Skip to Content

Oplon Secure Access Full Changelogs

Oplon Secure Access · Download

12.4.0

August 10, 2026

Workspaces

  • Fixed
    • Fixed some typos
    • Fixed some fields that were number insted of text
    • Fixed showing "last password change" in OSA Vault

RAG

  • Added
    • New Trusted Connection (NAT Mode)
  • Fixed
    • Improved Password Rotation
    • Improved Shared Folders stability

12.3.3

July 31, 2026

ADC

  • Fixed
    • File descriptor leak on multi-port SSL listeners

12.3.2

July 27, 2026

RAG

  • Fixed
    • Login requested twice

Worksapce

  • Enhancements
    • Restart=on-failure S96 service (now pkill -9 java does not work anymore, use oplonstop to stop services)

ADC

  • Added
    • WAF Adapter log through TCP

Core

  • Enanchement
    • Improve memory usage

Shared Folders

  • Fixed
    • Cookie set for the correct path, no longer for "/"

12.3.1

July 16, 2026

RAG

  • Added

    • Customizable SSH scrollback line terminal
    • SSH Search bar
    • Improve error handling on desktopgate
    • Updated SSH connectivity libraries for support of modern security algorithms. Backward compatibility, the following legacy algorithms remain enabled by default, and are now also user-configurable (globally or per-host):
      • KEX: diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1, diffie-hellman-group1-sha1
      • Host key / Pubkey: ssh-rsa, ssh-dss
      • Ciphers: aes128-cbc, aes192-cbc, aes256-cbc, 3des-cbc
    • New File Editor (standalone app)
      • Diff editor: view differences between a file and its modifications
      • Save / Save as functionality
      • Draggable file tabs with split view (up to two panes)
      • Open new files without requiring a machine connection
    • Access Reason: Optionally require users to specify a reason for connecting before granting access
    • Added quick button to disable copy&paste (allow users to use only remote clipboard)
  • Fixed

    • SSH text selection
    • Fix SSH sending unnecessary character in broadcast mode

Worksapce

  • Fixed
    • Improved stability (resolved some race condition and stackoverflow exception)
  • Added
    • Improved digital certificate selection when listener have SNI disabled

Core

  • Added
    • ETL module during TM/Analytics installation
    • Removed legacy DWH installation during TM/Analytics

Identity Link

  • Added
    • Added support for multiple allowed redirect URIs in accordance with the OpenID Connect/OAuth 2.0 specifications.

12.3.0

July 2, 2026

RAG

  • Added
    • [WORKSPACE] Test password rotation page
  • Fixed
    • Fix kerberos settings unnecessary krb5.conf
    • Changed logging logic for password rotation
    • Password rotation does not change password for disabled users
  • Changed
    • Sharpmode enhancement, definitive version

Worksapce

  • Fixed
    • Improved stability and resolved minor concurrency issues, reducing runtime bugs and enhancing overall reliability

ADC

  • Added
    • Digital certificates are automatically loaded and published by SSL listeners without needing a reinit (step required for CA Manager)

Identity Link

  • Added
    • SPID cache IDP Entity Configuration
    • Security headers for IDLINK pages

12.2.1

June 9, 2026

RAG

  • Fixed
    • BI Account creation

12.2.0

May 28, 2026

Core

  • Fixed
    • OPLON_INSTALL_CONTAINERS.sh now check for real container name

RAG

  • Added
    • Custom Temporary Connections
  • Fixed
    • ISO_8859_1 → UTF-8 conversion on pwd negotiation

Idetity Link

  • Fixed
    • Corrected SAML logout behavior against ADFS identity providers
    • Improved error handling for Proxy logout, ensuring the correct message is returned

12.1.6

May 19, 2026

RAG

  • Added
    • RDP and VNC Sharp mode
  • Enhanced
    • Improved input handling on hybrid devices. Previously, touch input took precedence over the mouse, causing UI confusion
  • Fixed
    • Broadcast Copy/Paste
    • Resolved an issue that prevented initiating a single user password change for Active Directory from the workspace interface.

