Chat now with support
Chat with Support

Safeguard Authentication Services 6.1 - Release Notes

Safeguard Authentication Services

Safeguard Authentication Services

Release Notes

Version 6.1

04 December 2024, 13:57

These release notes provide information about the Safeguard Authentication Services release. For the most recent documents and product information, see Online product documentation.

New features

New features in version 6.1

The following features have been added:

  • This new release of Safeguard Authentication Services 6.1 requires a new license. Please obtain the new license file before installing the new release. To obtain a new license, please refer to the License Key Upgrade page.

  • In addition to macOS, Certification Autoenrollment now also works on Linux. Certificates and keys can be stored in PKCS#12 files or protected by the TPM chip.

  • Automount support has been added.

    Safeguard Authentication Services provides the automount maps from Active Directory. Users can use automounts without involving NIS.

  • Added native IPS packages for Solaris. The install.sh script will now use these by default on Solaris 11, and the SVR4 packages only on Solaris 10. The "--variant svr4" or "--variant 10" arguments can be specified to still use the old package format.

  • Authentication Services now supports kerberos armoring, also known as FAST (Flexible Authentication Secure Tunneling), which is an enhancement to the Kerberos protocol designed to strengthen the security of the authentication process.

Related topics

Enhancements

The following is a list of enhancements implemented in Safeguard Authentication Services 6.1.

Table 1: General enhancements
Enhancement Issue ID

Safeguard Authentication Services now has a build with Control-flow Enforcement Technology (CET) enabled for Linux x86_64 architecture.

For RHEL 8 and later, it supports both shadow stack and indirect branch tracking. To install it, use the packages from the client/linux-x86_64-rh8 subfolder, or specify the --variant rh8 argument for install.sh.

452733

Resolved issues

The following is a list of issues addressed in this release.

Table 2: General resolved issues in version 6.1
Resolved Issue Issue ID

Some UNIX-enabled groups have been temporarily missing after upgrading or the first flush. A later flush could fix and fetch the groups correctly.

The problem affects versions 5.1.2, 5.1.3 and 6.0.0.

463495

A new message suggesting to run preflight utility is displayed when required communication ports appear to be blocked.

449158

After upgrading from SAS 5.x to 6.x, systemctl was not able to stop and restart vasd service. This has been fixed.

463442

The "includedir" MIT kerberos directive in vas.conf has not been ignored by the parser correctly when there was a new line before it. Additionally, this (or any other) parser failure could cause vgptool to crash. Both problems have been fixed.

467375

Fixed an issue with vascert trigger command displaying weird error message unless the /var/opt/quest/vascert/.machinetrigger file has already been created.

469623

The libdefaults / resolve-retries configuration option has been incorrectly documented in the manual to be available at libvas / resolve-retries and has also been set on an incorrect configuration path if it had been configured with a group policy.

469034

Self Service Tools
Knowledge Base
Notifications & Alerts
Product Support
Software Downloads
Technical Documentation
User Forums
Video Tutorials
RSS Feed
Contact Us
Licensing Assistance
Technical Support
View All
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating