Release Notes
This page contains release notes for the latest stable releases and release notes for:
-
Long-Term Support (LTS) versions: Past releases that continue to receive bug fixes and critical updates.
-
Legacy Long-Term Support (LLTS) versions: Past releases that receive critical updates.
This page contains information about the new developments and improvements made to Imprivata's Privileged Access Security (PAS) platforms. You can also find bug fixes and release notes to previous versions.
26.1.9 and corresponding LTS releases (25.2.9 and 24.3.9) for Privileged Access are now generally available. This release introduces the new Reports offering in VPAM and CPAM, the ability to create custom scripts, RDP converter improvements, introduces built-in clients for SQL databases, as well as many more improvements and fixes.
Privileged Access introduces custom script management, a new capability that lets authorized administrators create, manage, and run their own PowerShell and Bash/SSH scripts directly within the platform. Scripts reference Privileged Access-managed credentials through runtime variable placeholders for values such as username, password, and SSH keys, so sensitive data is injected at execution time rather than hard-coded. Custom scripts can be run on demand or on a schedule against target hosts through the existing gateway execution model, while the built-in scripts for tasks like password and key rotation remain read-only.
Custom script management moves customers beyond the previous fixed set of predefined operations, letting teams automate their own operational work, such as compliance reporting, provisioning, integrations, and routine maintenance, without embedding credentials in external tools or scripts. Because scripts draw credentials securely from Privileged Access at runtime, organizations can extend automation across their environment while keeping secrets protected and centrally governed. Administrators can enable the capability and grant it selectively to users with the appropriate permissions, keeping control over who can author and execute automation.
Other enhancements and updates for this release are:
The following bugs where fixed for this release:
Latest Releases
Navigate our previous release notes.
26.1.8 and corresponding LTS releases (25.2.8 and 24.3.8) for Privileged Access are now generally available. This release introduces new capabilities for personal credential management, emergency break-glass access, legacy credential migration to the new Secret Vault, and expanded database credential injection with PostgreSQL support, along with improvements for overall usability across the Privileged Access products.
Please note, this feature is only available for our PAM customers and VPAM customers with an additional PAM License.
Privileged Access introduces Personal Secrets, a new secret scope that allows internal users to privately store and manage their own credentials, including passwords and SSH keys, directly within the platform. Personal secrets are owned exclusively by the individual user, bypass approval and checkout workflows, and can optionally be selected at service connect time for brokered sessions. Administrators retain read-only visibility into the organization-wide inventory of personal secrets without access to sensitive values.
Personal Secrets give individual users a secure, private space to manage their own credentials within Privileged Access, eliminating the need to store passwords in external tools or unsecured locations. By integrating personal credential storage directly into the platform, organizations can extend their security posture to cover individually-managed credentials while maintaining administrative oversight without compromising user privacy.
Please note, this feature is only available for our PAM customers and VPAM customers with an additional PAM License.
The Break-Glass Client is a standalone command-line tool that allows authorized operators to access secrets stored in the PAS server during emergency scenarios where normal system access is unavailable. The client periodically syncs and stores secrets in a locally encrypted cache, enabling credential retrieval even when connectivity to the PAS server is interrupted. All retrieval operations are audit logged, and sensitive values are never persisted in plaintext.
In outage or emergency scenarios where the PAS server is unreachable, the Break-Glass Client ensures that authorized operators can still retrieve the credentials needed to restore systems and respond to incidents. By providing a secure, audited offline access path, organizations can maintain operational continuity without compromising security controls or resorting to insecure workarounds.
Privileged Access now provides a migration path that allows administrators to convert existing Legacy UI Global Credentials into Secrets in the new UI Secret Vault. This enables organizations to transition their full credential inventory to the modern secret management experience without manually recreating entries or disrupting existing workflows.
As the platform evolves toward the new UI, this migration path allows customers to carry their existing credential library into the modern Secret Vault without data loss or administrative overhead. Organizations can take advantage of improved visibility, access controls, and auditing in the new UI while preserving the credentials they already rely on.
Read more about Credential Migration.
Other enhancements and updates for this release are:
-
Desktop Sharing service audit files are now displayed in the History table. (26.1.8)
-
Added rate limiting to some endpoints that did not previously have rate limits. (26.1.8)
-
When browser-based connections are enabled, the option to launch with HTML5 now appears as a button instead of a link. (26.1.8)
-
All of the S3 Configuration and Storage settings appear in the UI without needing to enable them individually on the backend. (26.1.8)
-
PAM Configurations that have active credential dependencies can no longer be deleted. (26.1.8)
-
Resolved an issue where the Test Connection function on the PAM Server Configuration page failed with a certificate validation error when the PAM server used a custom certificate authority, even after the full certificate chain had been uploaded and saved. This is not new functionality but it's important to call out this was released to the LTS version 25.2.8 (26.1.8)
The following bugs where fixed for this release:
-
Resolved an issue where clicking a password reset link from email failed to complete the password reset process. (25.2.8 | 26.1.7.1 | 26.1.8)
-
Resolved an issue in the Role editor where selecting "Apply these departments to all permissions" did not correctly apply the department assignment to all permissions. (25.2.8 | 26.1.8)
-
Resolved an issue where HTTP credential injection failed with an SSL handshake error when audit logging was enabled. (26.1.8)
-
Resolved an issue where the Quick Connect User Group was not visible under User Management > User Groups in the new UI. (26.1.8)
-
Resolved an issue where enabling "Allow access to all Gatekeepers" for a user did not automatically grant access to newly created Gateway-hosted Gatekeepers. (25.2.8 | 26.1.8)
-
Resolved an issue where RDP session audit recordings were unavailable due to the audit file conversion process generating empty output files.
-
Resolved an issue where importing an application from VPAM into CPAM failed when the application description exceeded 128 characters. (24.3.8 | 25.2.8 | 26.1.8)
-
Resolved an issue where SAML SSO users who started in the new UI were redirected to the legacy UI to complete email-based two-factor authentication. (26.1.8)
-
Resolved an issue where service access events were not sent to syslog when a service was launched without an injected credential. (25.2.8 | 26.1.6)
-
Resolved an issue where system messages edited in the new UI were not reflected in the legacy UI. (25.2.8 | 26.1.8 | 26.1.9)
-
Resolved an issue where UCM failed to display a connection error when outbound port 22 was blocked, causing service launches to appear successful but hang indefinitely. (2025.12.7-universal-scm)
-
Resolved an issue where a Gatekeeper's version file could be written with an invalid value, causing the server to repeatedly offer the same Gatekeeper upgrade. (2025.12.7 | 2026.8.0)
-
Resolved an issue where Gatekeeper reconnect cycles could spawn multiple concurrent polling threads, causing authentication failures and excessive server polling. (2024.12.10 | 2025.12.7 | 2026.7.0)
26.1.7 and corresponding LTS releases (25.2.7 and 24.3.7) for Privileged Access are now generally available. This release introduces a refreshed CPAM user experience, secure break-glass access to critical credentials during outages, personal vaults for user-managed privileged secrets, and automatic redirection from rebuilt legacy VPAM pages to the new interface. Together, these updates help organizations improve business continuity, strengthen credential security, simplify user workflows, and continue the transition toward a more modern and consistent Privileged Access experience.
Please note, this feature is only available for our PAM customers and VPAM customers with an additional PAM License.
