3.1.0 Release Notes
8 min
This section provides information on the major features, fixes, and changes introduced in the new release 3.1.0 for Single Connect.
Contact Us
Contact us at [email protected]. Please note that only registered users can contact the support team.
Release Information
Release Summary
Below is a list of changes, fixes, and features in the 3.1.0 version of Single Connect..
Logging and Reporting
- The latest version of the reporting platform is available in Single Connect. Existing charts and dashboards have been transferred to the latest version.
- For the HTTP proxy, the client IP address is available in the session logs even if a load balancer is configured in front of the Single Connect..
- The client IP address is accessible from the Single Connect GUI even if a load balancer is configured in front of the Single Connect.
Privileged Access and Governance
- Unique Identifier Approval ID is set for all SAPM access and governance requests. The Approval ID is available in each step of the approval from each touchpoint.
- Access governance requests can have a timeout value defined for the entire process. Single Connect now allows privileged administrators to define the actions to be taken in the event of a timeout.
- Single Connect Mobile Application now shows more details about connection approval requests.
Privileged Credentials Management
- Required certificates for the APIs are now defined in the Single Connect secure vault.
- UX Enhancements:
- If the account is defined as STATIC, the Change Period field is no longer displayed in the GUI.
- If the privileged user wants to delete the accounts in the New User Log screen, the privileged user is prompted twice for confirmation.
- Assigned Credentials for SAPM show the IP address of the related SAPM account.
- Login parameters can now be set in HTTP configuration and Single Connect can use these parameters to connect.
- Single Connect can manage (randomize) Windows Server local account passwords using the AD account and Windows Server credentials that are already managed by Single Connect.
Privileged Session Manager
- SSH Proxy:
- The client IP address is now available in Single Connect Web GUI.
- Auth Script feature is now available for each endpoint.
- When an Auth Script is configured on the device-group level, Single Connect can match the SAPM account of each device with the IP address and run the same Auth Script with the SAPM account that belongs to the device.
- HTTP Proxy:
- MFA protection now works for each HTTP proxy session independently even though attackers capture user credentials and mimic the user's network fingerprints.
- The pass-through feature is available for the HTTP proxy. The HTTP proxy can log all the activities without applying any restriction to the web addresses.
- The HTTP proxy authentication mechanism is renewed, improving the security posture.
- A multiple credential selection feature is now available for websites using XHR requests.
- If configured, the current session user is accessible in the user selection list, similar to other proxies.
Multi-Factor Authentication
- Privileged Users can choose their OTP preference (SMS or Mobile App) by themselves.
- The Single Connect admin can select the OTP preference (SMS or mobile app) for the user groups. If the privileged users set their own preferences, Single Connect executes users' choices.
- The configurable timeout parameter is available for SMS OTPs.
Multitenancy
- A prevention mechanism is released for misconfiguration on LDAP integration between the Host and the Tenant.
Platform Features
- The policy key type Privileged Task feature has been retired.
- New UI is available for Desktop Applications and Mobile Applications with new Single Connect logos & color palettes.
- New logos & color palette is available for Single Connect Web GUI.
- Registering Token feature on Single Connect Mobile App is now protected with MFA OTP.
- The alarm messages can now be sent with the “High Importance” flag in the Alarm & Monitoring module.
- High availability (watchdog) management has been improved for the case when the database is down and the application is running on a specific node; the watchdog manages this case and behaves as if the application was down on that node.
- The master key can now be changed after the Single Connect installation.