IBM Support

IBM Security Verify Access v10.0.8 Release Notification

News


Abstract

We are proud to announce the electronic general availability of IBM® Security Verify Access, v10.0.8, and IBM Security Verify Access OpenID Connect Provider v24.04. Available on the 21 June 2024, together bringing a range of enhancements, features, and fixes to the IBM Security Verify Access platform.

Content

IBM Security Verify Access Version (ISVA) 10.0.8

IBM Security Verify Access helps organizations securely manage user access and protect applications against fraudulent and unauthorized access. It operates across web, mobile, and enterprise infrastructure, including network access and Windows and Unix servers.

The 10.0.8 release marks the eighth maintenance release on the v10 platform and delivers the following updates and enhancements:

Verify Access Platform

  • Configuration Container
    Provides a secure, lightweight environment for system configuration, enhancing flexibility and security in enterprise container settings. This feature allows for operation without advanced Kubernetes security contexts, speeds up boot times, and improves system supportability.
  • Reverse Proxy OIDC Relying Party Proof Key for Code Exchange (PKCE)
    Strengthens security in the authorization code flow by supporting PKCE, reducing the risk of interception.
  • OIDC SSO authentication to the Local Management Interface
    Facilitates secure and streamlined logins to the Local Management Interface using external OIDC 2.0 compliant identity providers.
  • Audit, Logging, and Compliance Enhancement
    • Auditing records for command line actions
      Increases transparency and compliance by automatically logging every command line action to the system event log.
    • WebSEAL request log directives
      Allows the inclusion of environment variable values in WebSEAL request logs, improving the granularity and usefulness of audit trails for security and compliance monitoring.
    • Auditing filter
      Enables selective exclusion of events from auditing logs, allowing for more targeted and efficient log management while maintaining compliance with relevant standards.
  • Serviceability Enhancements
    • Global tracing web service and CLI
      Offers administrators the ability to retrieve a comprehensive list of the current tracing status for all components, enhancing diagnostics and troubleshooting capabilities.
    • SFTP access to support files
      Facilitates secure, remote retrieval of support files via SFTP, providing convenient access for administrators to obtain necessary diagnostics and support data.
    • Snapshot manager
      Enhances system maintenance capabilities by allowing for the management of container snapshots, including viewing in JSON format and deletion functionalities to optimize storage and system performance.
    • Container administrator password
      Improves security and administrative ease by allowing environment-based control over administrator password changes, facilitating secure and manageable container operations.
    • Kerberos keytab management
      Facilitates secure authentication processes by enabling the export of Kerberos keytab files, previously only importable.

Advanced Access Control (AAC) & Federation

  • Authentication Policy Import
    Simplifies policy management by allowing the import of authentication policies via bundle files, accelerating deployment and updates across multiple deployments.
  • Managing the runtime server
    Offers direct control over server operations through AAC settings, enabling administrators to effectively manage runtime parameters.
  • Passkey metadata
    Gives administrators visibility into Passkey metadata usage, enhancing security measures and policy enforcement.
  • OTP and SMS Enhancements
    • OTP Enrollment Mechanism
      Introduces a new method for users to enroll in TOTP or HOTP during policy execution, including validation before completion.
    • OTP Policy Configuration
      Extends the configurability of TOTP, HOTP, and MAC OTP mechanisms with new template-level properties and updated policy-level settings, increasing flexibility and control over authentication processes.
    • SMS Gateway Server Connection
      Allows for shared SMS gateway configurations between authentication policies, streamlining setup of SMS-based authentication.
Additional functionality has also been marked as deprecated, for full information and a complete list of features and changes and critical changes in the v10.0.8 release, see What's New in the IBM Documentation.

IBM Security Verify Access OpenID Connect Provider v24.04

The OIDC Provider is a containerized lightweight OIDC provider, which supports advanced OIDC and OAuth standards. It can be deployed and scaled with modern orchestration systems, including Kubernetes.
The v24.04 release adds the following new features to this platform:
  • Support for JWT Bearer Authorization Grant
  • Support for OAuth 2.0 Device Authorization Grant
  • Support for protecting the IBM Security Verify Access OIDC Provider runtime using Mutual TLS
  • Support for monitoring using Instana and Dynatrace
For the formal list of features and changes in the v24.04 OIDC OP release, see What's New in the Documentation.
 