Privileged Access now supports Break-Glass Emergency Credential Access, providing organizations with a secure method for accessing critical credentials during planned or unplanned outages. Authorized administrators can retrieve synchronized credential information from an encrypted local cache when access to the primary Privileged Access platform is unavailable, ensuring business continuity during emergency situations.
Organizations depend on privileged credentials to maintain and recover critical systems during outages and disaster recovery events. Break-Glass Emergency Credential Access helps reduce operational risk by ensuring authorized personnel can access the credentials they need while maintaining strong security controls, encryption, and auditability.
Please note, this feature is only available for our PAM customers and VPAM customers with an additional PAM License.
The Personal Vault is a per-user secure storage space within Imprivata Privileged Access where individual users can create, store, and manage their own secrets, such as credentials, keys, and login records, separately from shared or corporate vaults. Each authenticated user is automatically provided a Personal Vault, giving them ownership and control over their personal privileged assets while keeping those items organized outside the global vault. This is a PAM-only feature and will not appear for VPAM users.
Personal Vaults help users securely manage privileged credentials that are specific to their own work without cluttering shared vaults or increasing the risk of accidental exposure. By giving users a dedicated, encrypted space for personal secrets, organizations can improve credential hygiene, reduce password fatigue, and support faster access through browser extension workflows. Administrators and auditors can still retain appropriate oversight where required, helping balance user productivity with security and compliance needs.
Other enhancements and updates for this release are:
-
Self-Service Face Biometrics Enrollment enables users and vendor representatives to enroll their Face Biometrics directly from My Account → Authentication Methods. This enhancement provides a centralized, self-service experience for managing biometric authentication, allowing users to proactively prepare for adaptive authentication requirements without waiting for an enrollment prompt
-
The Python SDK has been updated to use the native librssconnect connectivity library for launching remote services. This enhancement applies to the SDK's Connect module while preserving the existing Python SDK API and client contracts. The updated connectivity layer supports launching standard remote services—including SSH, SFTP, FTP, RDP, VNC, and Telnet—across supported Windows, Linux, and macOS platforms.
-
Improvement were made to Enhanced LDAP Authentication Logging that provides visibility of LDAP authentication failures by providing more descriptive server and administrative log messages. Administrators can now more easily identify the cause of authentication issues, reducing troubleshooting time and helping distinguish between user credential problems and LDAP integration issues.
-
This release offers and improvement for Gateway Administrative Activity Logging that provides auditing capabilities by recording Gateway lifecycle events in the Administrative Log.
-
Improved error messages to be more informative on EntraID Authentication workflows.
-
Time zone clarification / help text was added to relevant screens so users can see what their server time zone is and if it differs from the time zone they are currently in.
-
Improvements were made to the Discovery feature.
-
Improvements were made to the Admin Log error codes to be more specific with authentication failures.
-
Reworked the DNS Proxy into the Transparent Proxy so it can be enabled alongside other VPN solutions.
-
Resolved an issue where Gatekeepers were unregistering.
-
Resolved an issue with getting an error during registration when using the long registration key.
-
Resolved and issue on the 'Test Connection' button on the PAM Integrations page.
26.1.6 and corresponding LTS releases (25.2.6 and 24.3.6) for Privileged Access are now generally available. This release introduces new capabilities for cross-platform remote access, just-in-time privilege elevation, built-in SQL database connectivity, and enhanced multi-factor authentication controls for Nexus connections. In addition, the release includes improvements to auditing, identity and access management workflows, credential management, and overall platform security and usability.
Privileged Access now extends Imprivata Desktop Sharing to Linux and macOS, and macOS for QuickConnect, bringing the same native desktop sharing experience previously available on Windows to additional operating systems. This release includes native Linux and macOS desktop sharing clients, support for desktop sharing through Linux Gatekeepers, and updated portal labels that clearly distinguish the native client from the legacy Java-based option. Users can launch desktop sharing sessions without requiring Java, while organizations benefit from a more consistent experience across supported platforms.
This enhancement expands native desktop sharing capabilities across Windows, Linux, and macOS environments, helping organizations standardize their remote support workflows. By reducing dependence on Java and providing a unified cross-platform experience, users can connect more easily while administrators gain greater flexibility in mixed-OS environments.
Please note, this feature is only available for our PAM customers and VPAM customers with an additional PAM License.
Privileged Access now supports Just-in-Time (JIT) Privilege Elevation for Active Directory accounts, allowing users to request temporary elevated permissions on application connection, only when needed. Organizations can configure approval workflows that grant elevated access for a limited period, enabling users to perform privileged tasks without requiring permanent administrative privileges. Once the approved session ends or the approved access window expires, elevated permissions are automatically revoked.
Just-in-Time Privilege Elevation helps organizations reduce security risk by limiting privileged access to approved users, approved systems, and approved timeframes. By replacing standing administrative access with temporary elevation, organizations can better enforce least-privilege principles while maintaining the oversight and auditability required for security and compliance initiatives.
This release introduces built-in SQL database clients that allow users to launch database connections directly from the platform. This release introduces dedicated service types for MySQL, PostgreSQL, and Microsoft SQL Server, establishing a foundation for database-specific connection workflows. Initial support includes a fully integrated MySQL experience with credential injection and database activity auditing, while PostgreSQL and Microsoft SQL Server support are being expanded in future releases.
Built-in database clients simplify access to critical database resources by providing a more streamlined experience directly within PAS. Organizations can improve visibility into database activity through auditing capabilities while reducing the need for users to manually configure external tools and connection workflows.
Imprivata Privileged Access introduces in-application guidance designed to deliver relevant product information directly within the user experience. The initial release will include a simple Help center in the bottom right corner of the screen that links to Help Docs, Support, and Webinar events. Future releases will include contextual messages that provide feature announcements, onboarding assistance, release updates, and product guidance within the workflows where users are already working, making it easier to discover and adopt available capabilities.
By receiving information when and where it's most relevant, users can stay informed about new functionality, quickly identify features that support their objectives, and incorporate product enhancements into their daily workflows with less disruption. This approach also reduces the need to monitor separate communications, helping teams stay focused while ensuring they have access to the information they need to be successful.
Other enhancements and updates for this release are:
-
Improved the Syslog output to include service access events and credential usage which provides a more complete record of privileged service access in User Activity logs and syslog, helping customers monitor and prove who accessed which services and when.
-
Validations were added to the SAML metadata upload setup. If the metadata file is incomplete, malformed, missing required SSO elements, or contains placeholder values, the upload is rejected with clear error messages and the existing SAML configuration remains unchanged.
-
Improvements were made to the Audit Log to include entries when a user login is blocked because the request comes from outside the organization’s configured Authorized Networks.
-
Improvements were made to the External Credential Providers. Administrators can now assign External Credential Providers to connection ports through the new UI and validate those assignments before saving. This allows administrators to use externally managed credentials in port configuration workflows while ensuring that providers are authorized for the administrator’s scope and compatible with the selected connection type.
-
Improvements were made to the Credential Pool state-tracking. When an SDK client disconnects without properly closing a service, associated pooled secrets are now released so they can be used by subsequent users. Credential Pool inventory is also kept current when administrators add or remove secrets or delete pool providers, preventing stale in-memory state from affecting availability.
-
Resolved an issue with the Send Password Reset workflow.
-
Resolved an issue that prevented credentials from being added to a host service when an external (PAM) credential was previously assigned.
