2.20.0 Release Notes
12 min
This section provides information on the major features, fixes, and changes introduced in the new release 2.20.0 for Single Connect.
Contact Us
Contact us at [email protected]. Please note that only registered users can contact the support team.
Release Summary
Privileged Account Discovery and Onboarding
- Device Group Discovery and Onboarding Enhancements: Device Group Hierarchy and Devices under any CMDB/Asset management system can be discovered and onboarded into Single Connect. The changes on the source application/system, like additions or removals, are automatically reflected into Single Connect.
Adjacent System Integration
- Approval based on SMS (both-ways) for SMPP protocol support has been delivered. Within this feature the approvers can accept or reject the approval requests via SMS.
- New APIs
- Create Tenant
- Suspend Tenant
- Reactivate Tenant
- Drop Tenant
- List Tenants
- Edit Tenant
- Reset Tenant Password
- Adding Assigned Credentials: API developed to bulk import assigned credentials.
- For SAPM groups and accounts, APIs, created_at and updated_at parameters are added to the APIs response.
Ease of Deployment and Scalability
Single Connect provides effective data decryption and encryption mechanism, enabling the optional migration from the old schema to the new schema.
Logging and Reporting
- Tamper Proof Logging Enhancements
- Report Scheduling Enhancements
- Detailed Logs Enhancements on Jump Server scenarios (Target Application IP, Connection User, etc.)
- HTTP Proxy Log Enhancements: Connection User is added to the logs, for auto-login scenarios
- Newly customized dashboards and charts added to Single Connect
- Access Violation
- Authentication Statistics V2
- Compliance Index Dashboard
- Session and Authentication HeatMaps
- Audit Reports for Accounts
Privileged Access and Governance
- Connection Reservation Enhancements: privileged users can choose which connections users have access rights to while entering their reservation request. The approvers can see this information while approving/denying the requests.
- Assigned Credentials for User Groups: The credentials managed by the Secrets Management module can be assigned to user groups in addition to users, to be used for authentication in sessions conducted with Session Management.
- Assigned Credentials for SAPM AD Accounts: Active Directory credentials managed by the Secrets Management module can be used as assigned credentials for authentication in sessions conducted with Session Management.
Privileged Credentials Management
- When the SAPM rotates the password, Single Connect generates 2 separate log records in the SAPM Change Password logs. These transactions are separated from each other with Password Seen Expiration and Reset Password logs.
- The level of action to be taken for the Group in Permission, Approval Manager and Notification assignments is set over the SAPM Group Tree. (Full Tree, One Level (Group and Accounts), Only Group)
- The feature of assigning multiple permissions to User Groups has been developed. The permission level is set to apply to the highest permission User Group. (Full Control > Read Only)
- In order for the account to add and reset its own password, this feature has been developed so that it can be done with the Change Password option in Active Directory except Reset Password. This improvement has been made because the Change password option is default on Windows Servers.
- On the SAPM Group Tree, if it is necessary to get approval in the account at any level in the tree, it is set to get approval from the upper groups.
Privileged Session Manager
- New UX/UI Changes on privileged end users functionality on SSH Proxy:
- Settings feature is available (Font size and Theme can be selected)
- Privileged end users can open multiple SSH sessions from the tab menu of the session via single click
- The new window opens in full-screen
- New UX/UI Changes on privileged end users functionality on RDP Proxy:
- New menu bar on the top of the screen
- Settings/File Manager and Clipboard Options are available on the top menu
- Privileged users can change the settings during the session
- SSH Proxy is supported via CLI Based Usage, privileged users can run a Single Line Command to connect to the target device over the Single Connect SSH Proxy. This allows CLI based sessions to also be under the control of the Single Connect SSH Proxy.
Data Access Manager (SQL Proxy)
- New License Model: the SQL Proxy can be licensed with two different methods, according to features and/or database types. Features such as Data Access Manager, Logging, Policy Enforcement and Dynamic Data Masking can be licensed together. Database type licenses include Oracle, MSSQL, MySQL, Teradata, PostgreSQL, Cassandra, DB2, Couchbase, SAP HANA and Hive databases. These alternatives can be purchased together or separately.
- Oracle authorized/unauthorized support feature is supported by SQL Proxy.
- Dynamic Data Masking Improvements:
- Blocking all conditions and functions for masked columns
- Ease of use improvements in the SQL Proxy Policy screen
- Enabling setting a row limit for a masking policy. When this policy is applied, only a predefined number of rows can be received
- Adding a new feature for masking execution on a specific data type
- Enabling hiding a column for flagged masking methods
- Enabling transport of all masking definitions to the copied table, in case the user tries to copy a masking applied table
- Improvements made for Oracle databases:
- Character set support: Any character set for any language in Oracle DB is supported
- DB Link support: If an Oracle DB has a db link with any other Oracle DB, and the user tries to reach the masked data on the linked database, the SQL Proxy masks the data
- Partition blocking: Partitions can be blocked as an option. The SQL Proxy masks the data even if the partition is used. However, brute force queries with partitions enable the user to guess what the masked data might be. In such cases, partitions can now be blocked
- Synonym masking support: If any synonym is used for a table, and the user tries to access the table with the synonym, the masked data is not exposed
- View support: If a view consists of tables with masked columns, and the user executes queries on this view, the masked data is not exposed.
Multi Factor Authentication
- Mobile application links have been added to 2FA Tokens notification e-mails
Multitenancy
- On-Behalf Of Tenant Management for Host Administrators: The Host Admin can define the users who can manage the Tenants as Tenant Admins, as well as the users who can access the Tenant Devices as Privileged Users. These options are configurable according to the Tenant requests/approvals.
- On-Behalf Of Tenant Management: The Host privileged users can authenticate Single Connect once; later they can switch their tenants on the Single Connect GUI so they can access the Tenants devices.
- On-Behalf Of Tenant Management: The Single Connect desktop application supports On-Behalf of Tenant Management functionality. Privileged users connect to the Single Connect Desktop Application, choose the Tenants, and access the Tenants devices. The privileged users are able to establish several sessions for different Tenants at the same time. The platform supports parallel Session Management.
- On-Behalf Of Tenant Management: Single Connect supports On-Behalf of Tenant Management functionality for native client tools.
- Log Retention days can be managed based on the tenant.
- The Host Admin can define the VRF options in the Tenant Management module (Tenant Creation and Edit Tenant)
- Multitenancy platform supports PTA (Privileged Task Automation) based on the tenant.
- Multitenancy platform supports Data Access Manager (SQL Proxy) based on the tenant.
- Multitenancy platform supports Tacacs Access Manager based on the tenant.
- Multitenancy platform supports HTTP Proxy based on the tenant.
- Tenants can use their own Backup/Restore functionality.
- VRF support on Tacacs, LDAP Integration and SIEM Integration
- Tenant Connector feature provides Tenant Privileged Users the capability to build a secure connection trough their datacenters in a Secure Tunnel over the internet.
Platform Features
- New Krontech and Single Connect logos applied to the Web GUI.
- Customer may choose to enable/disable React User Interfaces.
- VRF information is added to the Single Connect Desktop Application.
- Desktop Application hides the device name if it is the same as the device IP address.
- New Encryption Key Mechanism:
- The new data encryption is key generated during the Single Connect runtime with a complex key generation function.
- Master Key can be defined in 3 different ways: during the installation, when the operating system is restarted, via an HSM device.
- There is no need to decrypt/encrypt the data when the Master Key needs to be changed.