Workspace

  • Added
    • [RAG] Search bar within the group form to make finding items easier
    • SSL endpoint button to connect to the keystore

12.1.5

May 7, 2026

RAG

  • Fix
    • Enhanced copy paste stability on RDP connection
    • Automatically focus the terminal on SSH connection
    • Config file during first installation
  • Added
    • ClearType is now a custom user config

Workspace

  • Added
    • [RAG] Bind/Unbind a group from N resources. In "Secure Access" > "Settings", edit the module and access the "Group Details" view to manage resource associations via the Add and Delete buttons.
    • [RAG] Directly open the Vault from the "Details" button of any user linked to a resource
    • Switch between Compact and Default display modes via a new toggle button

12.1.4

April 22, 2026

Shared Folders

  • Fix
    • Resolved cookie issue that caused random 401 status code

Workspace

  • Added
    • Press Enter to search in RAG view

12.1.3

April 20, 2026

Workspace

  • Fix
    • API call between nodes

12.1.2

April 15, 2026

Workspace

  • Fix
    • Showing available memory on Linux systems

Shared Folders

  • Fix
    • Validating secret stuck in some conditions
    • Minor bug fix

Trusted Connections

  • Fix
    • Minor bug fix

OSA

  • Fix
    • Defaulting username when missing in ssh connections

12.1.1

April 10, 2026

Core

  • Enhanced
    • increased module start timeout
  • Changed
    • kernel parameter vm.overcommit_ratio

12.1.0

April 2, 2026

Core

  • Enhanced
    • Auto install and auto update now work both with and without user input

Workspace

  • Added
    • ACME certificate generation now supports External Account Binding (EAB)
  • Enhanced
    • Improved frontend input update speed after every change

ADC

  • Changed
    • Fixed ALPN

RAG

  • Added

    • Kerberos authentication support for SSH, SFTP and RDP
      • (KNOW ISSUE!): RemoteAppRDP doesn't work with kerberos auth
    • Button to restore/reset IntelliHide
    • Progressive Web App (PWA) installer impelemented
  • Fixed

    • SSH reload button does not reload ssh connections
    • Make p2p and webdav objs shared between cluster
    • Fix Autoscale on non vnc connection

Identity Link

  • Fixed
    • Duplicate rewrite rules variable modifying input value in some cases. Now variables are in state read-only for IDLINK page
    • CIE & SPID: Fixed improper logout management in direct redirect cases (/login -> 302 vs IdP). These providers do not support logout, so the flow has been corrected accordingly.

12.0.1

March 30, 2026

Core

  • Enhanced
    • Auto install and auto update now work both with and without user input

Workspace

  • Added
    • ACME certificate generation now supports External Account Binding (EAB)
  • Enhanced
    • Improved frontend input update speed after every change

ADC

  • Changed
    • A single listener can now handle both port 80 and port 443

RAG

  • Added
    • Button to restore/reset IntelliHide
    • Progressive Web App (PWA) installer impelemented
  • Fixed
    • SSH reload button does not reload ssh connections

Identity Link

  • Fixed
    • Duplicate rewrite rules variable modifying input value in some cases. Now variables are in state read-only for IDLINK page
    • CIE & SPID: Fixed improper logout management in direct redirect cases (/login -> 302 vs IdP). These providers do not support logout, so the flow has been corrected accordingly.

12.0.0

March 13, 2026

Core

  • Added
    • New JDK 25
    • Automation of PostgreSQL setup in the OSA Analytics installation script

RAG

  • Added
    • Updated import logic to support Active Directory users and passwords
    • Bulk connection for Trusted Connection and Shared Folders
  • Enhanced
    • Optimized import velocity and memory management for faster data loading
  • Fixed
    • Filemanager copy&paste path bug
    • Accept button on "EULA Registration dialog" bug
    • Close button on windows causing window to flicker

Identity Link

  • Added
    • Token brokering
    • Added new Profile and Logout page

11.4.3

February 12, 2026

OSA

  • Added
    • Client Network Analytics: visible opening OSA Settings

Identity Link

  • Enhanced
    • SAML Single Logout (SLO)

Workspace

  • Added
    • New GUI for Identity Link

11.4.2

January 15, 2026

Identity Link

  • Fixed
    • userinfo and some minor issues on idtoken (openidprovider)

Core

  • Fixed
    • fixed license/ulicense.xml for webcache shc file upload

Trusted Connection

  • Added
    • upstreamAddress is now customizable (127.0.0.1, 127.0.0.2...)