-
Resolved an issue where the View Session link under a gateway was not working.
-
Resolve an issue where Microsoft SmartScreen incorrectly identified the Connection Manager as unsigned.
26.1.5 and corresponding LTS releases (25.2.5 and 24.3.5) for Privileged Access are now generally available. This release introduces additional features and workflows added to the Identity Assurance & Threat Detection offering, improvements to Nexus configuration settings, improvements to our MFA configuration settings, and many more improvements.
Other enhancements and updates for this release are:
-
Users who have an assigned Secret Category can now access secrets in their assigned category, as well as uncategorized secrets.
-
The fonts on customer notes were improved to be more distinguishable in the UI.
-
RDP sessions with multiple monitors can now move the RDP session between screens and enable full screen view.
-
Resolved an issue where Desktop Sharing failed to establish desktop sharing sessions in multi-monitor environments with high aggregate resolutions.
-
Resolved an issue where an error was thrown when adding an external credential provider (external PAM provider) and Secrets to the same host service.
-
Resolved an issue that allowed users to grant application access for longer periods than permitted by the server configuration.
-
Resolved an issue where users received an error when attempting to use the Reset Password link on the login page.
-
Resolved an issue where users received an error when adding a custom service profile to an application.
-
Resolved an issue where the My Recent Sessions table did not display all relevant sessions.
-
Resolved an issue where HTTP tunnels failed on the connection manager.
-
Resolved an issue where virtual channels on RSS RDP caused the client to crash.
-
Resolved an issue where valid SSL certificates were identified as invalid.
-
Resolved an issue where clicking Start Conversion on RDP video audits did not work for Gatekeeper Administrators.
-
Resolved an issue where Gatekeeper Connectivity Test results were inconsistent with actual connectivity.
-
Resolved an issue where the access expiration warning banner did not display for vendor reps in the new UI.
-
Resolved an issue where certain RDP host security configurations caused the service to fail.
26.1.4 and corresponding LTS releases (25.2.4 and 24.3.4) are now generally available. This release introduces Agentic Identities, Identity Assurance and Threat Detection (IATD), expanding Privileged Access with adaptive, risk-based authentication, continuous identity evaluation, and new biometric MFA capabilities, including facial authentication for both internal users and third-party vendors.
In addition, this release enhances visibility and control across the credential lifecycle with expanded Accounts Discovery and Secrets Import capabilities, enabling organizations to identify, onboard, and manage previously unmanaged accounts with minimal disruption. Updates to the Secrets Vault, including expanded Secret Categories across all secret types, provide more flexible and granular least-privilege access controls are also included, along with several other improvements.
Please note, this feature is only available for our PAM customers and VPAM customers with an additional PAM License.
Accounts Discovery enables customers to identify and onboard operating system–level accounts across their environment into the Privileged Access vault. Customers can choose to discover all accounts or focus only on privileged accounts, making it easier to bring unmanaged credentials under control without manual effort. The system securely connects to known hosts, discovers and consolidates accounts, and presents a curated list for selective import as secrets. During onboarding, administrators can assign a password or use a default value for managed access, without modifying the credentials on the target system, while retaining control over how accounts are mapped to services and access workflows.
This gives customers immediate visibility into unmanaged and potentially high-risk accounts, eliminating blind spots across their infrastructure. It supports a phased approach to credential onboarding while reducing reliance on manual inventory processes. By centralizing discovered accounts into the vault, customers strengthen control and auditability over credential usage and lifecycle, while ensuring operational continuity by avoiding disruption to active user sessions during credential onboarding.
Other enhancements and updates for this release are:
-
Secret Categories are now available across all secret types, extending beyond their previous use with Secret Pools to provide a more consistent and scalable way to manage access. Acting as flexible tags, categories can be assigned to both secrets and users or vendors, enabling access only when there is a defined match between them. This enhancement strengthens least-privilege access controls by giving administrators a more precise and efficient way to segment and restrict sensitive credentials.
-
Improved SSH connector to dynamically detect sudo password prompts and inject credentials as needed in the SSH Key rotation task.
-
Secret Scopes can now be applied to Secret Pools.
-
Take advantage of the Imprivata Learning Center, which is now available within the Help Menu.
-
Improved error messaging for secret checkout by providing clearer, distinct errors for access expiration and for on-demand tasks blocked by active check-outs.
-
Improvements were added to the IP Range Discovery Task workflow to enhance the user's experience when managing the results of that scan.
-
We now support Remote Desktop Services for Azure Active Directory for RDP Credentials when connecting to Azure domain joined hosts.
-
HTTP credential injection now supports Basic Authentication.
-
Resolved an issue with downloading and converting audit data.
-
Error messages were improved to provide more context and actionable steps if an issue is experienced during connections.
-
Resolved an issue where Approval Notification Emails were triggered with no active requests.
-
Resolved an issue with incorrect time stamps appearing on Access Requests.
-
Resolved an issue where the Modify action was not appearing in the Active Request table.
-
Resolved an issue with adding 25+ user groups to an API key.
26.1.3 and corresponding LTS releases (25.2.3 and 24.3.3) are now generally available.
Other enhancements and updates for this release are:
-
Improved the connection process to not allow users to launch a second instance of the Connection Manager, which reduces the amount of Invalid SSH Key errors seen.
-
Resolved an issue where some of the Gatekeeper Services were not available post-upgrade.
-
Resolved an issue so that users are directed to the proper landing page-post login.
-
Resolved an issue where an incorrect error was appearing in RPD sessions.
-
Resolved an issue that prevented RDP from launching.
-
Resolved an audit conversion issue.
-
Resolved an issue where users were experiencing errors when logging in using an SSO method.
-
Resolved an issue where active session count was incorrectly displayed on pooled gateway sessions.
26.1.2 and corresponding LTS releases (25.2.2 and 24.3.2) are now generally available. This release delivers a new report that has been requested by many customers, expanded rotation capabilities for our job manager, improvements to the Gatekeeper, and new system settings in the VPAM New UI.
Other enhancements and updates for this release are:
-
Secret Scope selection is now a required field when creating new secrets.
-
Resolved an issue where switching between the new and legacy UI resulted in an invalid token error.
-
Resolved an issue with the vendor rep self-registration workflow.
-
Resolved an issue where Mac users could not connect.
-
Resolved an issue with inconsistent RDP Audit download between the legacy connection manager and the new connection manager.
-
RDP session will no longer time out if audit limit was reached.
-
Resolved an issue where vendor messages could not be edited.
26.1.1 and corresponding LTS releases (25.2.1 and 24.3.1) are now generally available. This release delivers a new report that has been requested by many customers, expanded rotation capabilities for our job manager, improvements to the Gatekeeper, and new system settings in the VPAM New UI.
-
Added functionality to allow users to rotate Unix SSH Key secrets.
-
Custom UserIDs for API Key users are now supported.
-
Resolved an issue where Connection Manager mappings were not being cleared correctly on session disconnect.
-
Resolved an issue where the Connection Manager was not accepting special characters in UserIDs. Special characters are now accepted, with the exception of #.
2025 Release Notes
25.1.12 and corresponding LTS releases (24.2.12 and 23.3.5) are now generally available. This release delivers major PAM on PAS enhancements to privileged access workflows, including Discovery tasks, Secret Credential Pools, and Exclusive Secret Checkout to improve security and operational control. It also includes RDP performance and reliability improvements, VNC audit conversion support, and a set of usability and stability improvements to the connection manager, along with additional fixes and refinements.
