---
title: New Product Release – ADSS Server v8.4.3
description: ADSS Server v8.4.3 adds custom RDNs, RA-signed CSR enrollment, simultaneous Full and Partitioned CRLs, configurable OIDC scopes, and Unity Console updates.
image: https://blog.ascertia.com/hubfs/ADSS%20Release%208.4.3-FIMG-0710291118.png
---

[![](https://blog.ascertia.com/hubfs/asc-blog-logo-detail.png)](https://blog.ascertia.com/)

##### [View all posts](https://blog.ascertia.com/)

[Contact Us](https://www.ascertia.com/company/contact-us/)

# New Product Release – ADSS Server v8.4.3

Posted by [Mike Hathaway](https://blog.ascertia.com/author/mike-hathaway) on Oct 7, 2026, 10:59:59 AM

![](https://blog.ascertia.com/hubfs/Mike%20Hathaway%20Headshot%202023.png)

I’m pleased to announce the release of ADSS Server v8.4.3, the latest regular release update to our flagship PKI and Trust Services platform. This release gives Certificate Authority operators more flexibility in how certificates are structured and enrolled, extends the CRL capabilities introduced in v8.4.2, brings two more services into the Unity Console, and delivers a substantial set of security, performance and reliability updates.

![Data center server racks with digital certificate icons connected across the network, representing ADSS Server v8.4.3 managing certificate authority and trust services at scale.](https://blog.ascertia.com/hubfs/ADSS%20Release%208.4.3-FIMG-0710291118.png)

ADSS Server is a full‑featured, modular trust services platform trusted globally by enterprises, government agencies, and trust service providers to deliver certificate authority, digital signing, timestamping, validation, and lifecycle services from one unified platform.

## What’s New in v8.4.3

ADSS Server v8.4.3 focuses on the needs we hear most often from Certificate Authority operators and trust service providers: adapting the platform to local and sector‑specific certificate requirements, supporting a wider range of enrollment models, and running large‑scale PKI with confidence.

## Custom RDNs for Sector‑ and Jurisdiction‑Specific Certificate Profiles

Many national schemes, regulated sectors and enterprise PKIs define their own subject attributes, often identified by proprietary OIDs. ADSS Server now lets operators define custom Relative Distinguished Names (RDNs) for the subject distinguished name of CSRs and certificates, specifying the attribute name, OID and value encoding for each one.

For short‑lived certificates issued through ADSS Unity Service, operators can map identity claims directly to custom RDNs in the Unity Profile, so verified identity data flows into the certificate automatically, without custom integration work.

## RA‑Signed CSR Enrollment

Some business applications and token types cannot have the key holder sign a certificate request, for example hardware tokens that cannot sign until they have been activated. ADSS Server now supports RA‑signed CSR enrollment for certificate profiles configured for it: an RA operator signs the request, WebRA validates the RA operator’s signature, and ADSS Server issues the certificate for the key holder’s public key. Every request handled this way is recorded in the audit log with the profile and request details, so the enrollment model remains fully traceable.

Used together with Go\>Sign Desktop, this enables enrollment of activation‑gated PKCS#11 tokens without requiring the user’s token to sign the request.

## Full and Partitioned CRLs, Side by Side

Building on the configurable CRL settings introduced in v8.4.2, ADSS Server Local CAs can now generate and publish Full and Partitioned CRLs at the same time, each with its own publishing settings and location. Certificate templates determine which CRL issued certificates reference, so a single CA can serve relying parties that expect a complete CRL alongside high‑volume deployments that benefit from smaller, partitioned CRLs. Existing CA and template configurations continue to work unchanged.

## Configurable OIDC Scopes for Identity Provider Integration

ADSS RAS and ADSS Unity Service now let operators configure the OIDC scopes requested from external Identity Providers. Operators decide exactly which user information is requested during authentication, supporting data minimisation and simplifying integration with Identity Providers that expose claims through custom scopes.

## Continuing Unity Console Modernisation: TSL Monitor and LTAN

The TSL Monitor service, which keeps Trusted Lists current for signature and certificate validation, and the LTAN (Long‑Term Archive and Notary) service can now both be managed from the Unity Console. Following the ePassport services added in v8.4.2, this brings more of ADSS Server’s trust services into a single, modern administration experience.

