******************************************************************************** Product brand: Secomea Version: 11.9.626364010 Release type: Release ******************************************************************************** ================================================================================ GateManager 8250 Server ================================================================================ -------------------------------------------------- New features and enhancements: -------------------------------------------------- RD-7654: Adding the ability to bypass the in-browser GTA login prompt. Previously, GateManager decided on its own whether to show the in-browser GTA credentials entry dialog: it was hidden for agents pre-configured with credentials and shown for agents that weren't. Now this behavior is configurable per agent in SiteManager and overridable per connection via /crm/goto/agent. RD-7986: Deep links to GM from Prime. Endpoint /crm/login/account now accepts an optional landing_object parameter. Generated login link opens then directly on a specific domain, agent, or appliance instead of the default view. RD-8005: Add lightbulb for remote audit log server. Add lightbulb information to the following configuration parameters under the Web Services & Debug Console page for Remote Audit Log Server and Advanced Log Server. RD-8017: Add "gating" to "Credentials Prompt" and "Security" and enable "Security" for "Generic Remote Desktop (RDP)" agents. * The "Credentials Prompt" dropdown is now shown only for in-browser VNC and RDP agents, which are the only agent types it applies to. * The "Security" dropdown is now also available for "Generic Remote Desktop (RDP)" agents, and is likewise shown only where it applies. * The "Security" dropdown is no longer marked mandatory, since a dropdown always has a value. RD-8024: Audit logging of opening cust/dist domain can be bypassed. Hardened auditing customer domain entry by higher-level admins. RD-8051: Implement support for external in-browser GTA connections. An external front-end can now serve and drive its own in-browser Guacamole client instead of using the one built into GateManager. * {{/crm/goto/agent}} accepts {{'app':'extbrowser'}} and returns a ready-to- use {{wss://}} link with the secret embedded, together with a {{session}} code and a {{query}} flag string saying which credential fields the caller should collect. * {{'prompt':'true'}} forces the credentials form to be shown, {{'prompt':'false'}} skips it. * {{username}} and {{password}} may be supplied in the request. They are honoured only for in-browser (guacd) targets; for any other target the request is now rejected instead of the credentials being silently ignored. * Echoing the returned {{session}} code on a second request re-uses the same connection rather than opening a new one. * {{GET /crm/info}} now reports {{guacd-version}}, so the front-end can load a matching guacamole-common-js. RD-8127: In-browser VNC credentials form must allow entering a user name. Previously, the in-browser credentials dialog for a VNC service offered a password field only, so a VNC server that requires a user name could not be reached unless the credentials were already configured on the agent. The dialog now offers a user name field for VNC as well. -------------------------------------------------- Bug fixes: -------------------------------------------------- RD-7188: Domain import fails. Importing domain from file bigger than 1MB was failing. This has been fixed. RD-7326: Accounts joined using Advanced Groups can't delete or move domains in the domain tree. In the domain tree, a domain administrator who reached a domain only through an Advanced Group could not move or delete its subdomains: moving appeared to work and reverted on the next refresh, and deleting did nothing at all. This has been fixed. RD-7762: When connecting to GUACD, only look for "domain" parameter in "username" if session is RDP. User names containing a backslash now work for in-browser SSH, VNC and telnet sessions; only RDP still reads them as {{DOMAIN\user}} RD-7763: GTA RDP button doesn't show when using the In-browser GTA agent type. Fixed missing RDP button in GateManager when using the dedicated "In-browser GTA" agent types (RDP, VNC, SSH, Telnet). Previously, only the workaround of using a Generic agent with the in-browser viewer toggle produced a working button. Requires SiteManager firmware update. RD-7915: Incorrect usage statistics displayed in GM usage panel. Improved accuracy of connection time reporting in usage statistics for dynamic port-based GtA services (SSH, VNC, RDP). The server idle timer is now reduced immediately after a connection is established, preventing inflated connection times. The post-connection timeout is configurable via ui_server_post_connect_close_timeout in the config file (default: 25 seconds). RD-7923: CRM API activity stats, doesnt match. There was an issue with incorrect output of tx_bytes returned from /crm/info/activity endpoint. This has been fixed. RD-7932: Report generation stopped including new data. * Fixed an issue where monthly Usage reports generated on the 1st of the month would be incomplete — missing connections from that day and sometimes the last day of the previous month. Monthly reports now correctly include all expected data regardless of when you run them. * Added "Previous month" option to make it easy to generate reports for the complete previous month. * !! Behavior change: Reports set to "This month" now show just the current day when run on the 1st (instead of the full previous month). If you want the full previous month, switch those reports to "Previous month." RD-7958: Creating account with special character in account name fails using CRM API. Creating an account whose name contained non-ASCII characters failed through the CRM API although the same name was accepted in the web interface. This has been fixed. Signing in through an identity provider for the first time now creates the account only if the user name satisfies the same rules as accounts created by an administrator. A user name longer than 63 bytes is refused, instead of being silently shortened. RD-7969: Stack Buffer Overflow in add_relay_net(). Fixes a security vulnerability where specially crafted relay network configuration values could crash the Gatemanager. RD-8016: If an agent is configured with a password of 122+ characters, the password is silently corrupted and GateManager receives wrong password. An agent password of 122 or more characters was silently corrupted, so GateManager received a wrong password. This has been fixed - agent credentials are now limited to 255 characters per field and over-long values are rejected at entry. RD-8022: Groups disabled and unexpected "Advanced Groups license revoked" audit message when updating a customer domain. GateManager could incorrectly disable Advanced Groups (logging 'Advanced Group license revoked') when saving a customer domain whose Advanced Groups checkbox was hidden. This has been fixed. RD-8025: On private servers customer domain feature flags are stored and reported as disabled via the CRM API even though the licenses are present. On private servers, GateManager would incorrectly reset the default feature flags for customer domains. This has been fixed. RD-8026: RFA user can't see the Requests on the GM. A domain's configured Grant Access Account did not see the access requests