Other enhancements and updates for this release are:
-
VNC audit conversion now happens server-side and no longer requires downloading and running additional components in order to access VNC/desktop sharing audit.
-
We've added a rule to enforce an 'only one instance per user' rule for the connection manager.
-
Improvements were made to error messages to make them more intuitive for the end user.
-
Improvements were made to the connection manager for launching custom clients.
-
Resolved a login issue that was causing users from outside an authorized network to receive errors instead of the configured additional MFA check.
-
Resolved an issue that was causing an interruption for the Connection Manager, impacting both regular connections and Nexus connections.
-
Resolved an issue where some new user permissions were not appearing on certain servers.
-
Resolved an issue where users were receiving 'unauthorized' errors after logging in.
25.1.11 and corresponding LTS releases (24.2.11 and 23.3.5) are now generally available. This release introduces a highly requested customer feature, User Group Secret Scopes, configuration improvements to our new browser-based connectivity feature, and other fixes and improvements.
Administrators, and users who manage credentials, now have the ability to scope down access to sensitive credentials based on User Group assignment. Assigning a Secret to a specific User Group allows administrators to provision access more stringently by only allowing specific users to create, view, and manage Secrets.
Implementing a way for administrators to tighten down access controls provides better security hygiene by eliminating exposure of sensitive credentials to users who don't need that level of access, and it aligns with regulatory and cyber insurance requirements by providing audit trails and proof of following a least-privilege model. This new option gives users a way to give/revoke access to certain secrets, by either granting general access via permissions, or by scoping down the secret itself so that only certain users within a user group can manage secrets.
Other enhancements and updates for this release are:
-
Added support for additional SSH key types for SSH Audit.
-
Improvements to Plugin management were made so that when a user installs a new version of an already existing plugin, all existing configurations are automatically migrated to the new version.
-
Made an improvement to our end user's experience with using CyberArk credentials so that responses are case sensitive.
-
Resolved an issue where the BeyondTrust plugin was ignoring SSL Certificate configuration options.
-
Resolved a credential error on product startup.
-
Resolved an issue with the password reset workflow.
-
Resolved an issue with IPConnect and host name mapping with a host set to 'Launch via Host Name'.
25.1.10 and corresponding LTS releases (24.2.10 and 23.3.5) are now generally available. This release introduces a major technical improvement with Device Posturing, as well as other improvements and bug fixes.
We’ve added new UI controls to the Device Certificate configuration screen that lets administrators enable, disable, and adjust device posture checks directly. These controls manage both Active Directory Certificate Service (ADCS) validation and Posture/Safety Checks, ensuring that connections are only allowed from trusted machines with valid client certificates and compliant security settings (like up-to-date antivirus and firewall).
This update gives administrators full self-service control over security configurations without needing Imprivata assistance, while also improving overall system protection. By enforcing posture and certificate validation at the device level, it limits attack exposure and ensures that both the machine and the user are properly authenticated before access is granted.
The UI controllers are only in the Legacy UI and will be added to the new VPAM UI when that system settings page is built.
Other enhancements and updates for this release are:
-
Imprivata now automatically update Azure Entra ID (formerly Azure AD) SAML signing certificates during key rollovers, eliminating manual intervention. The system also supports multiple active certificates to ensure uninterrupted SSO authentication.
-
Imprivata now support additional Syslog protocols, including RFC 3164 and RFC 5425 (TLS over TCP), alongside the existing RFC 5424 (UDP) implementation. This enhancement enables more secure, flexible, and standards-compliant event logging across varied network environments.
-
We've added OAuth 2.0 support for SMTP so customers can authenticate securely with Microsoft 365.
-
Improvements were made to the process of syncing Gatekeeper hosts from the Nexus.
-
Resolved an issue where customers were unable to connect to XenApp service.
-
Resolved an issue where users were experiencing errors when logging in using an SSO method.
-
Resolved an issue with Reports V2 where an invalid sort was causing an error.
25.1.9 and corresponding LTS releases (24.2.9 and 23.3.6) are now generally available. This release introduces new major functionality for the PAS platforming initiative with browser-based connectivity, in-browser audit playback, new expansions for our Best Practices Checklist, as well as additional enhancements and fixes.
Before this release, ImprivataPrivileged Access Security (PAS) products supported best practices checks for HIPAA, PCI, NERC, and CJIS standards. This release offers users to enable a set of checks against NIST (National Institute of Standards and Technologies) to ensure their organization meets the controls and recommendations suggested by that regulatory entity.
Adding this standardization to our toolbelt of industry-specific checks enables our customers in government and other highly regulated industries to demonstrate their adherence to NIST standards alongside other regulatory checks offered with ImprivataPrivileged Access Security (PAS) products. These best practice checklists provide a single pane of glass for compliance posture and reduce manual cross-reference efforts to ensure compliance.
Other enhancements and updates for this release are:
-
Users can now access our public Help Documentation site directly from the UI Help menu.
-
Resolved an issue where a character limit was preventing user from creating or editing tunneled services
-
Resolved an issue where users were unable to enable application groups.
-
Resolved an issue where user was receiving an error when downloading a video audit.
-
Resolved an issue where connections were timing out due to Gateway maintenance tasks on a high number of Gateways.
-
Resolved an issue with inconsistencies on the User Preferences page.
25.1.8 and corresponding LTS releases (24.2.8 and 23.3.5) are now generally available. This release introduces new major functionality for the PAS platforming initiative with Secret Unlock and Task-driven Password Rotation, as well as some more technical-leaning features that both help improve our end user’s experience and help empower users to self-configure and self-help to configure and troubleshoot features on their own.
To tighten control over sensitive credentials, we will enforce a permissions-based gate on viewing protected secret fields; only users granted the right permission can unlock and reveal raw secret values. Following each unlock, any rotation task linked to that secret will automatically trigger after a configurable delay, ensuring that no credential remains exposed longer than necessary and maintaining a minimized “exposure window” for users.
This functionality improves compliance and auditability by logging unlock events in the admin log and linking rotation tasks to the triggering user, enhances security posture via automatic, time-bound credential rotation, and ultimately gets us one step closer to our 'PAM in PAS Co-platforming' product goals.
Before this release, the Tunneled Services only displayed either Online or Offline. When a tunnel is Offline, there is now a way to reset it or test it from the UI, or display contextual help information if something is misconfigured or not working.
This work helps our PAM integrations and syslog export with setup and testing by giving users the capability and guidance to test and troubleshoot in the UI. Additionally, this streamlines troubleshooting and resolution of connectivity issues that impact these service integrations which ultimately helps our internal teams.
Other enhancements and updates for this release are:
-
Additional data points were added to the Audit Archival Storage tables to reflect the storage usage based on the method used.
-
If you have multiple servers, automated emails will now include the specific server name.
-
The new connection manager is now able to authenticate and connect to an HTTP proxy server.
-
Resolved an issue where the connection manager's executable file was being flagged by Microsoft Defender SmartScreen for not having a publisher.
-
Resolved an issue where user was receiving an 'Invalid Application ID' error when deleting applications.
-
Resolved an issue where the History tab intermittently showed a 'Something went wrong' error.
-
Resolved an issue where customer was seeing blank SSH audit files with SFTP file transfers.
-
Resolved an issue where Gatekeeper Registration information was not showing in the Admin Log.
