Chat now with support
Chat with Support

Safeguard Authentication Services 4.2.1 Common Documents - Release Notes

One Identity Authentication Services 4.2.1

One Identity Authentication Services 4.2.1

Release Notes

July 2019

These release notes provide information about the One Identity Authentication Services 4.2.1 release.

About this release

Authentication Services extends the capabilities of UNIX, Linux, and Mac systems to seamlessly and transparently join Active Directory and integrate Unix identities with Active Directory Windows accounts.

Authentication Services 4.2.1 is a minor release that includes enhancements to the Starling integration and addresses customer-reported issues. For more information see Enhancements and Resolved issues.

Supported platforms

The following table provides a list of supported Unix and Linux platforms for Authentication Services.

Table 1: Unix agent: Supported platforms

Platform

Version

Architecture

Amazon Linux AMI

 

x86_64

Apple macOS

10.12, 10.13, 10.14

x86_64

CentOS Linux

5, 6, 7, 8

Current Linux architectures: s390, s390x, PPC64, PPC64le, ia64, x86, x86_64, AARCH64

Debian

Current supported releases

x86_64, x86, AARCH64

Fedora Linux

Current supported releases

x86_64, x86, AARCH64

FreeBSD

10.x, 11.x

x32, x64

HP-UX

11.31

PA, IA-64

IBM AIX

7.1, 7.2

Power 4+

OpenSuSE

Current supported releases

x86_64, x86, AARCH64

Oracle Enterprise Linux (OEL)

5, 6, 7, 8

Current Linux architectures: s390, s390x, PPC64, PPC64le, ia64, x86, x86_64, AARCH64

Red Hat Enterprise Linux (RHEL)

5, 6, 7, 8

Current Linux architectures: s390, s390x, PPC64, PPC64le, ia64, x86, x86_64, AARCH64

Solaris

10.x, 11.x

SPARC, x64

SuSE Linux Enterprise Server (SLES)/Workstation

11, 12, 15

Current Linux architectures: s390, s390x, PPC64, PPC64le, ia64, x86, x86_64, AARCH64

Ubuntu

Current supported releases

x86_64, x86, AARCH64

Enhancements

The following is a list of enhancements implemented in Authentication Services 4.2.1.

Table 2: Starling enhancements
Enhancement Issue ID

Multiple enhancements to Starling integration, including:

  • Proxy support: Authentication Services can now be configured to use a proxy server for outbound web requests to Starling.
  • Customizable attributes: You can now specify the user mobile number and user email address attributes to be used by Starling push notifications.
  • Support for additional platforms

797136

Resolved issues

The following is a list of issues addressed in Authentication Services 4.2.1.

Table 3: API: Resolved issues
Resolved Issue Issue ID

Update jannson version, potential fix for low memory segfault.

798406

Table 4: docs: Resolved issues
Resolved Issue Issue ID

Add include-local-group-memberships to man page list.

799734

Update man page for smb-dialect-range default to correct value, '1-2.1'.

802745

Table 5: FreeBSD: Resolved issues
Resolved Issue Issue ID

Add Netgroup support to the NSS module.

793024

Table 6: krb5: Resolved issues
Resolved Issue Issue ID

Symbol name-safe more libraries in heimdal.

797137

Fix GSSAPI for third-party application integrations.

798006

Fix double password (badPwdCount) increment on single bad password.

801349

Table 7: lam: Resolved issues
Resolved Issue Issue ID

Add NSS debug (QAS_ID_(DBG|CALL)_STDERR) to the lam module.

799038

Table 8: nss: Resolved issues
Resolved Issue Issue ID

In UPM, do not respond to samaccount name requests.

800853

Table 9: osx: Resolved issues
Resolved Issue Issue ID

Fix for using autogen with mapped users on OSX.

799462

Change vasd to use the OS provided logging instead of syslog.

799674

Fix self-enrollment issue on 10.11+.

799986

Table 10: package: Resolved issues
Resolved Issue Issue ID

Remove openssl.

774875

Fix preflight zip package.

797344

Add correct packages to the AIX zip package.

797347

Remove ncurses 5 dependency from rpms.

798015

Fix symlink for ncurses on Ubuntu 19.

800452

Add symlink for libgcc_s.a to root path.

801736

Table 11: pam: Resolved issues
Resolved Issue Issue ID

Fix small memory leak in the pam module around the prompt.

802684

Table 12: Powershell: Resolved issues
Resolved Issue Issue ID

Fix query that was returning a user's UID instead of GID.

781706

Table 13: Scripts: Resolved issues
Resolved Issue Issue ID

Modify vas_oneway_setup.sh to accept spaces in containers / keytab paths.

796189

Fix install.sh to handle upgrade of dnsupdate after name change.

798241

Table 14: Smartcard: Resolved issues
Resolved Issue Issue ID

Configure pam even if pam_vas is not configured.

706419

Table 15: Starling: Resolved issues
Resolved Issue Issue ID

Add support for proxy authentications.

797684

Table 16: Status: Resolved issues
Resolved Issue Issue ID

Fix false failure on new su-l include on Ubuntu 19.

800453

Better handling and reporting for bad Starling configurations.

801436

Table 17: vas.conf: Resolved issues
Resolved Issue Issue ID

Accept both % and $ for default_cc_name. % is preferred.

801908

Table 18: vasd: Resolved issues
Resolved Issue Issue ID

On AIX, with include-local-group-memberships set, return local group memberships when returning fresh group memberships from change 655560.

791058

Change enable-nonroot-disconnected-cache default to false. This setting is deprecated and will be removed at a future date.

793590

Clear out old srvinfo records during realmscache-sync-interval.

794218

Throttle socket file creation attempts.

794631

Fix error message about VGP versions when VGP is not installed.

795705

Make correct host.keytab alias entries, even if arcfour entries are removed.

799987

Fix access control forced processing every 30 seconds if there was a file in /etc/opt/quest/vas/access.d that did not end in .allow / .deny.

801076

Add urandom to allowed write of vasd_t in the SELinux policy.

801430

Table 19: vastool: Resolved issues
Resolved Issue Issue ID

Fix issue where vastool configure [extra-]realm removed default_etypes under some situations.

762605

Fix issue with configuring pam.d/* files when only one entry has an include style line.

787558

Allow 'vastool configure pam' to configure the authorization service.

790635

vastool configure [extra-]realm will now fill out multiple kdcs in the multi-line format.

797425

Handle SIGWINCH signal (window resize) during password prompt.

798226

During join with -U/-G, check for attributes in GC. Also test for in vastool status.

799032

When running status, unset wrapper library paths.

801737

Table 20: vasypd: Resolved issues
Resolved Issue Issue ID

Allow x.x.x.0 as a valid IP address in client-addrs.

796696

Table 21: vgp: Resolved issues
Resolved Issue Issue ID

Do not restart syslog each time a policy is applied if nothing changed.

795030

Table 22: Windows: Resolved issues
Resolved Issue Issue ID

Add new GUID class for Active Roles Server 7.3.

790013

Fix Control Central failure on startup when the Internet is unreachable.

798589

Do not fail to open the Control Center when there are unknown attributes in the QAC schema container.

800254

 

Self Service Tools
Knowledge Base
Notifications & Alerts
Product Support
Software Downloads
Technical Documentation
User Forums
Video Tutorials
RSS Feed
Contact Us
Licensing Assistance
Technical Support
View All
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating