- 13 Dec 2024
- 6 Minutes to read
- Print
- DarkLight
- PDF
UCMS 4.12/UP 2.7 Release Notes (May 2023)
- Updated on 13 Dec 2024
- 6 Minutes to read
- Print
- DarkLight
- PDF
Last Updated: April 29, 2024
Note
If you have any questions about these features or want to request a more in-depth discussion about the best way to leverage them, reach out to us at productmanagement@axiad.com.
Product Versions Included in this Release:
UCMS: 4.10.x, 4.11.x, 4.12.x
Unified Portal: 2.5, 2.6, 2.7
UCMS 4.12
New Features
Support for New Devices
UCMS now supports the issuance of management of new device types:
Gemalto IDPrime MD931
Yubico YubiKeys that can provide the identifier of their Batch Master Key as part of their metadata (version 5.3 and above). This is useful if you order YubiKeys programmed with a custom BMK unique to each order.
FEITIAN BioPass FIDO2 (K26, K26+, K27, K27+) devices.
To issue and manage these devices, you must create a new device profile and assign it those to a workflow.
Expanded Ecosystem Support
We now support the latest firmware of Utimaco HSMs (validated against their SecurityServer Simulator v4.50.0.1) for the storage of key materials.
UCMS is now validated for MySQL 8.
Enhancements
SCIM Enhancements
Support for the SCIM 2020 PATCH Format
We now support SCIM 2020 PATCH format, which simplifies the SCIM configuration when connecting your Axiad Conductor instance to an Azure tenant. Previously, the Axiad Conductor > Azure AD integration only supported SAML SSO.SCIM Imports (MyCircle Users/Groups)
MyCircle rules can now refer to entities and attributes that were imported from a SCIM-compliant provider, such as Azure AD, Ping Federate, or Okta.
Java KeyStore
New options were added to the config.properties file to allow for the configuration of different passwords for the oauth key and its containing keystore:
Key | Description | Default Value |
---|---|---|
oauth.keystore.default-key | Default name to use for the entry containing the OAuth bearer token in the configured keystore, if oauth.keystore.private-key.key was not configured. |
|
oauth.keystore.private-key.code | Password protecting the OAuth entry in the configured keystore. | If not configured, UCMS will use the the value of keystore.code. |
Deprecated Permissions
We changed our naming convention for Unified Portal privileges affecting the status of a device. Legacy permissions are still present but marked as deprecated, and will be removed in a later version:
Previous Permission Name | New Permission Name |
---|---|
all.deviceEnable | all.device.active |
all.deviceRevoke | all.device.revoked |
all.deviceDisable | all.device.suspended |
Assign Device Type Permissions Based on User Roles
With this release, you can configure the permissible actions available to your users, depending on their device types. For example, you can restrict their YubiKey revocation permissions, but allow them to replace their existing Axiad ID for a new mobile device.
Contact your Customer Success representative or customer.success@axiad.com for a complete list of permissions, and to enable them for your users.
Bug Fixes
Version | Ref ID | Description |
---|---|---|
4.10.x | PM-858 | Azure AD timestamps now display properly. |
PM-279 | Workflow certificate configuration changes now save the first time you save them, as expected. | |
PM-845 | When you import multiple KM certificates for multi-permanent workflows, a certificate serial number no longer displays multiple times. | |
PM-1036 | Windows Hello for Business revocation now fails as expected when Azure is unavailable. | |
PM-2185 | When you update fields in the Credential Profile, only those fields that are modified are saved, as expected. | |
PM-1034 | MyCircle rules now also apply to users coming from a SCIM source. | |
PM-3498 | When setting up the Workflow Steps for Windows Hello for Business, there are no more missing labels/names for the drop downs and text boxes. | |
PM-2982 | You can now attach default attachments in notification templates, as expected. | |
PM-3832 | Now, during a new device issuance, when the Imported Key management certificate is retrieved, UCMS ensures the workflow certificate configuration matches. | |
4.11.x | PM-4134 | An issue where SCIM group sync updates failed with Okta has been resolved. |
PM-4146 | You can now save Feitian certificates with Cloud HMS configurations as expected. | |
PM-3542 | You no longer receive a 403 Forbidden page when saving a virtual smart card CP with Utimaco HSM labels. | |
PM-3953 | You can now update and add attachments to email notification templates as expected. | |
4.12.1 | PM-3913 | The Windows Installer version now matches the UCMS version. |
PM-3175 | The displayed strings for the Revoke and the Revoke Certificate buttons are now independently customizable. | |
PM-2945 | Admins can reset PINs and/or renew certificates for IDPrime MD 930 smart cards as expected. | |
4.12.5 | PM-7428 | Addressed vulnerabilties: CVE-2024-1597/CWE-89, CVE-2023-52428/CWE-770, CVE-2024-23672/CWE-400, CVE-2024-22257/CWE-284, CVE-2024-22243/CWE-601/CWE-918, CVE-2024-24549/CWE-400, CVE-2024-22259/CWE-601, CVE-2024-29133/CWE-787 |
Unified Portal 2.5 - 2.7
New Features
"Single Pane of Glass" to Azure
Axiad Conductor now has the ability to track all authentication methods issued in Azure and report on them within the Unified Portal. This includes primary authenticators such as Windows Hello for Business, Microsoft Authenticator, and FIDO2, as well recovery authenticators like Temporary Password Access or SMS OTP.