-
Resolved an issue where users were experiencing an 'Invalid Filter Parameter' error when in the Edit Multiple Applications > Edit User Groups workflow.
-
Resolved an issue where service connection retries were not being captured in the Admin Log when the service was using a stored credential.
-
Resolved an issue where users were receiving a 'The server failed to provide a valid SSL certificate' error when launching the new connection manager.
-
Resolved an issue where a customer could not log in because the Terms & Conditions were not enabled.
-
Resolved an issue where users were unable to configure or use LDAPS servers.
25.1.7 and corresponding LTS releases (24.2.7 and 23.3.45 are now generally available. This release introduces Internal User Access controls for applications, the new connection manager graduating from Beta to being our primary default connection manager, and the expansion of task rotation types to include Windows and Linux/Unix.
Our new connection manager is out of Beta! This milestone release of this feature has overall improved stability and functionality with all services working to include a better end user experience for both Mac and Windows users.
The New C-based connection manager rewrite is finished and will be the default connection manager for both the New UI and Legacy UI. This enables new capabilities such as the Containerized Network feature as well as removing the dependency on Java. The new connection manager capabilities include integration with Nexus, HTTP Tunnels, Virtual Interfaces, IP Connect, FTP support, and Magnet Links. It does not include support for UDP at this time. Note that users can still download and use the Legacy Connection Manager (SCM) if they need it.
This release introduces the ability to configure credential rotation tasks for local RDP and SSH credentials. Whoever is configuring the tasks can configure the settings for tasks to be rotated based on events, such as the use of the credential, or run on demand. The new password is created based on criteria defined in the customized password policy.
25.1.5 introduced task rotation for AD credentials, so this addition expands the capabilities with new credential and task types for RDP and SSH, allowing for broader use of the secrets and password rotation tasks.
Other enhancements and updates for this release are:
-
Credential information is now available in the History tables and Session ID tables.
-
When using AWS and Imprivata's SES, we've made some improvements so that our SES recognizes domains outside of our default ones.
-
We've improved our Java8 optional support so users will no longer see error messages when editing multiple applications.
-
Performance enhancements and maintenance fixes went in to the new Connection Manager.
-
Resolved an issue where Credential Pools were not working for RDP connections over Nexus when the CPAM had version 25.1.5 and the VPAM had either version 23.3 or 24.2.
-
Resolved an issue with where the sorting function in Reports v2 wasn't working.
-
Resolved an issue where valid authentication combinations were returning errors.
-
Resolved an issue where users were unable to change the name of a Gateway.
-
Resolved an issue where an intermediate certificate was being placed into the SSL chain twice.
-
Resolved an issue where the server was not checking or recognizing additional LDAP servers when the first one failed.
-
Resolved an issue where connections were timing out due to Gateway maintenance tasks on a high number of Gateways.
-
Resolved an issue where Gateways stopped trying to connect after multiple server restart events.
25.1.6 and corresponding LTS releases (24.2.6 and 23.3.4) are now generally available. This release introduces Internal User Access controls for applications, the new connection manager graduating from Beta to being our primary default connection manager, and the expansion of task rotation types to include Windows and Linux/Unix.
Our new connection manager is out of Beta! This milestone release of this feature has overall improved stability and functionality with all services working to include a better end user experience for both Mac and Windows users.
The New C-based connection manager rewrite is finished and will be the default connection manager for both the New UI and Legacy UI. This enables new capabilities such as the Containerized Network feature as well as removing the dependency on Java. The new connection manager capabilities include integration with Nexus, HTTP Tunnels, Virtual Interfaces, IP Connect, FTP support, and Magnet Links. It does not include support for UDP at this time. Note that users can still download and use the Legacy Connection Manager (SCM) if they need it.
This release introduces the ability to configure credential rotation tasks for local RDP and SSH credentials. Whoever is configuring the tasks can configure the settings for tasks to be rotated based on events, such as the use of the credential, or run on demand. The new password is created based on criteria defined in the customized password policy.
25.1.5 introduced task rotation for AD credentials, so this addition expands the capabilities with new credential and task types for RDP and SSH, allowing for broader use of the secrets and password rotation tasks.
Other enhancements and updates for this release are:
-
All changes to Global RDP settings are now logged in the Admin Log.
-
Resolved an issue where user could not select and save a custom service on a host.
-
Resolved an issue where Internal Server Error was appearing when user tried to create a new report in reports v2.
-
Resolved an issue where Internal Server Error was appearing when user sorted/filtered a reports v2 dashboard.
-
Resolved an issue where convoluted user session history data was appearing on the History tables.
-
Resolved an issue where Nexus RDP connections with attached Credentials were failing when the CPAM customer was on 25.1.5 and the VPAM was on 24.2 or older.
-
Resolved an issue where admins were seeing audit entries attached to the wrong session user.
-
Resolved an issue where QuickConnect sessions were throwing log errors but no visible error for the end user in the UI. Note this issue was only observed on new databases.
-
Resolved an issue where data was not reflected in the Admin log on subsequent connection attempts to a service.
25.1.5 and corresponding LTS releases (24.2.5 and 23.3.3) are now generally available. This release introduces creating new Password Policies for Tasks, new User Management and Application features in the VPAM new UI, the ability to customize client title bars, and other enhancements.
This new functionality, suggested by one of our CPAM customers, allows administrators to define custom parameters for the Client Title launch parameters. The customized names will appear in the window and tab header, making it easier and faster to find a window. This improvement applies to both VPAM and CPAM.
Allowing users to customize the naming convention of title bars allows them to display what they think is the most relevant information at the beginning of the text string, ultimately making windows much easier to find if multiple sessions are ongoing at the same time and easier to switch between them. The customized naming convention appears when a user hovers over a minimized window.
Other enhancements and updates for this release are:
-
An improvement was made to the debug console that allows users to click on the 'Not Healthy' status on the status of Disaster Recovery Diagnostics to view and investigate the details of the Health Check.
-
Filezilla's internal putty process will default to IPv4 resolution when connecting to an SFTP service on MacOS.
-
Resolved an issue where the BeyondTrust PAM plugin was not working correctly.
-
Resolved an issue that prevented users from downloading Scheduled Reports on-demand.
-
Resolved an issue related to Disaster Recovery Health Checks where the UI was timing out before the health check was complete.
-
Resolved an issue on where the Connection Manager (beta) was not terminating correctly on Linux.
25.1.4 and corresponding LTS releases (24.2.4 and 23.3.2) are now generally available. This release includes brand new password rotation functionality for VPAM, the general availability of public facing CPAM end user documentation, and several other enhancements.
Other enhancements and updates for this release are:
-
Entra ID and x509 were added as authncontext SAML configuration options.
-
Ephemeral tokens now work with VNC credential injection.
-
A pagination issue was resolved that resulted in only 25 hosts displaying in an application.
-
An issue was resolved where SCP/SFTP audit logs were broken.
-
An issue was resolved so that ARM Linux receives the proper architecture Java package on upgrade.
-
An issue was resolved where Nexus vendors were unable to register or connect to Gatekeeper V2 with a proxy.
-
An issue was resolved which caused hostname mapping to fail after upgrading from Windows 11 23H2 to 24H2 with IP Connect installed.
25.1.3 and corresponding LTS releases (24.2.3 and 23.3.1) are now generally available. This release includes new features and functionality in the new UI for VPAM, and pre-flight checks for self-upgrades in the legacy UI.