OSA

  • Fixed
    • Small UI adjustment

Browser Isolation

  • Added
    • updated to 140 ESR and themes
    • now all new link is open i a new tab

11.4.1

December 5, 2025

OSA

  • Fixed×2
    • fix bug on parsing scheduler
    • fix creadentialAD not present

ADC

  • Fixed×1
    • Fixed autocomplete host/ad login

11.4.0

November 28, 2025

OSA

  • Added×2
    • Multiple impersonification added
    • AD Passowrd Vault + Rotation
  • Fixed×1
    • Some UI adjustment on Trusted Connection and Shared Folders

ADC

  • Fixed×3
    • Fixed ulicense
    • Small adjustment on browserbridge docker

Identity Link

  • Enhancement×1
    • JWT Rewrite Rule

11.3.1

November 7, 2025

OSA

  • Added×2
    • Functionality to set a time window for accessing resources (Access Schedule)
    • New grid view of resources
  • Performance (1 change)
    • Enhanced keyboard handling and improved copy/paste
  • Fixed×1
    • The settings menu were partially hidden if there were too many groups assigned to the user

ADC

  • Fixed×2
    • Rewrite Rules Template
    • In some cases, sending statistics to SIEM generates an error

11.3.0

October 22, 2025

Trusted Connection

  • Added×1
    • The Reliable Connection feature has been introduced. Create a connection to a service via a browser.

11.2.2

October 13, 2025

Identity Link

  • Fixed×1
    • Claims transformations regression

Core

Fixed×1 - TM installation

11.2.1

October 6, 2025

OSA

  • Added×1
    • Added compatibility with legacy Keyexchange algo for ssh connections

11.2.0

October 3, 2025

Identity Link

  • Added×3
    • OpenID Provider: changed logic for defining the value of the sub claim
    • Added tag parameter for identity provider identification
    • Added REWRITE_CLASS_N and REWRITE_CLASS_PATH_N parameters for JWT IDLink rewrite rule

Shared Folder

  • Added×1
    • Introduced Shared Folders feature to allow users to share directories across accounts or groups, now only for windows
    • Link to Shared Folders Documentation

11.1.0

September 9, 2025

RAG

  • Added×1
    • Implemented the new SSH, which includes a more responsive interface. The logs have been converted into videos and are available in the same way as RDP videos. In the Secure Access configuration, you can manage these videos in the same section as RDP videos.
  • Fixed×1
    • The automatic password change now correctly updates the password information for each host that contains the same Active Directory user.

11.0.14

September 1, 2025

Identity Link

  • Enhanced×1
    • New variable added: NORMALIZE_CLAIMS_VALUE (see documentation at https://archive.oplon.net/it/docs )

RAG

  • Added×1
    • Added automatic password change for Active Directory users

11.0.13

August 14, 2025

Identity Link

  • Enhanced×1
    • Added a skew for checking the SPID response issue instant

11.0.12

August 11, 2025

Identity Link

  • Fixed×1
    • SPID is using a wrong certificate on request

11.0.11

August 6, 2025

Identity Link

  • Enhanced×1
    • CIE file management
  • Fixed×2
    • Blank page displayed when clicking the browser's back button during login with an identity provider
    • Removed the character in the signature of a SAML request as it is not accepted by some identity providers

11.0.10

July 28, 2025

Identity Link

  • Fixed×1
    • Error logs and graphics according to SPID rules

11.0.9

July 22, 2025

Identity Link

  • Fixed×1
    • The Sub field of User Info is now set correctly

11.0.8

July 10, 2025

RAG

  • Added×2
    • Import host list from csv
    • Added new Active Directory parameter (Referral)
  • Fixed×1
    • Soket SIEM was not being closed in some specific cases

Core

  • Changed×2
    • instScratch always performed during installation and update
    • CHROOT will be asked during the first installation

ADC

  • Changed×1
    • automatic reload licence without restart
  • Fixed×2
    • Play recorded video fail in some cases
    • Geolocalization whitelist fail in some cases