This equips your IT department with a more complete picture of the current state of your passwordless rollout across your environment. If authorized, Help Desk Operators have the option to delete any of those credentials.
The Axiad Knowledge Center
To provide better and more comprehensive self-service for Axiad’s product offerings, we've developed a new, comprehensive Knowledge Center for our products. The first iteration of the Knowledge Center includes product documentation for Axiad Conductor, with additional products added in the coming months.
Content published in the Knowledge Center is verified and up-to-date.
New content will be added frequently (sometimes daily).
In a future release, a direct link to the Axiad Knowledge Center from within the Unified Portal will be available in the Account menu.
Access the Knowledge Center via https://docs.axiad.com.
Hardware Support
The Unified Portal now supports the following hardware devices:
FEITIAN BioPass FIDO2 (K26, K26+, K27, K27+)
Gemalto IDPrime MD931
IDEMIA Cosmo v8.2
Yubico YubiKeys that can provide the identifier of their Batch Master Key as part of their metadata (version 5.3 and above). This is useful if you order YubiKeys programmed with a custom BMK unique to each order.
Contact your Customer Success representative or customer.success@axiad.com to enable these hardware devices.
Enhancements
Customizable Link in your Unified Portal Header Bar
You can add your own link (such as one to your organization’s customized or branded documentation) to your Unified Portal header bar via a new icon:
By default, this enhancement is set to Off. Contact your Customer Success representative or customer.success@axiad.com to enable and customize a link in your organization’s Unified Portal header bar.
Send Axiad Feedback from within the Unified Portal
In our continuous efforts to improve our products, we want to hear from you. Use the new Feedback option in your Account menu, located in the top right corner of all pages in the Unified Portal, to send your thoughts and suggestions directly to us.
This opens a new Send Feedback page, where you can select a star rating and enter comments:
By default, this enhancement is set to On. Contact your Customer Success representative or customer.success@axiad.com to opt out of this feature.
One-Time Password Testing
For testing purposes, users with an Operator role can use a one-time password (OTP) for a given device without providing a PIN.
This enhancement is On for all Operators.
UX Enhancements
To improve your user experience in the Unified Portal, YubiKeys are now listed as YubiKey regardless of their firmware version. Advanced users or IT operators can access a YubiKey’s firmware version via the Details View or Reports.
TIP
If you deploy YubiKeys and create your own custom documentation, we recommend you update it to reflect the simplified label.
Before:
After:
Automatic Action Grouping
If two or more actions are available to a user or Operator on a given device, the first two actions display as buttons. Additional actions are then grouped in the context menu.
Any time-sensitive actions such as Renew are always listed first.New Report Columns
You can now display the first name, last name, and UPN when looking at or reporting on users.
Selective Certificate Lifecycle Management
Help Desk Operators are now able to selectively suspend, resume, and/or revoke a certificate on a given device without affecting other credentials on the same device. This is useful for cases where for instance ownership of a specific encryption certificate is tied to a distinct background check.
Bug Fixes
Version | Ref ID | Description |
---|---|---|
2.5.x | PM-1730 | On the Help Desk page, when you click the Preferences icon, your selections save as expected. |
2.6.x | PM-1978 | The error message you receive when attempting to assign an already-assigned device to another user is improved for usability. It now reads, "Serial has already been assigned to another user." |
PM-1452 | The issue where some mobile OTP authenticators displayed as OTP Device has been resolved. | |
PM-823 | The Emergency section no longer displays if there is nothing to show and/or if the user doesn't have the .userResetSecurity permission. | |
2.7.0 | PM-2798 | Workflow certificate configuration changes now save as expected when you click the Save button. |
PM-1978 | The error message you receive when attempting to assign an already-assigned device to another user is improved. | |
2.7.4 | PM-7431 | Addressed vulnerabilities: CVE-2024-29133/CWE-787, CVE-2024-22257/CWE-284, CVE-2024-22243/CWE-601/CWE-918, CVE-2024-25710/CWE-835, CVE-2023-26159/CWE-20 |