News
Abstract
We are glad to announce the electronic general availability of IBM® Security Verify Access, Version 10.0.4 on June 24, 2022, bringing a range of enhancements, features, and fixes to the Verify Access platform.
Content
IBM Security Verify Access Version 10.0.4
IBM Security Verify Access helps organizations securely manage user access and protect applications against fraudulent and unauthorized access across web, mobile, and enterprise infrastructure, including network access and Windows and Unix servers.
The 10.0.4 release marks the fifth release on the v10 platform and delivers the following enhancements:
- Migration tool for IBM Application Gateway
A new tool is available on the LMI to export reverse proxy configuration and junctions to an IBM Application Gateway (IAG) deployment. Rapidly move your legacy protected applications onto the containerized IAG platform with simplified configuration and management. - New and improved HTTP Transformation Rules
New in this release, is the ability to write transformation rules using Lua. A range of scripting utilities have been included, including the new ability to modify a request and response body.
Note: Backwards compatibility with XSLT based rules, continues to be available. - FIDO2/WebAuthn Support improvements
IBM Security Verify Access can now integrate with the FIDO Metadata Service v3 and has an out-of-the-box scenario for solicited in-line platform authenticator registration and authentication. - Integrations with major application servers
IBM Security Verify Access major application server integrations have been refreshed and are now available on the documentation hub. - Instana Monitoring
IBM Security Verify Access supports the Instana platform for monitoring, with the plugin soon to be available through the IBM Security Application Exchange. - Content Security Policy
Improved default content security policy stance across all the standard template pages. - HSM Support in container deployments
IBM Security Verify Access containers can now function against Luna HSMs in a container environment, bringing enhanced security to Kubernetes and OpenShift deployments of Verify Access. - Amazon Web Services (AWS) Updated Platform Support
IBM Security Verify Access Virtual appliances are now available for the current generation instance types.From version 10.0.4 onwards, the Verify Access image is only available to deploy on instances which are powered by the AWS Nitro System hypervisor. - Open banking and FAPI Support
IBM Security Verify Access OIDC framework formally support some of the latest standards and specifications from the OpenID foundation. Additional detail will be shared pending its formal certifications. - New Web Application Firewall component (Beta)
With the end of life announced (end of December 2022) on the existing Web Application Firewall powered by the IBM PAM component, v10.0.4 introduces a new web application firewall capability –to replace this functionality. If you would like to try this feature out or want more details–join our Early Access Program –detailed below.
For a more complete list of features and changes in the v10.0.4 release, see What's New in the IBM Documentation.
Critical changes
IBM Security Verify Access now publishes a dedicated page to capture changes that will likely have a significant impact on a deployment during or after an upgrade. See Critical changes.
To access a wide variety of technical resources for this product, see the IBM Security Verify Access Version 10.0.4 product documentation in IBM Documentation.
Since v10.0.0, entitled customers of IBM Security Verify Access can make use of the IBM Application Gateway to access and protect applications. The IBM Application Gateway is an ultra-lightweight container deployment of the reverse proxy, with declarative configuration and without any runtime dependencies on a policy server or LDAP server. Authentication is performed using a Verify Access OIDC OP deployment (or IBM Security Verify SaaS). For more information about the IBM Application Gateway see the documentation hub.
Are you interested in learning more about the new product features planned for upcoming releases of IBM Security Verify Access? Would you like the opportunity to try a Beta version of an upcoming IBM Security Verify Access release and the ability to give feedback regarding new product features? Are you interested in learning about other IBM Security product offerings?
If you answered “yes” to any of these questions, the IBM Security Agile Client Experience (ACE) programmay be the right opportunity for you.
The IBM Security ACE program offers a range of early access programs and prototype feedback sessions for selected IBM Security products including IBM Security Verify Access.
Throughout these interactive programs, the IBM Security development teams deliver resources and/or host sessions to provide participants with an insight into the new features that are being designed and implemented.
When you participate in this program, IBM gives you early access to the design and/or features for your evaluation and feedback before the general availability of the new product releases. The overall goal of the Security ACE program is to garner important feedback from participants to help shape the direction of our products. Participation is free of charge. The content of the program is confidential and is available to interested parties who accept the program terms and conditions.
Getting started is easy! Please register your interest in joining the program using this registration form: http://ibm.biz/security-ace-registration.
Version 10.0.4 is available from Passport Advantage, Fix Central, and Docker Hub.
This technote details the information required to download and access the v10.0.4 release of IBM Security Verify Access and its supporting programs: https://www.ibm.com/support/pages/node/6562133
IBM Security Verify Access only delivers defect and security updates to the latest current patched (fixed) release. With the release of IBM Security Verify Access v10.0.4, 10.0.4 becomes the ‘current patched release’ where all fixes and patches will be delivered to v10.0.4. For more information, see this notification: https://www.ibm.com/support/pages/node/6453645.
In case you missed it, IBM has announced the end of support date of IBM Security Access Manager Gen1 Hardware Appliance(5122-83K) for April 30, 2023. For more information, see this notification: https://www.ibm.com/support/pages/node/6452057
In case you missed it, IBM Security Access Manager v9.0 is now End of Support. For more information, see this notification: https://www.ibm.com/support/pages/node/6452057.
[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSRGTL","label":"IBM Security Verify Access"},"ARM Category":[{"code":"a8m0z000000cxuHAAQ","label":"Security Verify Access"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0.4"}]
Was this topic helpful?
Document Information
Modified date:
24 June 2022
UID
ibm16594449