The IDR 12.22.0.0.37 release includes improvements to the IDR software upgrade process. It also features Tomcat upgrade and removal of no-company-specific URLs.
Tomcat Upgrade
IDR v12.22.0.0.37 now runs Tomcat v9.0.98, which includes a fix for the critical vulnerability identified as CVE-2024-56337.
Removal of Non-Company-Specific URLs from IDR
Access through non-company-specific URLs will soon be disabled. This change involves replacing the URLs used by the IDR to connect to the Software Update Repository and Adapter Update Repository with company-specific URLs. To ensure uninterrupted access, add the company-specific URL to your firewall's allow-list.
To determine if you are impacted, sign in to the Cloud Administration Console, navigate to Platform > Identity Router, and expand the Identity Router section to view the Status Indicators.
The Software Update Service/Adapter Update Service Status Indicator includes three statuses:
- The first two statuses check the IDR's connectivity through region-specific URLs.
- The newly introduced third status, Company Specific URL, verifies connectivity through the company-specific URL.
If the Company Specific URL status shows as healthy, no action is needed. However, if it is unhealthy, check your firewall rules to ensure the company-specific URL is included in the allow-list.
RSA recommends adding the wildcard access domain name (*.{baseAccessDomainName}.securid.com) to your firewall’s allow-list. If it is already listed, no further action is required. If not, you must add the company-specific URL to the allow-list to maintain uninterrupted access.
Company-specific URL format: companyName.{baseAccessDNSName}.securid.com
Company-specific URL format for GOV deployment: companyName.access.securidgov.com
Example: If the company name is rsa-dev in US deployment, then the company-specific URL will be: rsa-dev.access.securid.com.
Refer to the following table for baseAccessDNSName.
| Deployment | baseAccessDNSName |
| US | access |
| GOV | access |
| ANZ | access-anz |
| EMEA | access-eu |
| India | access-in |
| Japan | access-jp |
| Canada | access-ca |
| Singapore | access-sg |
Related Articles
Transitioning to Company-Specific URLs in RSA Authentication Manager (AM) 43Number of Views Company-Specific Administrative URLs Update Instructions 313Number of Views What to expect during an RSA SecurID Access Identity Router (IDR)/Cluster software update 594Number of Views Identity Router (IDR) Version 12.22.x Rollback and Update Announcement 117Number of Views Can an upgraded RSA SecurID Access Identity Router be rolled back to a previous version? 66Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x