2.17.0 Release Notes
This section provides information on the major features, fixes, and changes introduced in the new release 2.17.0 for Single Connect.
Contact Us
Contact us at [email protected]. Please note that only registered users can contact the support team.
Release Summary
Dynamic Password Controller
- Additional User Group info for SAPM New User Log: User group information has been added for new users found using SSH and SMB methods in SAPM.
- WebLogic Data Connection Pool password can be reset by using an AAPM trigger: The WebLogic application server has Connection Pool Management capabilities. Weblogic servers keep database credentials in the connection pool mechanism. When the Single Connect SAPM manages and randomizes these database credentials, the new credentials should be updated in the Weblogic Server Connection Pool Mechanism. This feature allows Single Connect to manage these updates as soon as it randomizes the database credentials, via an AAPM Trigger mechanism on the WebLogic Server Connection Pools.
- WinRM support for AAPM trigger: WinRM support is available for Windows Service accounts management. SAPM provides service accounts management. The service configuration files can be updated using an AAPM trigger via WinRM.
- Auto-load list of secrets in SDV: This feature has been developed for ease of use. When a secret group is selected on the Secret Data Vault Group management screen, accounts will be displayed automatically.
- SDV group-based authorization support: The user has been made visible only to the authorized parent groups and subgroups.
- All SDV accounts are set as Private accounts by default: Every account added to the Secret Data Vault is configured as Private Yes by default.
- New User Creation Authority role in SDV Management: A Group Admin role has been created for authorization purposes, when adding accounts to the Secret Data Vault. Users with this role can create accounts.
- SDV Account is not visible to adjacent user groups: Accounts created by each user have been classified as private. No other user in the user groups the user belongs to can see the account, unless the user gives permission to the group.
- Parametric SDV group management support: The group field is mandatory whenever the user adds a new secret. The parameter (sdv.group.required = true) has been adjusted according to this configuration ad can be added from the system config manager screen.
Session Manager
- Customized Approval Workflow Support: This new feature was developed to enhance flexible managerial approval configuration in situations where approval authority can also be established. The number of managerial approval levels can now be increased by configuring a workflow, allowing the use of different types of managerial approval methods (email, SMS, push notification) at multiple levels, for both connection (RDP, SSH, SFTP Proxy) and command (SSH Proxy) approval.
- SSH Proxy:
- Log in to SSH Proxy with both password and RSA key: In previous releases, log in with only password, only SSH key, and SSH key or password to SSH Proxy were available. Users could not be forced to log in with both password and SSH key simultaneously. With this release, users can be forced to use both SSH key and password to log in, if so configured in the SSH Key Management>>User Group Key Management screen.
- RDP Proxy:
- RDP Proxy Policy for File Transfer and Copy-Paste rights: Some RDP session related properties, such as File Transfer and Copy/Paste rights were previously defined in the Device Properties, which led to them having same value for each user connecting. The new RDP Profile page was created to enable the definition of these properties separately for different user groups. File Transfer and Copy/Paste rights can currently be defined in different RDP Profiles, which can be included in Policy Groups, to be linked with Device Group Realms, resulting in Policy Realms.
Data Access Manager
- SAP HANA Database support: SAP HANA Database support is added in this release. The DbVisualizer client can be used while connecting to a SAP HANA Database. Masking can be applied after all the definitions are set up.
- MSSQL Database Single Sign-On support and Oracle (12c r1) DB Single Sign-On support: In previous releases, the SQL Proxy feature is used with only usernames defined in the target databases. This release supports Single Sign-On in MSSQL and Oracle 12c release1 databases, enabling the use of global username/password and global username/ SAPM Password.
- Toad 11 client support: The Toad 11 client is supported for Oracle databases.
- Select * improvement for Oracle Database masking: The Select * command is fully functional in this new release and the SQL Proxy captures all the masked and unmasked columns in the same order as the target database. In previous releases, whenever masking was applied to table columns while data was being gathered, the select * command generated a warning and no data would be displayed even if only some of the columns were masked.
API
The 2.17.0 release includes a major improvement of its API Collection. There are 2 new folders and 41 new API Methods available.
