All pages
Powered by GitBook
1 of 21

オンプレミスSSOコネクト

Keeper SSO Connect is released and downloaded through the Keeper Admin Console.

Please click on the navigation to the left in order to read each release note.

オンプレミスSSOコネクト 17.0.0

2025年2月12日リリース

廃止予定機能のお知らせをご覧ください。

バグ修正

ありません

セキュリティアップデート

  • KSC-433: SAML認証におけるXSSの修正

その他の向上点

  • KSC-392: Windows ServerでのJava 17 LTSのサポートを追加

  • KSC-426: RSA PKCS1 バージョン1.5の非推奨化

オンプレミスSSOコネクト 16.0.8

2023年12月リリース

バグ修正

ありません

セキュリティについてのアップデート

  • KSC-423: Crypto-js CVE-2023-46233のセキュリティの脆弱性

その他の向上点

  • KSC-419: vault/previewを有効な宛先として追加

  • KSC-421: key=parameter形式のECCキーに対応

  • KSC-422: SSO成功/エラー画面の色とスピナーを変更

オンプレミスSSOコネクト 16.0.7

2024年4月10日リリース

バグ修正

  • KSC-411: Androidサポート用に追加のSAML宛先URLが追加しました。この値は、オンプレミス SSOユーザーがPBKDF2反復レベルを変更する際にに使用されます。

  • KSC-395: 「API error: XXX」というエラーメッセージが表示される不具合を修正。

  • KSC-387: TOTP方式による2要素認証で「コードはテキストメッセージで送信されます」という間違ったメッセージが表示される不具合を修正。

セキュリティのアップデート

  • KSC-415: CodeQLに指摘されたSAMLのXML解析のセキュリティを向上

その他の向上点

  • KSC-412: UIでIDプロバイダの一覧を拡充

SSO Connect Version 16.0.4

Released Jan 6, 2022

SSO Connect (On-Prem) Version 16.0.4 contains a security update that is recommended for all customers. This release upgrades SSO Connect Log4j to version 2.17.1.

Important: SSO Connect 16.0.4 requires Java 11 or higher. General SSO On-Prem Upgrade instructions are below:

https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

SSO Connect Version 16.0.3

Released on Dec 16, 2021

SSO Connect (On-Prem) Version 16.0.3 contains a security update that is recommended for all customers.

Important: SSO Connect 16.0.3 requires Java 11 or higher. General SSO On-Prem Upgrade instructions are below:

https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

SSO Connect Version 16.0.2

Released on December 10, 2021

SSO Connect (On-Prem) Version 16.0.2 contains a security update that is recommended for all customers.

Important: SSO Connect 16.0.2 requires Java 11 or higher. General SSO On-Prem Upgrade instructions are below:

https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

Please contact Keeper Enterprise support if you require assistance with the upgrade.

SSO Connect Version 16.0.1

Released on Nov 29, 2021

SSO Connect (On-Prem) Version 16.0.1 contains a security update that is recommended for all customers.

Important: SSO Connect 16.0.1 requires Java 11 or higher. You can obtain Java 11 from either OpenJDK project: https://github.com/ojdkbuild/ojdkbuild General SSO On-Prem Upgrade instructions are below:

https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

SSO Connect Version 16.0.0

Released on Aug 23, 2021

SSO Connect (On-Prem) Version 16.0.0 is a general update that is recommended for all customers. In particular, this updates all libraries and dependencies within the software to the latest stable versions.

Important: SSO Connect 16.0.0 requires Java 11 or higher. You can obtain Java 11 from either OpenJDK project: https://github.com/ojdkbuild/ojdkbuild General SSO On-Prem Upgrade instructions are below:

https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

SSO Connect Version 15.1.1

Released on May 23, 2021

Bug Fixes

  • KSC-367: HSM initial startup can lead to unintentional Service Start

  • KSC-368: Logout from SSO configuration web page does not logout from SSO IdP

SSO Connect Version 15.1.0

Released on April 2, 2021

Bug Fixes

  • Unable to upload a new SSL certificate

  • Security updates

Improvements

  • Support for Australia (AU) region

Upgrade Process

Please follow the upgrade guide for updating the Keeper SSO Connect software: https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

Most issues can be resolved quickly by following the step by step guide.

SSO Connect Version 15.0.1

Released March 15, 2021

Bug Fixes

  • KSC-359: Duo 2FA fails on SSO Connect Admin Console

  • KSC-360: Web socket push connections fail

  • KSC-361: Unable to upgrade Windows via the msi installer

Please follow the upgrade guide for updating the Keeper SSO Connect software: https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

SSO Connect Version 15.0.0

Released March 10, 2021

Improvements

  • Login V3 General Availability (GA) More information available here: https://docs.keeper.io/enterprise-guide/login-api-v3

  • Protection against sync issues between user devices and SSO Connect server, due to a user being deleted or the SSO Connect server losing websocket connectivity.

Bug Fixes

  • KSC-350: Sync issues occurring on the SSO Server

  • KSC-349: An error message should be generated when unable to add JIT user to SSO Connect node

  • KSC-335: Updated 3rd party libraries by either removal or update to latest versions.

  • KSC-358: Updated Jetty version (CVE-2020-27218)

  • KSC-352: Ensure all Data and Folders are deleted upon SSO Connect uninstallation

Upgrading

Please follow the upgrade guide for updating the Keeper SSO Connect software: https://docs.keeper.io/sso-connect-guide/upgrading-sso-connect

SSO Connect Version 14.2.1

Released March 23, 2020

Enhancements & Benefits

  • SSO Connect provides a flow where the login token is returned with the HTTP 301 redirect response.