it was responsible for approving: its Access Requests page was empty, while accounts that were not the approver could see those requests. Approving from the notification email was unaffected throughout. This has been fixed. RD-8027: User creation upercase domain. Uppercase, email style usernames are now accepted. RD-8037: Fix opening domain in new tab when loadForceUtcPrefs failed. Opening domain in new tab lead to blank page in some cases. This has been fixed. RD-8065: /crm/login/account fails when timezone is offset with negative value. CRM API now correctly recognizes a plain negative integers. RD-8120: Upload forms in Files > Public, Shares and per-agent Shared Files are destroyed by a panel reload on visibilitychange. An open file upload form in the GateManager web GUI was destroyed, along with the selected file, when the browser tab was switched away and back or the file picker was closed. This has been fixed. RD-8132: CRM API rejects the short grant-id form when the target is an appliance or an agent. /crm/get/grant refused the short grant-id form with "400 malformed" whenever the target was given as an appliance or an agent, so only a domain target worked. This has been fixed. RD-8133: CRM API stores response_type 0 as a character, so it reports 1 and notifies the requester anyway. A grant created over the CRM API with response_type 0, meaning no notification, was stored as though email notification had been requested. It was reported back as 1, and the requester was sent a message when the request was answered from the GateManager interface or from the emailed approve link. This has been fixed. RD-8134: CRM API refuses a group id in the account filter although it reports one. When a group was configured as a domain's Grant Access Account, /crm/get/domain reported the group's id as an account id. A client that read a domain's configuration and wrote it back could therefore repoint the approver at an unrelated account. This has been fixed. The API specification now also documents how to expand a group approver into its member accounts. RD-8139: An access request raised from a domain ABOVE the Grant Access Account is emailed to the approver but never shown on its Access Requests page. An access request raised by an account in a domain above the one carrying the Grant Access Account setting was accepted and the approver was notified by email, but the request never appeared on the approver's Access Requests page. This has been fixed. -------------------------------------------------- Security advisories: -------------------------------------------------- To be announced. -------------------------------------------------------------------------------- Upgrade instructions can be found here: https://kb.secomea.com/docs/upgrade-gatemanager-firmware -------------------------------------------------------------------------------- ================================================================================ SiteManager and SiteManager Embedded ================================================================================ -------------------------------------------------- New features and enhancements: -------------------------------------------------- RD-8004: Update agent name. The QuickPanel Pro agent has been renamed to QuickPanel+2. RD-8079: Stable/configurable LAN/WAN interface settings. Previously the internal interface was picked according to an internal heuristic or configurable using a static IP address. A third option based on the interface name has been added. RD-8117: SME server relay UI interface selection. Server Relays on SiteManager Embedded now have an Interface selector, matching the one already available on SiteManager. It constrains which interface connections are accepted from, and takes precedence over any address information in the Server Virtual Address field. The default, Auto, preserves the previous behaviour. -------------------------------------------------- Bug fixes: -------------------------------------------------- RD-7395: DCM MQTT data server reconnection issue. When a SiteManager lost its internet connection, DCM stopped trying to reach the MQTT broker after a fixed number of attempts, about five minutes' worth, and did not try again. If connectivity returned later, the data server stayed disconnected until DCM was restarted. DCM now keeps retrying indefinitely, at increasing intervals, so the connection recovers on its own once the SiteManager is back online. RD-7471: Static routing between DEV and UPLINK stops working. There was an issue where static routing between the DEV and UPLINK interfaces would stop working. This has been fixed. RD-7827: DCM certificate contents are altered after being opened. Opening and re-saving a DCM external key or certificate could leave carriage return characters in its contents. The characters were then sent as part of the tenant id and device name when authenticating against a Cumulocity data server, and authentication failed. Carriage returns are now removed from the certificate before it is used. RD-7906: Issue with WiFi Access Point mode for SM xx49. SiteManager FW version 11.7 introduced a regression that broke Wi-Fi Acces Point mode. This has been fixed. RD-7973: Generic GTA agent always uses default screen resolution. * "Keyboard Layout", "Screen Width" and "Screen Height" are disabled in the Generic RDP agent (if the 'in-browser' checkbox is unchecked). RD-8069: NTP & Email relay behavior. The timeout behaviour of UDP relays differs from the timeout of TCP relays. The documentation has been updated to reflect this. RD-8157: An MQTT or AWS/MQTT dataserver can silently stop delivering data after a broker disconnect, or crash: it reconnects from two threads and never confirms that the broker accepted the connection. An MQTT or AWS/MQTT data server could stop delivering data after losing its connection to the broker, either by stopping unexpectedly or by continuing to run while silently failing to deliver, and it did not resume until the DCM or the appliance was restarted. This has been fixed. -------------------------------------------------- Security advisories: -------------------------------------------------- RD-8149: Pending. -------------------------------------------------------------------------------- Upgrade instructions can be found here: https://kb.secomea.com/docs/en/upgrade-sitemanager-firmware -------------------------------------------------------------------------------- ================================================================================ LinkManager Windows Client ================================================================================ -------------------------------------------------- New features and enhancements: -------------------------------------------------- - -------------------------------------------------- Bug fixes: -------------------------------------------------- - -------------------------------------------------- Security advisories: -------------------------------------------------- - -------------------------------------------------------------------------------- Upgrade instructions can be found here: https://kb.secomea.com/docs/en/upgrading-linkmanager-to-the-newest-version -------------------------------------------------------------------------------- ******************************************************************************** End ********************************************************************************