What's New
version 25 1 3 1 rsa authentication manager 8 8 support for rsa authentication manager 8 8 is qualified as part of the validation for ics 25 x as a result, users who have upgraded to rsa authentication manager 8 8 will be able to use this functionality with ics 25 1 3 1 for rsa authentication manager 8 8 and newer versions, ivanti recommends using the new rsa (rest api) authentication server, see using a rsa server (rest api) docid\ xspmmkliydjkgpv mrnqi version 25 1 3 0 automated certificate management environment (acme) support ics now supports the automated certificate management environment (acme) protocol, enabling automated certificate enrollment, renewal, and lifecycle management this reduces administrative overhead associated with certificate maintenance and helps simplify certificate operations, see acme server docid\ q5tn0rv6w3ngbn7wg4tge oauth group claims for role mapping ivanti connect secure (ics) now supports role mapping based on group claims received from oauth providers such as microsoft entra id (azure ad) administrators can use group information included in the oauth id token or userinfo response to assign user roles within ics user realms, see oauth group claims role mapping docid\ njc3m md5dcwo94zhduxq windows hello for business (whfb) single sign on enhancements this release includes enhancements to windows hello for business (whfb) single sign on functionality, providing improved integration with modern authentication workflows and passwordless authentication deployments, see windows hello for business sso server docid\ xspmmkliydjkgpv mrnqi fido2 authentication enhancements ics has been enhanced to support fido2 related authentication improvements, enabling support for modern passwordless authentication methods and strengthening identity security, see fido2 support for mobile isac docid\ fca2 nllsvwvdtbtpizvf http/2 ingress support in nginx nginx has been enhanced to support http/2 for inbound client connections http/2 provides improved connection efficiency and performance through multiplexing and optimized protocol handling, see http protocol configuration docid\ fca2 nllsvwvdtbtpizvf health check diagnostic logs a new health check diagnostic logging capability has been added to improve visibility into system health monitoring operations administrators can use these logs to assist troubleshooting and operational diagnostics, see rest api diagnostic logs and healthcheck diagnostic logs docid l4b156w5wogzec2josty default vlan id support with ipv6 on internal interfaces ivanti connect secure now supports the use of the default vlan id when ipv6 is configured on the internal interface this enhancement ensures that the default vlan id remains available and functional when both ipv4 and ipv6 are enabled, see default vlan id docid\ fca2 nllsvwvdtbtpizvf host header validation ivanti connect secure now provides a console based option to disable host header validation on the management interface, see host header validation docid\ wif9nf5azei8keco6sizv rest api diagnostic logs a new rest api diagnostic logging capability has been added to improve visibility into system health monitoring operations administrators can use these logs to assist troubleshooting and operational diagnostics, see rest api diagnostic logs docid l4b156w5wogzec2josty configurable certificate challenge timeout administrators can now configure the maximum interval between certificate challenge exchanges during the pre authentication phase of certificate based authentication the timeout value can be set from 1 to 4 minutes, with a default value of 1 minute, see certificate challenge timeout docid\ nlmek44 rtzxgrnbf7dv3 version 25 1 1 0 dsidid enforcement for secure vpn authentication dsidid enforcement ensures secure vpn authentication by verifying both dsid and dsidid cookies this provides an additional layer of device and session validation, enhancing overall security, see configuring miscellaneous security options docid\ fca2 nllsvwvdtbtpizvf proxy servers for psam connections ics now supports proxy server for connections to psam destination (tcp only) via proxy servers administrators can modify existing policies to route traffic through proxy servers, enhancing both security and scalability, see proxy servers for psam connection docid\ iixfpddqb3weawsarzoal source ip and geo location access restriction allow administrators to configure and enable both geo location and manual ip lists simultaneously this enhancement improve ics security by allowing customers to better restrict access from bad actors while permitting legitimate traffic, see / / /22 7r2 11/ics adminguide/content/general access management htm#general access management 28561674 1012043 docid\ gopxhyb7c9dl5i6zhuvnp specifying source ip restrictions at the realm level docid\ fca2 nllsvwvdtbtpizvf fallback authentication server ics now supports configuring authentication fallback options within any user realm currently, the available fallback option is totp (time based one time password) this means if the primary authentication methods such as certificate, ldap, or active directory fails, users can use totp as a backup method, see / / /22 7r2 11/ics adminguide/content/auth realms htm#select docid\ gopxhyb7c9dl5i6zhuvnp fallback authentication server docid\ njc3m md5dcwo94zhduxq samsung knox manage this feature enhances security by ensuring that only authorized android devices are permitted access based on validated device identifiers, see configuring an mdm server docid\ xspmmkliydjkgpv mrnqi version 25 1 0 0 rotate internal storage key \ this process encrypts sensitive information like passwords when storing them internally and ensures the encryption key is unique and random for every ics instance, see rotate internal storage key docid\ wif9nf5azei8keco6sizv security enhanced waf operation this feature protects connect secure gateway web applications by filtering and monitoring http traffic, preventing attacks such as sql injection, cross site scripting (xss), and other web exploits, see configuring web application firewall ui docid\ wif9nf5azei8keco6sizv and security enhanced waf operation console docid\ wif9nf5azei8keco6sizv shared secret key this feature configures a shared secret for each source/target pair at time of creation of push config target, see configuring targets docid\ l7wkyx0b0ax0kejqyud6t password key generation new api's introduced to generate and fetch the password key, see apis https //help ivanti com/ps/help/en us/ics/22 x/apig/rest api soln guide/ics spec configs using restapis htm#generate2 next generation web server the next generation web server has been developed to enhance the performance and scalability of web server infrastructure, see next generation web server docid\ wif9nf5azei8keco6sizv web server logs are implemented for web related event codes with debug severity, see using the debug log docid e 11 dzbhgfjweit0nz selinux security policy the ics system provides an enforcing only selinux capability, ensuring that even the root user or admin cannot switch selinux to permissive mode without rebooting the system, see selinux security policy docid\ wif9nf5azei8keco6sizv verbose log administrators can toggle selinux verbose logging to control the detail level of selinux related logs, see selinux verbose log docid\ wif9nf5azei8keco6sizv
