Release Notes Archive - Cloud Authentication Service and Authenticators (March 2024 - January 2024)
a day ago

March 2024 - Cloud Authentication Service

Cloud Authentication Service Updates

The following sections provide information on the new and enhanced features of the Cloud Authentication Service (CAS).

CAS Now Supports OATH HOTP Hardware Authenticators

The Cloud Administration Console now allows administrators to view and manage OATH HOTP hardware authenticators. They can upload OATH HOTP OTP seed files to the Cloud Administration Console and assign authenticators to users. Consequently, users can self-register, activate, and manage their tokens in My Page. Supported models are listed in the Cloud Administration Console when seeds are imported. For requesting support for additional HOTP models, administrators can contact RSA Technical Support.

 

New Identity Source Attribute – Manager

A new user identifier attribute, Manager, is now available in LDAP and Active Directory identity sources. In the Cloud Administration Console, administrators can configure and synchronize the Manager attribute for user accounts within LDAP and Active Directory identity sources. This attribute enables administrators to specify users' managers and identify to whom they report. In addition, the All Users report now includes a new column for the Manager attribute.

 

Enhanced Verbose Logging in the Cloud Administration Console

For more comprehensive logging, verbose logging now includes the Cloud portal Single Sign-On (SSO) related events, for example, user login events. Administrators can monitor user authentication events for applications and relying parties by selecting the Include Verbose Logs option on the User Event Monitor page.

Automatically Prefilled User ID Field on Login Authentication Page

When a user authenticates to a protected resource using FIDO, Emergency Access Code, or SecurID OTP authentication methods, their User ID is now stored on the login screen via a browser cookie. This enhancement ensures that the User ID input field is automatically pre-filled when a user attempts to log in again.

 

Upcoming End of Primary Support (EOPS) Details

The following table provides details of the RSA products reaching the end of support within the next six months:

 

ProductVersionEOPS DateExtended Support Level 1/Level 2
Authenticator for Windows6.1.1August 2024No
RSA Authentication Manager8.6August 2024August 2025/August 2026
SDK for iOS and Android3.1June 2024No
2.5 (iOS)
2.8 (Android)
Authentication Agent for Microsoft Windows7.4.xJune 2024No
MFA Agent for Microsoft Windows2.1.xJune 2024No
Authenticator App for iOS and Android4.2June 2024No
4.1.xJanuary 2024No
Authenticator App for macOS5.0March 2024No
Authentication Agent for Citrix StoreFront2.0.xMarch 2024No
Authenticate App for iOS and Android3.9.xMarch 2024No

 

Third-Party Integrations from RSA Ready

The following integrations are recently completed or certified by RSA through the RSA Ready Technology Partner Program. Implementation Guides will be coming soon. For the complete catalog of Implementation Guides, see RSA Ready Integrations on the RSA Community.

• 1Password (new) – supports RSA Cloud Authentication Service using OIDC.

• Barracuda (update) – added support for the Authentication Manager using REST.

• ForgeRock Identity Cloud (new) – now supports RSA Cloud Authentication Service using SAML.

• Google Workspace (update) – added support for My Page SSO using SAML.

• Salesforce Slack (update) – added support for My Page SSO using SAML.

 

Fixed Issue

The following table lists the issue that is fixed for this release:

Fixed IssueDescription
NGX-141056                

On an Identity Router (IDR) status page, both the Notification service and Authentication Manager displayed incorrect statuses after the deployment of Authentication Manager (AM) 8.7 SP2. The Notification service was labeled as "Unhealthy" and the Authentication Manager as "Partially Healthy."

Support for the Notification service will be added in IDR version 12.20.0.0. Until then, the status for the Notification service will be "N/A," with no impact on the overall status of AM.

 

Known Issues

The following table lists the known issues in this release:

Fixed IssueDescription
NGX-142597                           In the Cloud Administration Console, enabling the Use Single OTP Web Authentication Page option under My Account > Company Settings > Sessions & Authentication displays the new OTP Web Authentication pages only in English. Currently, these OTP Authentication pages are not available in all supported languages. However, they will be localized for all supported languages in the April release.
NGX-144061On the Assurance Levels page, the new authentication method 'OATH HOTP' for OATH HOTP Hardware Authenticators is currently visible but is not yet available for use until the March release is rolled out.
The OATH HOTP method will become available for use in the March release.

 

February 2024 - Cloud Access Service

Cloud Authentication Service Updates

The following sections provide information on the new and enhanced features of the Cloud Authentication Service (CAS).
  

Disabled Use of FIDO Synced Passkeys

In the Cloud Administration Console, the use of FIDO synced passkeys for authentication is now disabled by default. If you want to enable users to use FIDO synced passkeys, select the Allow the use of FIDO syncable passkeys option on the Access > FIDO Authentication page. However, RSA recommends that you leave this option cleared. For more information, see the "Configure FIDO Synced Passkey Settings" section on the FIDO Authentication and Custom App Authentication page.
  