Supporting program and license updates
The IBM Application Gateway is now included as a "supporting program" of some IBM Security Verify Access Licenses. This is a change from the prior component-based delivery, to the 'full product' definition since October 2023.
Note: This update also clarifies that the IBM Application Gateway contributes to 'license consumption'. Users of the IBM Application Gateway must be licensed under and in conjunction with the primary program (IBM Security Verify Access). Similarly it contributes to the consumption of processor (e.g. Base or EE - PVU) licenses when deployed.

Customers operating on Hardware Appliances may use the IBM Application Gateway or OpenID Connect Provider containers under their existing licenses - when using the new container on appliance functionality.
For further clarity, contact your IBM account representative.
Notes and updates from previous releases
  • Supporting software Updates:
    • IBM Security Verify Directory
      IBM Security Verify Access now bundles IBM Security Verify Directory v10.0.
    • IBM Security Directory Server v6.4 and IBM Security Directory Suite v8.0.1 have announced their future end of support dates.

Critical changes

IBM Security Verify Access publishes a dedicated page to capture changes that will likely have a significant impact on a deployment during or after an upgrade.

For more information see: Critical changes

To access a wide variety of technical resources for this product, see the IBM Security Verify Access Version 10.0.8 product documentation in IBM Documentation.
Early Access Program (EAP)
Are you interested in learning more about the new product features planned for upcoming releases of IBM Security Verify Access? Would you like the opportunity to try a Beta version of an upcoming ISVA release and the ability to give feedback regarding new product features? Are you interested in learning about other IBM Security product offerings?
If you answered “yes” to any of these questions, the IBM Security Agile Client Experience (ACE) program might be the right opportunity for you.
The IBM Security ACE program offers a range of early access programs and prototype feedback sessions for selected IBM Security products.
Throughout these interactive programs, the IBM Security development teams deliver resources and/or host sessions. This can provide participants with an insight into the new features that are being designed and implemented.
When you participate in this program, IBM gives you early access to the design and/or features for your evaluation and feedback before the general availability of the new product releases. The overall goal of the Security ACE program is to garner important feedback from participants to help shape the direction of our products. Participation is free of charge. The content of the program is confidential and is available to interested parties who accept the program terms and conditions.
Getting started is easy! Register your interest in joining the program by using this registration form:  http://ibm.biz/security-ace-registration
Downloading the product and assemblies
This version is available from Passport Advantage, Fix Central, and the IBM Container Registry.
This technote details the information required to download and access this release of IBM Security Verify Access and its supporting programs: 
Upgrading and staying in support
IBM Security Verify Access delivers defect and security updates only to the latest current patched (fixed) release. With this release of IBM Security Verify Access, v10.0.8 becomes the ‘current patched release’ where all fixes and patches are delivered to this version. For more information, see this notification: https://www.ibm.com/support/pages/node/6453645
Additional information for IBM Security Access Manager Gen1 hardware appliance
 IBM Security Access Manager Gen1 Hardware Appliances (5122-83K) are now End of Support (30 April 2023). For more information, see this notification: https://www.ibm.com/support/pages/node/872590
Additional information for IBM Security Verify Access Gen2 hardware appliance
IBM announced the end of support date of IBM Security Access Manager and IBM Security Verify Access Gen2 Hardware Appliances (5122-81T) for 30 September 2025. For more information, see this notification: https://www.ibm.com/support/pages/node/872590
Additional information for IBM Security Access Manager v9.0
IBM Security Access Manager v9.0 is now End of Support. For more information, see this notification: https://www.ibm.com/support/pages/node/6452057.

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSRGTL","label":"IBM Security Verify Access"},"ARM Category":[{"code":"a8m0z000000cxuHAAQ","label":"Security Verify Access"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0.8"}]

Product Synonym

IBM Security Verify Access; IBM Security Access Manager; ISAM; ISVA;

Document Information

Modified date:
20 June 2024

UID

ibm17154812