Pre-flight checks were added to the self-upgrade process via the CLI.
The CLI now has the ability to run the pre-flight check without performing the upgrade, including checking on Disaster Recovery notes. If anything is amiss in the DR configuration the pre-flight check will fail and notify the user. Adding this functionality will empower hundreds of customers to self-service their upgrades while reducing operational burden from our Support team.
Other enhancements and updates for this release are:
-
Resolved an issue that prevented users from inputting an MFA code into the login screen successfully. The MFA login workflow works as expected now.
-
Resolved an issue that prevented reseting registration keys in some circumstances.
-
Added a configuration option for disabling port monitoring from the Gatekeeper or Gateway. When this feature is disabled, the Gatekeeper or Gateway will not check if configured services are listening, and users will not see those services rendered as red text in the UI if no service is available on the remote system.
25.1.2 and corresponding LTS releases (24.2.2 and 23.3.1) are now generally available. This release includes the general release and availability of the new UI for VPAM, and additional items including updates to the self-upgrade process and the Best Practice Checklist.
New checks and regulations added to our CJIS, HIPAA, and PCI Best Practices Checklists. The additions include updates and additions around password length and requirements, MFA, account expiration, client anti-virus health, and disaster recovery.
These additional checks ensure organizations continue to operate within regulatory boundaries, minimize operational risk, and maintain quality and efficiency within their industry.
Other enhancements and updates for this release are:
-
The Imprivata FTP client is now enabled for Linux (Alma, CentOs and Ubuntu) for FPT and SFTP services.
-
Improvements were made to the self-upgrade process for an overall better user experience, including enabling the self-upgrade dashboard by default.
-
An issue was resolved which allowed disabled non-admin users to log in to the mobile app and approve access requests.
-
An issue which was causing unintended side effects by checking then unchecking the "Require MFA validation from iDP for SSO users" setting has been resolved, and the customers experiencing this issue should not experience further inconsistencies when configuring this setting.
25.1.1 and corresponding LTS releases (24.2.1 and 23.3.1) are now generally available. This release includes the general release and availability of the new UI for VPAM, and additional items including updates to add custom fields in certain notification emails and further improvements to the self-upgrade functionality.
Other enhancements and updates for this release are:
-
Continued updates and bug fixes for the new Connection Manager are available in this release for sites who have enabled the beta of this from System Settings.
-
If any issues arise while executing the self-upgrade option, a “reason for failure” will be logged in the Admin Log within the UI as well as via CLI output notification sent to the user.
-
Resolved an issue that prevented copy/paste from working correctly on RDP sessions.
2024 Release Notes
24.1.11 and corresponding LTS releases (23.2.11 and 22.4.21) are now generally available. This release includes continued updates to the content available within the new UI for VPAM and contains a change to address the RDP rendering issues users experience after upgrading to Windows 11 24H2.
A change in the Windows 11 24H2 (released 10/1) MSTSC client affected the rendering of audited RDP sessions. This release contains a property that changes how bitmap information is sent in those RDP sessions to address this issue without the need for previously available workarounds which included disabling audit or using a separate client.
Users rely on MSTSC for capabilities such as drive sharing which cannot be delivered by the available workaround client. This ensures that users on the latest version of Windows can continue making connections as they did before Windows updates.
Other enhancements and updates for this release are:
-
Continued updates and bug fixes for the new Connection Manager are available in this release for sites who have enabled the beta of this from System Settings
-
Resolved an issue that prevented the search function on the report distribution list page from working as intended
-
Improved the reliability of launching the SFTP/FTP client
-
The available memory line when viewing a Gateway Instance now properly shows available memory rather than used memory
24.1.10 and corresponding LTS releases (23.2.10 and 22.4.20) are now generally available. This release includes continued updates to the content available within the new UI for VPAM as well as a number of component updates and bug fixes.
Updates to tunneled services to provide clarity around which Gateway a service is routed through and resolve a problem state that can prevent tunneled service connections from resuming after network connectivity issues.
This helps ensure that tunneled services can be easily used and relied upon for customers with complex network deployments and customers that need to route to on-prem services for authentication, SMTP or integrations when deployed in Imprivata cloud.
Other enhancements and updates for this release are:
-
Resolved an issue on CPAM that would result in usability issues when the user’s browser is set to German.
-
Resolved an issue that caused the login page to be difficult to read with the login page design.
-
Created API endpoints for managing sessions.
-
SMTP server response codes of 250 will now be correctly treated as successful.
-
Security updates in response to our annual penetration testing.
24.1.8 and the corresponding LTS release (23.2.8) are now generally available. This release includes the beta of the new Connection Manager which can be enabled from the settings in the system admin module.
The beta new connection manager is available to all users on Windows, Mac or Linux as of this release when enabled from the settings in the system admin module. This is available on both VPAM and CPAM.
The new connection manager significantly reduces the time it takes to go from clicking ‘connect’ on an application or Gatekeeper to having access to the endpoints. Additionally, previous requirements that periodically resulted in the need to clear temp files for some users have been addressed to provide a more consistent and reliable experience for all users. Finally, the new connection manager enables our new Containerized Network functionality.
The Containerized Network feature allows users on Windows to map services to new interfaces outside of the 127.X.Y.Z loopback addresses. This feature is for Windows users only and is automatically enabled when the Next-Gen Connection Manager is used.
VPAM and CPAM have always used an alternate port process for granting access when the local port selected is unavailable. For most use-cases this is unnoticed and allows users to connect without issue. In select use cases such as SMB access or access to PLCs with certain thick clients – alternate ports result in an inability to connect. This new feature allows an alternate interface to be used to ensure the required port is available and makes the connection process for these types of services significantly easier for the end user.
The History section has been added to the new UI and allows a new service access level view of history.
This is a major milestone for the new UI and brings a significantly improved experience to reviewing history. Users can now view history at the service level without the need to drill into multiple sessions to get the data needed. Additionally, the history table can be filtered by any available column or columns including the user, vendor, host, port, access time and more.
Other enhancements and updates for this release are:
-
Initial components to allow administrators to initiate upgrades from within the product have been added
-
API endpoints for access details, session details, Gateway management and others have been added
-
Resolved an issue that prevented custom application access request forms from being properly used for Nexus connections
24.1.6 and the corresponding LTS release (23.2.6) are now generally available. This release contains a number of bug fixes and improvements and continues adding functionality to the beta of the new UI.
Approval requests that previously would notify only the users with the proper permission and department settings needed to handle the approval can now optionally notify system administrators as well.
This new option will make it easier for system administrators who would like a higher level of notifications for approval processes or those who would also be responsible for handling the approvals or may consider themselves an escalation point for those approvals.
Updated versions of the C#, Java and Python SDKs have been released which contain additional functionality and bugfixes.
This release coincides with our regular SDK update. SDK capabilities have been expanded and these updates require the new version of the SDK along with 24.1.6 or newer.
Other enhancements and updates for this release are:
-
Resolved an issue that could prevent the system from properly establishing tunnels for Gateway tunneled services
-
Resolved an error that would occur when users without local accounts, such as SAML users, attempted to use the password reset functionality
-
Resolved an issue that could cause a users’ service access event to not appear on the session history page for access to a web service when a stored credential was used
-
VPAM and CPAM servers deployed in Imprivata Cloud will now have Crowdstrike AV installed
24.1.5 and the corresponding LTS release (23.2.5) are now generally available. This release contains a number of bug fixes and improvements and continues adding functionality to the beta of the new UI.