## Security, Performance and Reliability

ADSS Server v8.4.3 updates key components supplied with the platform, including Apache Tomcat 10.1.60, BouncyCastle 1.85, Apache PDFBox 3.0.8 and the DSS libraries, addressing 29 published CVEs.

The release also delivers nearly 30 performance and reliability improvements, many shaped by customer deployments operating at scale. Highlights include faster certificate revocation and certificate lookup, quicker signature authorisation in ADSS Unity Service, more robust HSM integration with Utimaco CP5 and Azure Managed HSM, and automatic recovery from temporary database outages.

## Why This Matters

Every PKI is shaped by its context: the regulations it operates under, the sector it serves, and the identity and token ecosystem around it. With custom RDNs, RA‑signed enrollment and configurable OIDC scopes, ADSS Server v8.4.3 adapts to those requirements through configuration rather than custom development.

For Certificate Authorities and trust service providers, it means certificate profiles and revocation services that match exactly what their schemes and relying parties require. For organisations running PKI at scale, it means a faster, more resilient platform with an up‑to‑date security baseline. And for every customer, it means continued confidence that ADSS Server is evolving with the standards and operating realities that shape digital trust.

## A Stronger Trust Services Platform from Ascertia

This release reinforces ADSS Server as a flexible, dependable platform for certificate authority and digital trust operations.

With custom RDN support, RA‑signed CSR enrollment, simultaneous Full and Partitioned CRLs, configurable OIDC scopes, continued Unity Console modernisation and a broad set of security and reliability updates, ADSS Server v8.4.3 gives customers more control over how they issue, protect and validate digital trust at scale.

These enhancements support our wider mission: helping governments and organisations establish digital trust in the systems, documents, identities, and transactions that matter most.

[Visit Ascertia.com](https://www.ascertia.com/)

This is a search field with an auto-suggest feature attached.

 Search

- There are no suggestions because the search field is empty.

### Recent Posts

### Posts by Topic

- [News (64)](https://blog.ascertia.com/tag/news)
- [Digital Trust (53)](https://blog.ascertia.com/tag/digital-trust)
- [Esignatures & Digital Signatures (41)](https://blog.ascertia.com/tag/esignatures-digital-signatures)
- [Case Study (32)](https://blog.ascertia.com/tag/case-study)
- [Esignatures, Digital Signatures & Digital Signing (25)](https://blog.ascertia.com/tag/esignatures-digital-signatures-digital-signing)
- [Remote Signing (21)](https://blog.ascertia.com/tag/remote-signing)
- [Ascertia Partners (16)](https://blog.ascertia.com/tag/ascertia-partners)

### Subscribe to Blog

### Download this essential eBook

Choosing the right type of e-signature  
for your business

[![Download your eBook](https://no-cache.hubspot.com/cta/default/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8.png)](https://cta-redirect.hubspot.com/cta/redirect/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8)

- Signing
- EU eIDAS Compliant Advanced & Qualified Signatures
- [SigningHub](https://www.ascertia.com/products/signinghub/)
- [ADSS Signing Server](https://www.ascertia.com/products/adss-signing-server/)

- PKI
- Modular solution for your Trust Service needs
- [ADSS Certificate Authority](https://www.ascertia.com/products/adss-ca-pki-server/)
- [ADSS Registration Authority](https://www.ascertia.com/products/adss-ra-server/)
- [ADSS Validation Authority](https://www.ascertia.com/products/adss-ocsp-server/)
- [ADSS Time Stamp Authority](https://www.ascertia.com/products/adss-tsa-server/)
- [ADSS Archive Authority](https://www.ascertia.com/products/adss-ltans-evidence-server/)

- Tools
- Integrate, test & monitor your Trust Services
- [ADSS Auto File Processor](https://www.ascertia.com/products/adss-auto-file-processor/)
- [ADSS Client SDK](https://www.ascertia.com/products/adss-client-sdk/)

- Solutions
- [Mobile Signatures](https://www.ascertia.com/solutions-by-technology/mobile-signing/)
- [Remote (Cloud) Signing](https://www.ascertia.com/solutions-by-technology/remote-signing/)
- <https://www.linkedin.com/company/ascertia> <https://www.youtube.com/user/ESIGNwithAscertia>

[Terms of Use](https://www.ascertia.com/terms-of-use/)   |   [Privacy Policy](https://www.ascertia.com/company/privacy-policy/)   |   © Ascertia. All rights reserved. ISO 9001:2015 Certified