Identity Link

  • Added×1
    • OpenID Connect Provider

11.0.7

June 12, 2025

ADC

  • Fixed×1
    • Blacklist propagation problem via api/SeerBox resolved
  • Changed×1
    • MFA User is now available in Syslog

IdentityLink

  • Fixed×1
    • Hidden chars (CRLF) removed from SPID metadata

11.0.6

May 28, 2025

OSA

  • Fixed×1
    • Logout now accepts all types of account

Worksapce

  • Performance (1 change)

    • Loading variables optimized
  • Fixed×1

    • WAF rules form
  • Added×1

    • New Rewrite class: CertBlock5

Core

  • Added×1
    • Thread name at workspace executors

11.0.5

May 20, 2025

RAG/WAG

  • Added×2
    • New Connection Acknowledge Message parameter to customize the message displayed when a session is registered
    • Option to make the Connection Acknowledge Message parameter mandatory

BrowserIsolation

  • Added×1
    • Multilanguage support (English, Italian, German)
  • Fixed×2
    • Fixed issue when hiding a single tab
    • Fixed general UI issues

Analytics

  • Added×2
    • New variable UNIFIED_CLAIMS_n (transforms JWT response keys)
    • Syslog for SIEM (OSA only)

CORE

  • Performance (1 change)
    • Virtual threads that were causing 100% CPU usage

11.0.4

May 13, 2025

Identity Link

  • Fixed×3

    • authentication for IDP's without sign attribute
    • duplicated DOM on Chrome during popstate
    • template
  • Performance (1 change)

    • Webauthn enhance db file (only Platform)

11.0.3

May 5, 2025

ADC

  • Added×1
    • enable/disable attribute in Modules -> General start parameter

Identity Link

  • Fixed×1
    • SPID template

11.0.2

April 16, 2025

Identity Link

  • Added×1
    • SPID

Workspace

  • Fixed×1
    • Interface freez in cluster resolved

11.0.1

February 18, 2025

Identity Link

  • Added×2
    • WebAuthn local storage
    • WebAuthn with Active Directory

WebCache

  • Fixed×1
    • Template with duplicate OA_INTERACTION, OA_PERFROMANCE, OA_ERROR tables

Certification Manager

  • Fixed×1
    • Use of digital certificate during creation

MFA

  • Fixed×1
    • Purge query parameter

Core

  • Changed×1
    • From Thread to Virtual Thread Emmbedded application server workers

ADC

  • Changed×2
    • Geolocation files have been updated
    • Template Browser Isolation, WebAuthn

11.0.0

February 18, 2025

Core

  • Added×1

    • New openjdk 21.0.1

    • New SNMP model to enable SNMP set the definitions: -DTCO_SNMPListenerAddress and -DTCO_SNMPListenerPort with valid values

      eg.: -DTCO_SNMPListenerAddress=0.0.0.0 -DTCO_SNMPListenerPort=161

    • License management is now dynamic. It is no longer necessary to turn off and on instances to update the license.

    Startup behavior: If the license has expired or violates limits such as CPU release memory etc, the module does not start.

    During operation: During operation for all modules except the ADC module, it is possible to update the license either by sizing (CPU memory limits etc.) or by updating the expiration. For the ADC instead, if the license expires or violates the limits the ADC module performs a shutdown. This behavior is necessary to avoid that some features are disabled such as: 2FA, Firewall, WAF etc., which could compromise the security of the system.

    It is therefore recommended to update the licenses in time before they expire.