Configure My Page Enrollment Policy

In the Cloud Administration Console, administrators can now enable the My Page Enrollment Policy setting to verify users and manage how they register an authenticator using secure enrollment. For the My Page enrollment policy, administrators can create and define rule sets targeted at specific user populations for different user verification methods.

Note:  This feature is currently available in limited release. If you are interested in securely enrolling users to their RSA authenticators with an ID proofing method, please contact your RSA Sales Representative.
  

Reminder: Maintain Custom Domain Certificates

Administrators need to replace or update a custom domain certificate before it expires to avoid any disruption. Expired certificates will cause traffic to a custom domain to stop working. For more information, see Customize and Configure Domain Name.
  

New Builds for RSA SDK 4.0 for iOS and Android

New builds were released for RSA SDK V4.0 for iOS and Android. In the RSA SDK 4.0 for iOS build 4.0.6, the 'PrivacyManifest' was introduced in Xcode 15. In the RSA SDK 4.0 for Android build 4.0.2, the SDK was split into parts. For more information, see RSA SDK Documentation.
  

Upcoming End of Primary Support (EOPS) Details

The following table provides details of the RSA products reaching the end of support within the next six months:

ProductVersionEOPS DateExtended Support Level 1/Level 2
Authenticator for Windows6.1.1August 2024No
RSA Authentication Manager8.6August 2024August 2025/August 2026
SDK for iOS and Android3.1June 2024No
2.5 (iOS)
2.8 (Android)
Authentication Agent for Microsoft Windows7.4.xJune 2024No
MFA Agent for Microsoft Windows2.1.xJune 2024No
Authenticator App for macOS5.0March 2024No
Authentication Agent for Citrix StoreFront2.0.xMarch 2024No
Authenticate App for iOS and Android3.9.xMarch 2024No
Authenticator App for iOS and Android4.2June 2024No
4.1.xJanuary 2024

 

Third-Party Integrations from RSA Ready

The following integrations are recently completed or certified by RSA through the RSA Ready Technology Partner Program. Implementation Guides will be coming soon. For the complete catalog of Implementation Guides, see RSA Ready Integrations on the RSA Community.

  • Absolute Secure Access (update) – added support for the Cloud Authentication Service using SAML.
  • AWS (update) – added support for My Page SSO using SAML.
  • Dell Unisphere for PowerMax (new) – support for Authentication Manager using RSA MFA API (REST).
  • Microsoft Azure AD (update) – added support for the Cloud Authentication Service using SCIM.
  • Shibboleth IDP (update) – added support for My Page SSO using SAML.

 

Fixed Issues

The following table lists the issues that are fixed for this release:

Fixed IssueDescription
NGX-139101
NGX-138226
A script error occurred when logging into Citrix Secure Access. Certain JavaScript code was not supported by the Internet Explorer browser. This issue has been fixed. 
NGX-133737When Code Matching was used for Approve notification, user authentications sometimes failed.
NGX-137901When accessing the My Page Self-Service portal via mobile devices, some dialogs were not completely visible. 

 

January 2024 - Cloud Access Service

Cloud Authentication Service Updates

The following sections provide information on the new and enhanced features of the Cloud Authentication Service (CAS). 

Publish Changes to the Cloud Authentication Service Faster 

In the Cloud Administration Console, the Publish Changes button will no longer publish changes to an identity router (IDR) if the changes do not affect that IDR, thereby reducing publish time. For example, when you edit RSA My Page customizations, the changes will be published only to the Cloud Authentication Service.
The new "Force Publish to all IDRs" option is now available on the Publishing Status page so that administrators can publish changes to the Cloud Authentication Service and all registered Identity Routers to resend the current configuration settings to each IDR or to resolve an IDR's issue (if any).

Register Multiple FIDO Authenticators

Users can now register a maximum of five FIDO authenticators using the RSA My Page to still log in if their primary authenticator is unavailable. On the My Page > My Authenticators page, users can view all their registered FIDO authenticators.
In the Cloud Administration Console, administrators can view a user's registered FIDO authenticators on the Users Management > a user's details page. In the "All Users" report, a new column, titled "Number of FIDO Authenticators", has been added to help administrators view the number of registered FIDO authenticators per user. Moreover, administrators can enable the option to automatically send an email notification when users register a FIDO credential on the My Account > Company Settings > Email Notifications page.

A New Unified View of Usage Information in the Cloud Administration Console Dashboard

In the Cloud Administration Console, the Usage Information dashboard has been enhanced with a unified view of total users and credentials of both Cloud Authentication Service (CAS) and on-premises Authentication Manager (AM) for your hybrid deployments. To display the unified view, the connection between the Cloud Authentication Service and Authentication Manager needs to be established. A new, refreshed look and feel has been developed to visually present the Cloud-only data when there is no AM and CAS connection. 
Note: To view the unified usage dashboard with on-premises information, you need to upgrade your Authentication Manager to 8.7 SP2, scheduled for release by the end of January 2024.

  

Enable Approve and Biometrics Code Matching Feature

Administrators can now enable Code Matching with different modes, even if the various components in their environment (Authenticators or Agents) do not support it for Approve and Biometric notifications. Once this feature is enabled, Code Matching is then used for a given authentication event only if both the Agent and the Authenticator app involved support the configured mode.