Other enhancements and updates for this release are:
-
Resolved an issue that could prevent deletion of applications in some cases.
-
Users will no longer be able to inadvertently set the session timeout to zero minutes in the UI which would result in users unable to maintain sessions
-
Non-admin users that can create external credential providers (PAM Integration) can now properly see the created objects on the list view
-
Sorting choice for the list roles table will now persist for users
-
Pre-connection notifications on VPAM will now be properly labeled as Application Pre-Connection Notes rather than “Site” Pre-connection Notes.
-
Removed the ‘reason for access’ prompt automatically included when using a custom application access request form with other fields.
24.1.4 and the corresponding LTS release (23.2.4) are now generally available. This release coincides with the beta release of our new UI! For this release the new UI will not be enabled by default but will be available to be enabled in customer sandbox environments.
Custom Application Access Approval Profiles are now functional over the Nexus, ensuring that vendor reps connecting through Nexus relationships can be prompted for the same information as local vendors when determining approval.
An important piece of any new features brought to VPAM or CPAM is to ensure that, if applicable, those features work across the Nexus. This work closes that gap on a recent feature release both to ensure Nexus does not create any loss in functionality and to meet a direct request by an existing customer.
Other enhancements and updates for this release are:
-
The new Linux SCM is available in beta form and can be enabled with the 24.1.4 release. When the Windows and Mac versions of the SCM are made available we will announce this as a major release highlight.
-
Resolved an issue with a previous release version resulting in renaming Gatekeepers that were hosted on a Gateway
-
The logout.action will now properly forward to the SAML logout for SAML users
24.1.3 and the corresponding releases (23.2.3, 22.4.117) are now generally available. This release contains a number of direct customer requests as well as updates that change the default behavior around support contact information.
The success@imprivata.com email has been removed from the login page text and default settings placeholder for support contact information.
After reviewing the emails that we receive at this address, the vast majority are issues where Imprivata cannot help the end user (anything from accounts being disabled to endpoints not online). The support contact information in system settings should be set with a proper contact for the customer site to ensure users can quickly get to a resource that can help them.
Nexus vendor reps enabled/disabled status will now be determined by the CPAM side of the Nexus connection by default and update the status on the VPAM side during the connection process if needed. Multiple customers ran into issues where local settings on the VPAM side unintentionally affected the ability of Nexus users to connect and requested an update to allow Nexus users to proceed with connecting if their account was in an enabled state on the CPAM server. This resolves an issue that would require manual actions from an admin to re-enable a disabled account. Settings options for the related property allow other behaviors that include rejecting the connection or allowing the user to request to be enabled when the local VPAM account is disabled.
Other enhancements and updates for this release are:
-
Resolved an issue that prevented updated Gateway names from showing on specific pages
-
Resolved an issue that could result in tunneled services going offline due to a hung scheduled tasks thread
-
Updated Best Practices Checklist Password Length to 12 characters to better align with best security practices
-
Updated instances of "Access Restrictions" settings headers to "Authentication Requirements" to better reflect the purpose of those settings
-
Added a UI option for toggling the dynamic HTTP(S) service proxy on and off. When enabled, the proxy is dynamically enabled only for connections with stored credentials.
-
Removed instances of "SecureLink" from certain emails and the "unavailable" page text.
24.1.1 and the corresponding releases (23.2.1, 22.4.15) are now generally available. This release coincides with the official naming update to Vendor Privileged Access Management (formerly SecureLink Enterprise Access) and Customer Privileged Access Management (formerly SecureLink Customer Connect). This release also includes a fix for the audit linking issue (SLK-3423) in the 24.1.1 release only.
The UI has received a branding update to ensure the new name is visible in the top left and color elements have been updated from the former SecureLink color scheme to Imprivata colors. This update also applies the new naming within the UI and emails to replace former instances of “SecureLink”.
This is a major step towards the unified solution naming across the Imprivata portfolio and ensures we can start getting this in front of customers immediately rather than coordinating this with the availability of the new UI.
Instances in a Gateway pool can now be drained to prevent new sessions from beginning on that instance.
It is also now possible to see what sessions are through a given instance. This request came from multiple customers as a means to isolate Gateway instances when there is a need to bring them offline for updates or other maintenance without impacting user connections.
Users can now set a preference for their preferred tunneling method for the Connection Manager.
Having the option to set a preferred tunneling method ensures faster connectivity for users who do not use the standard SSH tunnel by not requiring them to wait while an SSH attempt times out.
Other enhancements and updates for this release are:
-
The “Launch via” setting for services can now be defined upon service creation instead of only on editing the service
-
Gateway CRUD actions will now properly generate admin log entries
-
Resolved an issue that prevented updates to audit retention settings from taking effect
2023 Release Notes
23.1.12 and the corresponding releases (22.4.14, 21.4.10.14) are now generally available. This release includes multiple features and fixes targeting specific customer requests including a fix for the audit linking issue.
Approval profiles grant customization to the questions a user must fill out when requesting access. This feature allows that same customization in a new area where requests previously only had a "reason for access" prompt.
This gives customers more control over the information they're gathering and in turn allows for more informed decision making when granting approval for individual vendor reps to access applications. For some customers this enables them to bring workflows into VPAM that previously were completed outside of the product.
A new custom field for Terms and Conditions that applies to recipients of Quick Connect sessions has been added and will now allow capturing those users' approval of these terms in logs.
This request was completed to fulfill a specific CPAM site's needs, however, it has broad applicability for any site using Quick Connect to manage access to end users at their customer's sites.
Other enhancements and updates for this release are:
-
MFA via Mobile Authenticator is now available for Gatekeeper Users on CPAM.
-
Updating a credential will no longer allow duplicate usernames in the same credential pool.
-
MSDP port type has been added.
3.1.11 and the corresponding release (22.4.13) are now generally available. The main feature within this release is Admin Log Export, available on both VPAM and CPAM.
A new feature has been added to allow exporting information directly out of the admin log to csv. This allows exporting the full content or content filtered by search terms and/or a date range. Many customers ask for custom reporting to gather information either not in the reports module or not easy to gather from the admin log. Syslog integration addresses this for some customers, but adding this functionality addresses it for many more. This will help reduce requests for custom reports and redirect those into upgrade opportunities.
Other enhancements and updates for this release are:
-
Fixed an internal error that occurred when creating tunneled services while no gateways were available.
-
Fixed errors that would occur when deleting applications or Gatekeepers via the SDK.
-
Updating credentials in a credential pool will no longer unintentionally allow multiple credentials to share the same name.
23.1.10 and the corresponding releases (22.4.12, 21.4.10.13) are now generally available. This release contains an important fix for RDP connectivity to the latest versions of Windows 11 as well as an update to allow easier access to component versions among other fixes.
Resolved connectivity issues that impacted users connecting both to and from systems on the latest version of Windows 11.
This issue impacted only systems on the latest version of Windows. Addressing this now helps ensure the impact is minimal and resolution is available before more broad adoption of the latest Windows updates.
We now support proxy configurations for pull upgrade connectivity, a requirement for a small number of sites.
Enabling this ensures that the pull upgrade model, required for upgrading to modern versions, is available to customers with proxy requirements.