ADC

  • Fixed×1
    • Proxy location evaluation. Preview: node defined endPointsGroupingParams and sslCertificatesManagement

10.12.3

January 21, 2025

RAG

  • Performance (1 change)

    • Improved Mobile Responsiveness (now follow 100dvh)
  • Changed×1

    • On Screen Keyboard button always visibile

Browser Isolation

  • Changed×1
    • Decreased min width on mobile devices (>150px)

10.12.2

December 20, 2024

RAG

  • Added×1

    • Custom params for host, app and collection
  • Fixed×2

    • Virtual Drive fix .part files bug on upload
    • fixed grid view now showing correct number of resources
  • Performance (1 change)

    • UX/UI improvements with pinch2zoom gesture

Workspace

  • Added×2

    • Default value for SAN
    • Subject key identifier and authority key identifier
  • Fixed×1

    • Certificate view

ADC

  • Performance (1 change)

    • Improved performance in h2 POST method
  • Changed×2

    • Set default iproxy for Platform to run Oplon Seucre Access
    • Setting host timezone to container

Adapter for Matomo

  • Performance (1 change)

    • Parallel request to the same matomo url (keymap changed from MatomoUrl to IDSITE)
  • Changed×3

    • Delete bulk if matomo returns 500
    • Delete CANCELLED folder
    • Sanitize document_title

10.12.1

November 21, 2024

RAG

  • Performance (1 change)

    • Small UX/UI Improvements
  • Fixed×1

    • Fix "paste button" on firefox
  • Changed×2

    • Full screen button now on left bar
    • Trim username
  • Added×1

    • Custom param

Workspace

  • Fixed×1
    • Regression in ACME certificate renew

Adapter for Matomo

  • Performance (1 change)
    • Generic enhancement

10.12.0

November 6, 2024

RAG

  • Performance (3 changes)

    • UX/UI improvements
    • UX/UI improvements for mobile devices
    • Increased support for mobile devices
  • Added×3

    • New Virtual Keyboard (OnScreenKeyboard/Textbox) only for VNC/RDP
    • New settings for mobile devices
    • New Gridview

Browser Isolation

  • Added×1

    • Added new tab
  • Removed×2

    • Automatic translation
    • Unnecessary warning

10.11.7

October 25, 2024

ADC

  • Performance (3 changes)

    • Waf Rules regular expression evaluation enhancement
    • Security improvements: TLS 1.2/1.3 enabled by default for :4444 and OSA
    • Security improvements: deprecated weak cipher for TLS (3DES, CBC)
  • Fixed×1

    • Error in black list Ip Regular expression evaluation

RAG

  • Added×1
    • New Settings for VNC Connection => autoscaling (enable/disable)

10.11.6

October 11, 2024

Workspace

  • Performance (1 change)

    • Import PEM enhancement
  • Fixed×1

    • TLSv1.2 TLSv1.3 set as default ssl protocols

RAG

  • Fixed×1
    • Problem during Password Bulk Import

10.11.5

October 3, 2024

Workspace

  • Added×1
    • Added support to EC SSL certificates.

ADC

  • Fixed×2
    • Listener Http1 protocol over http2 listener regression
    • Node defined rewrite rule. Fixed xml validation

Core

  • Changed×1
    • In the new virtual appliances there are new policy files for gray test assessment

RAG

  • Fixed×1

  • Credential list view

  • Added×1

    • import RAG password from EXCEL

10.11.4

September 23, 2024

Workspace

  • Changed×1
    • TLSv1.2 TLSv1.3 setted as default ssl protocols

ADC

  • Performance (1 change)
    • Http2 tunnel optimization

10.11.3

June 24, 2024

RAG

  • Changed×3
    • Show resource info for a single Windows
    • Upload shows feedback on complete
    • Remove session credentials for user

Workspace

  • Added×1
    • Legacy flag in export certificates function

ADC

  • Added×1

    • New parameter defaultHeaders
  • Performance (1 change)

    • Improved threads cpu usage in http2 balancing

Core

  • Added×1
    • New ALERT message type ALERT. This message type must be used to notify application problem messages. This message not increment the errors number like ERROR or FATAL

10.11.2

June 24, 2024

ADC

  • Changed×1

    • Preview node defined rewrite rule
  • Fixed×1

    • Waf Adapter. Fixed query string parameter analysis

Workspace

  • Added×1
    • Enable flag in inventory, for nodes and clusters

RAG

  • Fixed×1

    • Scroll-X RDP window
  • Added×1

    • New classes utility for SSO Webapps
    • Multiuser for webapps

Analytics

  • Performance (1 change)
    • Auto add domains to Matomo enhanced

WebCache

  • Fixed×1
    • Fata exporting aggregator

10.11.1

June 24, 2024

RAG

  • Added×1
    • RDP Drive Redirection

Browser Isolation

  • Fixed×1
    • Trimming whitelisted site

Analytics

  • Changed×1

    • Improve download information
  • Added×1

    • Auto add domains to Matomo

ADC

  • Fixed×1
    • Shared object counting visualization bug

10.11.0

June 14, 2024

RAG

  • Added×1
    • Browser Isolation (check documentation for more info)

