News
Abstract
We are glad to announce the electronic general availability of IBM® Security Verify Access, Version 10.0.5 on December 09, 2022, bringing a range of enhancements, features, and fixes to the Verify Access platform.
Content
IBM Security Verify Access Version 10.0.5
IBM Security Verify Access helps organizations securely manage user access and protect applications against fraudulent and unauthorized access across web, mobile, and enterprise infrastructure, including network access and Windows and Unix servers.
The 10.0.5 release marks the fifth release on the v10 platform and delivers the following enhancements:
- Container Registry Changes
IBM Security Verify Access containers are no longer be available on Docker Hub after 31 December 2022.IBM Security Verify Access no longer hosts images on Docker Hub after 31 December 2022. All images are accessed from their new location on IBM Cloud® Container Registry.
This change is a breaking change to many automated deployment pipelines, and administrators must validate and modify their container deployment routines to source these containers from their new location.
For full information on the IBM Security Verify Access Container locations, use one of the following URLs. - Support License - no longer required or issued
The Flexera/Flexnet powered IBM Security License Key and Download Center service used with IBM Security Verify Access - ISVA (and IBM Security Access Manager – ISAM) will be shut down after December 28th, 2022. The associated license files will not be issued or available from this service after this time. This will not have any effect on the products functionality or ability to raise a support ticket. Earlier versions of IBM Security Verify Access will require updates to be downloaded by administrators from IBM Fix Central. For more information, see the following technote. - Multi-JDK support for PD.jar
The Policy Directory Java™ library (PD.jar) has been updated to support both IBM® Java 1.8 and OpenJDK 11. Previously, administrators were required to use the legacy version of PD.jar for versions of Java lower than 11. Now administrators are no longer required to move to Java 11 to use the latest version of PD.jar. For more information about using PD.jar to retrieve information from the runtime user registry/policy server, see the Administration Java classes overview. - SafeNet Luna High Availability (HA) support
Support for SafeNet hagroup configurations was added to Verify Access. Administrators who install the SafeNet HSM Extension from IBM App-Exchange can group one or more SafeNet devices into an HA group. For more information about configuring HSM devices, see Configuring network Hardware Security Module (HSM).
- AAC Authentication Policy JSON API
A new API was added to the Local Management Interface (LMI) that represents AAC Authentication Policies as JSON. Previously, the policy itself was represented solely as XML. For more information about the API and usage examples, see the WebServices documentation that is available from the appliance LMI. Apply the filter “Full JSON API” to show the appropriate pages for the new API.
- AAC Access Control Policy JSON API
A new API was added to the Local Management Interface(LMI) that represents AAC Access Control Policies as JSON. Previously the policy itself was represented solely as XACML 2.0. For more information and usage examples, see the WebServices documentation that is available from the appliance LMI. Apply the filter “Full JSON API” to show the appropriate pages for the new API.
- SCIM User Password Schema
It is now possible for a user to change their password by using the SCIM API without the need for a two-phase update process. See User password change and recovery.
- Identifier First Authentication Scenario
A new scenario is now available in the Example Branching Policy Scenarios wizard, called Identifier First Authentication. This scenario initially prompts the user only for their username. The user is then able to choose between FIDO2/WebAuthn authentication, MMFA authentication, or standard username and password authentication. For more information, see Scenarios.
- FIDO2 Mediation
In the FIDO2 custom mediator, two new properties can be accessed from the registration object
backupEligibilityandbackupState. Both relate to the backup of the public key credential source of a registration. For more information, see FIDO2 Mediation. - JavaScript Allowlisted Classes
In the available JavaScript classes, two new methods are available in the following two classes
com.tivoli.am.fim.registrations.local.FIDORegistrationandcom.tivoli.am.fim.fido.mediation.FIDO2Registration. They both now provide getter methods forbackupEligibilityandbackupState. For more information, see JavaScript allowlist. -
Template Files
In the management of template files, directories can now be created at the root level. For more information, see Managing template files.
IBM Security Verify Access OpenID Connect Provider
In September 2022, a new dedicated OIDC Component was released.
Critical changes
IBM Security Verify Access now publishes a dedicated page to capture changes that will likely have a significant impact on a deployment during or after an upgrade. See Critical changes.
Product Synonym
IBM Security Verify Access; IBM Security Access Manager; ISAM; ISVA;
Was this topic helpful?
Document Information
Modified date:
01 March 2023
UID
ibm16842013