We’ve implemented an about page within the previous debug page to provide information on component versions.
This is intended to quickly confirm component versions that may assist in resolving issues not related to the VPAM/CPAM server version. Above all, this should help our support team with easier access to information they need frequently.
Other enhancements and updates for this release are:
-
Hosts may now be enabled via the SDK
-
SDK connection failures will now see an accurate error
23.1.9 and the corresponding releases (22.4.11 and 21.4.10.12) are now generally available. This release contains improvements to performance and usability of specific pages and coincides with the latest update to the SDK that enables features not previously supported by the SDK.
Multiple reports generated from the reports module have been updated to display the hierarchical departments rather than the legacy department field.
This update makes reporting clearer for sites that utilize the departments hierarchy for managing users and their permissions.
The credential and credential category list pages will now include paginated tables the same way many other list tables in the UI are displayed.
This will improve performance when loading these pages on sites that heavily utilize these features. Additionally, this allows column-based sorting.
Updated versions of the C#, Python and Java SDKs have been released and include support for Quick Connect, credential tokens and other fixes.
Customers using the SDK can begin using the latest versions (2.6.0 for C#, 2.3.0 for Python and Java) along with this release to utilize the new endpoints and updates.
Other enhancements and updates for this release are:
-
Added support for Gatekeeper registration codes without expiration dates
-
Added the Gatekeeper registration code to the Gatekeeper downloads page
-
Resolved an issue that resulted empty upgrade commands being sent to Gatekeepers
-
Departments will now appear in order when bulk editing applications
23.1.8 and the corresponding releases (22.4.10 and 21.4.10.11) are now generally available. This release contains Gatekeeper information updates and important bug fixes including multiple fixes related to the reporting module.
Connections to HTTP and HTTPS services will no longer have our man-in-the-middle component for HTTPS enabled by default. This will only be enabled for a connection if there is a credential that needs to be injected for the user.
This component can slow down connections and break specific HTTP(S) services. Ensuring it’s not running when it isn’t needed allows for more connections to work without requiring workarounds to disable this manually. This should decrease the number of HTTP(S) related cases opened for our support team.
Gatekeepers that are duplicated either through manual means of copying keys to use the same registration code or through the cloning of an entire VM that has an installed Gatekeeper will now be properly displayed to the user.
This is an important change for CPAM customers who had little insight into this before. This information can be helpful in identifying Gatekeeper connectivity issues, particularly intermittent issues, and sites that require separate Gatekeeper installations.
Changes have been made to improve performance with our built-in desktop sharing components. This should help resolve latency and framerate issues seen in recent versions.
Desktop Sharing performance has impacted several customers, and multiple steps have been taken to resolve the issues. This should drastically improve the experience for customers who rely heavily on desktop sharing.
Other enhancements and updates for this release are:
-
Resolved an issue where email links for RDP2 audit conversions would be invalid
-
Resolved an issue where in-browser notifications for completed audit conversions would lead to a “Page not Found” error
-
Resolved an issue where disabling audit at the Gatekeeper Group level would prevent credential injection
-
Multiple API Updates
-
Updated the concurrents report in the ReportsV2 module to use our weekly_concurrents table for data
23.1.7 and the corresponding releases (22.4.9 and 21.4.10.10) are now generally available. This release contains Gatekeeper information updates and important bug fixes including multiple fixes related to the reporting module.
Users can now see additional Gatekeeper Information in the UI in relation to the JVM memory and threads.
This will help quickly identify and resolve Gatekeeper issues that can occur for Gatekeeper deployments on systems with low or minimal specifications.
Sessions created for Gateway tunneled services such as AD/LDAP or PAM integration connections will no longer generate any empty session data visible in the session history
Users and administrators reviewing audit will no longer have unnecessary data visible in the session history and can more quickly find user audit.
Other enhancements and updates for this release are:
-
Resolved an issue where reports that included data in or out information with large values could result in emailing a blank report
-
Resolved an issue that resulted in the Vendor Connection Report on VPAM being unable to show preview data in the UI
-
Editing multiple scheduled reports without refreshing the page will no longer result in applying the initial report’s filters to subsequent reports
-
Updated SSHD to fix a bug that could result in SSHD processes using an amount of memory exponentially higher than expected
23.1.6 and the corresponding releases (22.4.8 and 21.4.10.9) are now generally available. This release contains important bug fixes, back-end updates and coincides with the latest release of our SDK.
As of this release we now have updated VHDs for deployments in Azure that are based on AlmaLinux 8 and support our pull model for upgrades. This is available for new deployments in Azure or migrations to Azure.
We’ve updated how our SSH audit is captured and stored in order to capture raw data with headers. This ensures more data is captured in the audit file to help resolve an infrequent issue that could cause SSH audit to be captured but not linked in the UI on session history.
With this release we've both created the credential token endpoint and updated our SDK versions. This will allow the credential tokens we use for injection to be available to the SDK as they are for users via the UI for endpoints such as HTTP/HTTPs services.
We’ve updated the Java and Jetty versions used by the PAS appliance. While the previously used versions posed no security risks, this upgrade ensures we’re using any security and performance fixes while addressing any concern with older versions appearing on scans.
Previously the local audit conversion on the SecureLink appliance could fail when creating a file larger than expected, preventing admins from viewing particularly long RDP sessions. We’ve adjusted the default limitation to prevent this issue in most, if not all circumstances.
23.1.5 and the corresponding releases (22.4.7 and 21.4.10.9) are now generally available. This release contains important bug fixes and back-end updates.
VPAM is now available in German and will display in German for any user with German language settings set as default in their browser. This is dynamic based on the browser setting and does not require users to navigate menus to find language settings within PAS.
Administrators may now configure AD integration to sync roles for users on authentication. This previously was limited to user information including groups
Resolved an issue that had prevented admins or other users with appropriate permissions from being able to delete applications under specific circumstances.
Resolved an issue that prevented credential injection with telnet services in Putty and could degrate telnet connection performance.
Resolved an issue that could prevent admins from being able to use the "Move GK" option in CPAM.
23.1.3 and the corresponding releases (22.4.5 and 21.4.10.7) are now generally available. This release contains key bug fixes and improvements as well as general availability for new features related to audit retention.
This release enables UI controls over audit retention and archival settings. Previously any changes to these settings required our Technical Operations team to make configuration changes.
In addition to mounted storage for audit files, customers will now be able to configure S3 buckets for audit. This also opens up availability for this to our cloud environment and reduces the cost for long term audit retention in cloud.
Latency issues in our desktop sharing provided both by the Gatekeeper and in Quick Connect that were introduced in a prior release have been resolved.
23.1.2 and the corresponding releases (22.4.4, 22.3.7, 22.2.10 and 21.4.10.6) are the last releases under the current version schema. This release contains key bug fixes and improvements and no new major features.
This release resolves multiple connectivity issues with Universal Gatekeeper that could occur during Gatekeeper upgrades or routine connectivity key rotation.
Resolved an issue that resulted in session chat not allowing separate users connected to the same Gatekeeper to use the feature.
Resolved an issue that resulted in a "request is malformed" error when requesting access to a Gatekeeper with an ID greater than or equal to 1000.
Relocated the directory for temporary file storage during audit conversion to prevent conversion failures related to a lack of disk space.
For services that have had HD audit disabled by admins, rather than showing an empty space where the audit link would appear in session history, we will now show an indicator that HD audit has been disabled.