Analytics

  • Performance (1 change)
    • Improve AnalyticsCollector Chrome/Chromium based browser compatibility

10.10.5

May 13, 2024

Workspace

  • Added×1
    • New api /japi/firewall/ip

ADC

  • Fixed×1

    • Rewrite classes: Fixed issue in endpoint tags evaluation.
  • Added×1

    • Template rewrite rule LBLHTTPBasicAuthentication: Added REALM parameter

10.10.4

March 26, 2024

Workspace

  • Added×1

    • New api /japi/status/endpoints
  • Fixed×1

    • Issues in rewrite rules visualization
  • Performance (1 change)

    • Endpoints view performance enhancement

ADC

  • Added×1
    • New prefetch incoming connections double queue

10.10.3

March 11, 2024

RAG

  • Performance (1 change)

    • Improve Azure Active Directory supports
  • Changed×1

    • OSA LOG now available without Oplon Analytics
  • Fixed×1

    • Small UI fixes

Radius server

  • Changed×1
    • Fortigate dictonary updated

10.10.2

March 27, 2024

RAG

  • Fixed×1
    • New file/folder not showing when chrooting Windows environment

10.10.1

March 18, 2024

ADC

  • Fixed×1
    • Fixed a regression in destination port evaluation during proxy redirection

10.10.0

March 13, 2024

WAF

  • Added×1
    • New Adapter

RAG

  • Added×4

  • Enable/Disable File Manager flag

  • It is possible to create a resource that only has the file manager among the accesses (accessible via the file manager menu)

  • New File Editor detached from the window (accessible from the left bar), the previous one is still accessible from the Window

  • Closing And/Or Saving Multiple file at the same time

  • Changed×5

  • File Manager have been moved on the left bar, now has its own menu

  • File Manager now can open multiple resources at the same time, thanks to Tabs view

  • Download/Upload/Hypercopy icons have been moved on the left bar (they can show the states globally)

  • File editor now can open multiple file at the same time, thanks to Tabs view

  • RDP Drive Redirection (collection only): For RDP connections, possibility to do File Managing without SFTP

  • Fixed×1

  • Bug fixing, UI/UX Improvements

  • Removed×1

  • Right menu

10.9.7

February 13, 2024

ADC

  • Fixed×2
    • Default redirection URL in proxyLocation evaluation. The new system parameter LBL_BLANK_PROXY_URL_DEFAULT is added to restore the default redirection URL evaluation before this fix. eg: -DLBL_BLANK_PROXY_URL_DEFAULT=true
    • "clear password" didn't trigger save and reinit

RAG

  • Fixed×1
    • UseImpersonification with AD

10.9.6

February 7, 2024

ADC

  • Small fixes and improve stability

10.9.5

January 24, 2024

RAG

  • Fixed×1
    • Missing parameters in Collection (enable/disable copy&paste)

10.9.4

January 19, 2024

RAG

  • Added×2

    • Self-service change password for Active Directory
    • Implemented Collection with load-balancing-info
  • Fixed×1

    • AD/Session Credential

10.9.3

January 19, 2024

RAG

  • Fixed×1
    • Missing front end parameter for TS connection broker (load-balancing-info)
    • Unnecessary AD warning

10.9.2

December 6, 2023

ADC

  • Fix×1
    • HTTP2 two issues have been fixed. The first issue occurred if the endpoint connection was disconnected during a stream. The second issue occurred while waiting for the "settings" http2 frame, and it doesn't arrive from the client. The useful waiting time is (3 seconds). In both cases, when the events occur the system responds with an HTTP2 goAway.

10.9.1

November 29, 2023

ADC

  • Added×1
    • Ldap service healthcheck added

MFA

  • Fixed×1
    • Timeout timing with ACM