Enable Saving Primary Authentication Method Preference

In the Cloud Administration Console, administrators can now enable the option to save a user’s last successfully used primary authentication method and its associated policy as their preferred one in a browser cookie. Therefore, when a user attempts to authenticate again, they will be prompted to use the same saved primary authentication method.

Customize Cloud IdP User Instructions

Administrators can now add Cloud IdP instructions or text displayed during authentication. Users can easily perform Primary Authentication via Cloud IdP by following the displayed on-screen instructions during authentication.

Access Policies Terminology Changes in the Cloud Administration Console

In the Cloud Administration Console, terminology changes have been made to the UI labels of access policies. These changes aim to create a more unified and standardized experience while managing your access policies for authentication. For example, when you add a Microsoft Azure Directory Relying party, in the Authentication tab, the “Access Policy for Additional Authentication” label has been changed to “1.0 Access Policy for Additional Authentication”. In addition, when you add an application, in the User Access tab, the “Select a policy” label has been modified to “Select a 1.0 policy”.

MFA Agent Citrix StoreFront V3.0 Now Released!

MFA Agent Citrix StoreFront V3.0 is now released with the following features:

  • New and intuitive user interface for an enhanced user experience, with new terminology adapted.

  • Support for Emergency Access Code as a new method and enhanced Approve and Biometrics methods to support Confirmation Code. 

  • Enhanced Agent settings interface allows easy configurations relevant to the Cloud Authentication Service (CAS) and Authentication Manager (AM) using the Server and Advanced tabs.
  • Support for Authentication Manager failover (The Agent can switch to AM replicas in case of AM failure when using AM as a secure proxy to connect to CAS).
  • Ability to enable WPI either during installation or by using configuration settings after installation.
  • Enhanced Agent reporting.
  • Support for silent mode installation and upgrade.
  • Deprecated UDP connection to Authentication Manager and risk-based authentication (RBA) support. For more information, see Deprecated Features for RSA MFA Agents.

Upcoming End of Primary Support (EOPS) Details

The following table provides details of the RSA products reaching the end of support within the next six months:

ProductVersionEOPS DateExtended Support Level 1/ Level 2
Authentication Agent for Microsoft Windows 7.4.xJune 2024No
MFA Agent for Microsoft Windows2.1.xJune 2024No
Authenticator App for macOS5.0March 2024No
Authentication Agent for Citrix StoreFront2.0.xMarch 2024No
Authenticate App for iOS and Android3.9.xMarch 2024No
 Authenticator App for iOS4.2June 2024 No
 
4.1.5January 2024
4.1.0 
 Authenticator App for Android4.2June 2024  No
4.1.6January 2024
4.1.0

Identity Router Update Schedule and Versions

This release includes miscellaneous identity router improvements. Identity routers will be updated according to the following schedule. Downloading the new identity router image when you deploy new identity routers ensures you benefit from the latest security improvements.

DateDescription
AU: 3/11/2024Updated identity router software is available to all customers.
EU / IN: 3/13/2024
NA: 3/14/2024
Gov: 3/14/2024
Saturday 4/20/2024 Default date when identity routers are scheduled to automatically update to the new version unless you modify the update schedule or update manually.
Saturday 5/18/2024  If you postpone the default date, this is the last day when updates can be performed.

Note: Please update all your IDRs to v12.19 before the updated identity router software is available in your region and ensure that the IDRs have no reachability issues with the region-specific domain names before May 2024. For more information, see View Identity Router Status in the Cloud Administration Console . 

The new identity router software versions are:

Identity Router Deployment TypeVersion
On-premises12.20.0.0
Amazon CloudRSA_Identity_Router 12.20.0.0

 

Fixed Issues

The following table lists the issues that are fixed for this release:

Fixed IssueDescription
NGX-138067

An identity router failed to connect to the Cloud Authentication Service in the USEAST region. The hostname was not resolving  and had a different format than the expected one. 

NGX-132415

A customer could not reset their LDAP password. The following error message was displayed: Unable to change the password. Please contact your administrator for assistance.

NGX-131144

NGX-129486

Some security vulnerabilities were fixed in identity routers portals. 

NGX-130202

A customer's identity router stopped responding, although its status was Active in the Cloud Administration Console.

NGX-122833

A customer reported that they could not connect their embedded identity router to the Cloud Authentication Service.  There was a DNS error. 

NGX-118058

A customer reported that their identity routers’ status changed to distressed and encountered “too many open files” errors when they tried to restart their IDRs. 

 

Known Issue

The following table lists the known issue in this release:

Known IssueDescription
NGX-143918Issue: After upgrading the IDRs, the Test Connection of an identity source failed. The error message displayed states: "Error occurred while connecting to the directory server. Unable to connect to Active Directory server. Review the configuration details." This issue impacts the Test Connection functionality but not authentication or other IDR services.
Resolution: Restarting the IDR resolves this issue.