSL 0.9.8r with fixes for following vulnerabilities: CVE-2010-4180, CVE-2010-4252, CVE-2011-0014.
March 4th, 2011· Updated to Subversion 1.6.16 with fix for critical vulnerability: CVE-2011-0715.
December 1st, 2010· Updated to Subversion 1.6.15.
· Updated to Apache 2.1.17
· Updated to OpenSSL 0.9.8p
· Updated to neon 0.29.5
· mod_headers Apache module is included into the installation package.
October 12th, 2010· Updated to Subversion 1.6.13
July 14th, 2010· Updated to Subversion 1.6.12.
· Allow to grant access rights for a domain computer account.
· Prohibit to grant access rights for a domain distribution group (since Active Directory distribution groups are not intended to manage permissions).
· Fixed: installation package behaves incorrectly when AlwaysInstallElevated policy is enabled.
· Fixed: VisualSVNServerHooks.exe does not work if VisualSVN Server service account doesn't have access permissions to all parents of the repositories folder.
· Fixed: non-ASCII characters are incorrectly logged to Access and Operational logs.
· Fixed: unable to install if computer name contains underscore characters.
· mod_deflate Apache module is not loaded anymore.
April 27th, 2010· Updated to Subversion 1.6.11.
· Disallow installation on servers with non-ASCII hostnames.
· Generate Apache config in the UTF-8 encoding.
February 16th, 2010· Updated to Subversion 1.6.9.
· Being installed for the first time, VisualSVN Server pre-generates 2048 bits long private key for SSL certificates.
January 19th, 2010· New feature: Integrated Windows Authentication. With Integrated Windows Authentication users gain access to VisualSVN Server without being prompted for username and password. Available in Enterprise Edition only.
· Fixed: access permissions settings can be interpreted incorrectly when Windows Authentication is used.
· Favicon is added to web pages produced by VisualSVN Server.
· Updated to Neon 0.29.3.
· Updated to OpenSSL 0.9.8l with fix for critical vulnerability: CVE-2009-3555.
October 28th, 2009· Updated to Subversion 1.6.6.
· NetworkService account receives explicit access permission to the installation folder (as a workaround for the situations when it does not have such permissions implicitly)
· Fixed: WMI provider may be not reloaded after the server upgrade.
· Fixed: VisualSVN Server may crash if Windows permissions settings file contains invalid data.
September 12th, 2009· Fixed: commits sometimes fail with the "SSL negotiation failed.." error message.
August 28th, 2009· Updated to Subversion 1.6.5.
· Updated to Apache 2.2.13 with fix for critical vulnerability: CVE-2009-2412.
August 7th, 2009· Updated to Subversion 1.6.4 with fix for critical vulnerability: CVE-2009-2411.
· Updated to Apache 2.2.12 with fixes for critical vulnerabilities: CVE-2009-1891, CVE-2009-1195, CVE-2009-1890, CVE-2009-1191, CVE-2009-0023, CVE-2009-1955, CVE-2009-1956.
August 3rd, 2009· GZip compression is disabled because of potential memory leaks.
August 3rd, 2009· Fixed: installation process terminates in some environments with the "Cannot get effective rights from ACL: Access is denied" error messsage.
· Fixed: WMI permissions are not configured properly on Windows Server 2003/XP.
July 23rd, 2009· Fixed: adjusting permissions can be performed very slowly during the installation process.