- API for Policy Management
37 new API methods are available in the API Collection v2.17.0. Policy Management can be handled by using the new API methods.
- API for Secret Data Vault
Secret data vault account records are now managed via API, including 6 functions on the interface screens related to the account.
- New Listing Requests
The API Collection includes many listing requests, with and without parsing parameters. The listing requests are enriched with new generic get requests, which lead users to get a response with all the elements without any parsing parameters. There are also new API listing options to view the server and utility status in the Device Management and Diagnostics section.
- API Calls Block in SCC Environment Regions: The Controller logic is also available in the new API Collection, just like in the Web Application. All of the API methods (99 in total) are configured to be either allowed or not allowed in Controlled Instance environments, according to the permissions of the Controlled Instance environments. In general, API methods are not allowed in Controlled Instance environments, if the request involves configuring something on the instance. If the requesting is only related to listing something that the user is privileged to view, there will be a successful response to the API request, even if it is called from a controlled instance.
Operation & Maintenance
- Environment information, CPU status, memory and disk utilization: Instance names, IPs and instance status are displayed in the Monitoring screen. Summary charts and detailed CPU performance trends, memory and disk utilization are available by selecting each instance.
- Monitoring of all services, including trend charts: The service status is listed and monitored in the Service Monitoring screen and the user can open a pop-up window to visualize the service status’ detailed trend.
- Latency between Instances: The latency between all nodes is measured and displayed.
- License monitoring based on device count, user count, concurrent sessions and 2FA: The license usage historical trend is displayed, based on device count, user count, concurrent sessions, and 2FA. For each element, the used and licensed amounts will be visible, if the
- Monitoring alarms:
- Alarms created by the alarm job can be visualized on this screen. The alarms can be filtered by their instance, severity, IP, status, and creation time.
- Users can execute two actions after (multi)selecting the alarms: Send Email or Clear Alarm.
- The Send Email feature directs outlook to open a new email window, fill out the subject and body of the email, and keep the destination blank. The body of the email will include the alarm information (complete row). The subject includes the alarm message.
- The Clear Alarm option changes the alarm status manually to Close.
- Alarm Job Development
- Setting up alarm thresholds dynamically:
- In the Alarm Configuration screen, the thresholds can be set up according to the customer requirements. The following alarm thresholds can be set for each severity level (minor, major, critical).
- CPU (in percentage)
- Memory (in percentage)
- Storage (in percentage)
- License Count (in percentage)
- License Expiration (in days)
- Latency (in milliseconds)
- When opening the screen, the previously defined values are automatically displayed. All thresholds can be edited and updated by the user, then saved by clicking Save.
- Alarm email configuration: Any email configurations can be set up in the Mail Configuration tab. The Subject and body part of the email can be changed dynamically. The suggested default text and parameter usage can be changed.
- High Availability for Controller and controlled Regions: A watchdog mechanism was developed to watch over all instances and execute failover scenarios. The watchdog application runs within each instance and communicates with other watchdogs in the environment. If an instance or the master Netright-Tomcat is down, the next prioritized instance will become the master.
Other
- Support to delete Empty User Groups upon LDAP import:
- A large set of user groups can be imported into Single Connect. Whenever the user search phrase was limited during an integration, empty user groups would persist in Single Connect. Empty user groups can also exist in the LDAP server. This new feature allows Single Connect to delete empty user groups upon LDAP import.
- This feature can also be set as a System Config Manager parameter. sc.integration.ldap.delete.empty.user.groups: the value can be set as true or false. If the value is true, the empty LDAP user groups will be deleted from Single Connect.
- Negative Selection Search Support for Log Screen: The field exclusion feature was added as a filtering option in log pages, as illustrated by the following screenshot.
- TCP Protocol Support for Syslog Integration: In previous versions, the SIEM Integration supported only UDP to send syslog packages to the server. The 2.17.0 Release allows users to configure the SIEM Integration to send syslog packages to the SIEM server via TCP. The options can be managed by a system-wide property to select the transport protocol for syslog packets.
- SC-2323 Session ID filtering in the Command Log Screen.