Bug Fixes

  • Fixed: "New password" field is not appearing when the client sends new password action to SSO Connect.

  • Fixed: The JIT flag is cleared after entering into Configuration and Saving.

  • Fixed: NPE received in Configurator when certificate file can't be read during SKS initialization.

SSO Connect Version 14.2.0

Released on January 3, 2020

Features & Benefits

  • Support for TLS 1.3

  • Support for Amazon AWS CloudHSM v2

  • New "SAML Debug" screen which displays all recent SAML request/response history for troubleshooting purposes.

  • Improved messaging when using a 2FA method such as Google Authenticator

  • Improved debug logging

  • Additional information regarding HSM is displayed on UI of Admin Panel

  • Better handling of service startup when network connection has not been established on the instance

  • Improved handling of AD FS logout to remove error messages in logfile

  • Messaging to notify users when incompatible Java versions are found

SSO Connect Version 14.1.3

Released on December 5, 2019

We have released an update for Keeper SSO Connect, with new security and performance improvements. Please download and update your Keeper SSO Connect to version 14.1.3 by following these steps:

LogoUpgrading SSO ConnectSSO Connect Guide

SSO Connect Version 14.1.2

Released on August 22, 2019

Features & Benefits

  • Just-in-time provisioning ("invite_new_users" property) is now in shared.properties rather than instance.properties. The old setting may remain in instance.properties; it will be ignored.

  • User is now notified in the SSO Connect interface if the SSL certificate is expired or expiring soon. Modified the backend API properties handler to send two new properties: ssl_expires_soon and idp_cert_expires_soon. If true, the UI will turn the appropriate date red on the screen to inform the admin that they need to update the certificate.

  • Modified the “Entity ID” display to filter out :443 if the port is 443. The HTML element is “sp_entity_value”.

Bug Fixes & Security Updates

  • Fixed: UI issue related to ECC signed certificates

  • Fixed: Error if "key_type" parameter missing from config file

  • Fixed: Replaced old Keeper logos with new logo files

  • Fixed: When the user is on the Configuration page and presses "Save", it is possible to get an Alert box in the browser that simply says, "undefined".

SSO Connect Version 14.1.1

Released on July 19, 2019

Features & Benefits

  • UI improvement on the SSO Connect admin panel

  • UI improvement on the installer

  • Improved Safari browser support

  • Additional error handling from the identity provider.

    Now interprets 23 possible StatusCode responses from the IDP, plus the cases of an unknown StatusCode and a missing StatusCode. Any errors are propagated to the Keeper client in the values of the ‘result_code’ and ‘message’ properties which are displayed to the user.

SSO Connect Version 14.1

Released on May 9, 2019

Features & Benefits

  • SSO Connect now has a new configuration parameter: key_type. The value can be “rsa” or “ec” (case-insensitive). This is a shared property so it is stored in the data/shared.properties file.

    It is also synchronized with KeeperApp and shared with other instances.

    We also removed the “key password” dialog box on the Configuration page when the SSL certificate file is in .pfx format. The library we are using assumes that if the file has both a “key store password” and a “key password”, they are the same. So we shouldn’t allow the user to enter a different “key password”.

  • Package Keeper SSO Connect as .msi installer

  • The SAML IDP Metadata standard says that the metadata must contain one SingleSignOn binding, either POST or REDIRECT. Keeper SSO Connect is requiring Redirect. Changed the validator to accept either POST or REDIRECT.

  • Support for password-protected .pfx certificate files

SSO Connect Version 14.0

Released on March 4, 2019. This is a major release update that provides Gemalto HSM integration for on-premise and cloud-based secure key storage.

Enhancements & Benefits

  • Support for Gemalto Luna HSM modules for enhanced key protection

  • Improved README and online documentation

  • Improved reliability and stability

Bug Fixes

  • ​Admin Console login issues with IE and Edge browsers are resolved

  • Switched from Google protobuf to protobuf.js library

Coming Soon

  • ​Version 14.0.0: Support for Gemalto HSM key storage, support for latest Keeper Backend API encryption updates.

SSO Connect Version 12.0.5

Released on January 23, 2019.

Enhancements & Benefits

  • Over 20 bug fixes and improvements to the Keeper SSO Connect application service.

  • Ability to add additional SAML debugging logging

  • Show IDP errors in the UI console in addition to log file

  • Update the user prompts during the config process

  • CLI auto-switches between US and EU regions

  • Improvements to OKTA integration

  • Removed information disclosure related to the internal HTTP server version

  • Removed external Javascript content downloads

Bug Fixes

  • ​User not logged out from IdP (Okta) on Keeper Logout

  • Malformed request on Okta IdP logout

  • UI string fixes

  • CLI switching between US and EU regions

  • Port 443 explicitly configured on the UI not compatible with Okta

  • Inconsistent "ping" status response in HA environments

  • Support <EntitiesDescriptor> at the top level of SAML metadata file

  • OneLogin IdP login failures

  • Full support of SAML data compression according to SAML 2.0 specification

  • Disable client-initiated renegotiation

Coming Soon

  • ​Version 14.0.0: Support for Gemalto HSM key storage, support for latest Keeper Backend API encryption updates.