2.19.0 Release Notes
14 min
This section provides information on the major features, fixes, and changes introduced in the new release 2.19.0 for Single Connect.
Contact Us
Contact us at [email protected]. Please note that only registered users can contact the support team.
Release Summary
Privileged Account Discovery and Onboarding
- Discovering detailed changes (account group/attribute changes) in Privileged Accounts
- Discovered account reports will be tagged on whether or not they are managed in Single Connect
Adjacent System Integration
- Notification mechanism enhanced with e-mail grouping options. Instead of individually, notification e-mails can be sent in a combined e-mail. The combination period can be set by the customer
- SMPP Connector is supported for SMS notifications
- LDAP Integration is improved with GUID matching
- New Secret Management APIs have been added, meaning each GUI functionality is provided within the APIs. More than 100 new APIs are delivered with the 2.19.0 release:
- Secrets: Secret Add/Delete/Set/Show Credential/Reset Credential/Show Old Values/Update Credential
- Secret Tree Structure: Add/Delete/Set/Modify/List New Groups
- Permission Management: Add/Delete/Set/Modify Secret Permissions
- Approvals Management: Approve/Disapprove , Add/Set/Delete/Modify/List Approval Managers
- Reservation Management: Add/Modify/Set/List Reservations
Ease of Deployment and Scalability
- The Watchdog application supports different interfaces.
Logging and Reporting
- The reporting module provides a set of features that allow the customer to create their own reports and dashboards.
- The reporting module and Single Connect share SSO functionality.
- The reporting module roles are managed by Single Connect.
- The implicit Filter feature is supported: whenever the customer creates a new report within this feature, it will run according to the profile of the user running the report. If the user is an auditor, all the data in the system will be visible, otherwise the user will only see the data based on privileges assigned to him/herself or his/her data groups, according to the organizational structure.
- Ability to support PDF export for dashboards/charts
- New Customized Dashboards (Added more than 20 new dashboards)
Privileged Access and Governance
- Until now, the manager of the user groups had to be a group member; this restriction has been removed
Privileged Credentials Management
- Both Static and Dynamic Accounts are managed together and have the same feature set
- Conversion between Static and Dynamic accounts is possible without account re-creation
- The tree view structure management is provided for accounts
- The new roles are defined on the Secrets Management. These roles provide various Secrets capabilities
- For Secret Access Requests, Access Reviews, Access Certifications, Approval Process Workflows for Privileged Accounts, Permission Management of Privileged Accounts
- End User
- Can view credentials and account groups, according to their permissions/approvals
- View waiting approvals and waited approvers
- End Users Manager
- Can view credentials and account groups, according to their permissions and approvals
- Can create new accounts/account groups
- Can view approvers
- Can approve/disapprove the waited approval requests
- Normal Users
- Can view credentials and account groups, according to their permissions and approvals
- Can create new accounts/account groups
- Can view approvers
- Admin Users
- Can view credentials and account groups, according to their permissions and approvals
- Can create new accounts/account groups
- Can view approvers
- Can set/define the accounts/account groups’ approval manager
- Auditor Users
- Can view account information
- Can view account group information
- Can view approvers
- Can access all the activity logs on Secrets (creation, deletions, permission management, approval records, credential access, credential rotation, etc.)
- The Secrets are safe, even if theSingle Connect Admin can not access any credentials
- A notification mechanism is established on Account Groups; the notified users can be defined at the Account Group level
- A privileged account approval mechanism is established on the tree view structure. The inheritance mechanism is provided to efficiently manage millions of accounts in the tree view structure
Privileged Task Automation
- WinRM support is provided for Script Player
- Ability to execute scripts on multiple devices and device groups
Application to Application Password Management
- AAPM Accounts can be used by multiple IP’s/Applications.
- AAPM Accounts can be associated with multiple Privileged Accounts or Privileged Account Groups.
- AAPM Accounts can be defined with a usage limitation.
- AAPM Accounts can be managed on a time expiration basis.
- A new API added to the Collection creates a list of which Privileged Accounts are associated with the AAPM Account.
- A set of performance improvements is provided on AAPM Accounts:
- 1000 TPS of Account Access Requests can be returned in 1 second for more than 250K Privileged Accounts in a basic machine (16 CPU,32 GB Ram).
Privileged Session Manager
- Connection Reservation Request Enhancements:
- A privileged accounts limitation is provided. The connection reservation request can contain time, target device, and privileged account-based restrictions.
TACACS & Radius Access Manager
- Radius has MS Chap v2 support.
- The TACACS Key Encryption Mechanism was enhanced for internal attackers.
Data Access Manager (SQL Proxy)
- SSL Encryption is supported for Oracle Database:
- User Client Tool to Single Connect
- Single Connect to Database
- Both of the above
Multitenancy
- Multitenancy release and Single Instance release are merged in the 2.19.0 release, meaning all the features and bug fixes will be delivered in the same release. This option will be managed by the license manager.
- Tenants can manage their backup & restore policies.
- VRF definition is provided on the Tenant Management screen, making it more user-friendly and efficient.
- Concurrent Session License management is available for Tenant based instances; it will be set and configured on the Tenant Management screen.
Platform Features
- Enhanced Break-the-glass procedure with a new alternative: the customer is able to access the credentials from the backup file without restoring the entire system. This provides a more efficient alternative in a disaster recovery scenario.
- Enhanced Job Management for better troubleshooting capabilities, such as seeing how many of the records are processed by Job successfully, how many of them have errors, what are the error messages and details.
- Bulk import capability is provided for User Management.
- Tokenization mechanism is built in between the User Mobile Application, the Mobile Server, and the Single Connect Server.
- During the authentication phase, after the credential check mechanism, the JWT Token is sent by Single Connect to the User Mobile Application. The session time limit is configured in the Single Connect Mobile Server.