Oplon Secure Access Full Changelogs
12.4.0
August 10, 2026
Workspaces
- Fixed
- Fixed some typos
- Fixed some fields that were number insted of text
- Fixed showing "last password change" in OSA Vault
RAG
- Added
- New Trusted Connection (NAT Mode)
- Fixed
- Improved Password Rotation
- Improved Shared Folders stability
12.3.3
July 31, 2026
ADC
- Fixed
- File descriptor leak on multi-port SSL listeners
12.3.2
July 27, 2026
RAG
- Fixed
- Login requested twice
Worksapce
- Enhancements
- Restart=on-failure S96 service (now pkill -9 java does not work anymore, use oplonstop to stop services)
ADC
- Added
- WAF Adapter log through TCP
Core
- Enanchement
- Improve memory usage
Shared Folders
- Fixed
- Cookie set for the correct path, no longer for "/"
12.3.1
July 16, 2026
RAG
-
Added
- Customizable SSH scrollback line terminal
- SSH Search bar
- Improve error handling on desktopgate
- Updated SSH connectivity libraries for support of modern security algorithms. Backward compatibility, the following legacy algorithms remain enabled by default, and are now also user-configurable (globally or per-host):
- KEX:
diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 - Host key / Pubkey:
ssh-rsa,ssh-dss - Ciphers:
aes128-cbc,aes192-cbc,aes256-cbc,3des-cbc
- KEX:
- New File Editor (standalone app)
- Diff editor: view differences between a file and its modifications
- Save / Save as functionality
- Draggable file tabs with split view (up to two panes)
- Open new files without requiring a machine connection
- Access Reason: Optionally require users to specify a reason for connecting before granting access
- Added quick button to disable copy&paste (allow users to use only remote clipboard)
-
Fixed
- SSH text selection
- Fix SSH sending unnecessary character in broadcast mode
Worksapce
- Fixed
- Improved stability (resolved some race condition and stackoverflow exception)
- Added
- Improved digital certificate selection when listener have SNI disabled
Core
- Added
- ETL module during TM/Analytics installation
- Removed legacy DWH installation during TM/Analytics
Identity Link
- Added
- Added support for multiple allowed redirect URIs in accordance with the OpenID Connect/OAuth 2.0 specifications.
12.3.0
July 2, 2026
RAG
- Added
- [WORKSPACE] Test password rotation page
- Fixed
- Fix kerberos settings unnecessary krb5.conf
- Changed logging logic for password rotation
- Password rotation does not change password for disabled users
- Changed
- Sharpmode enhancement, definitive version
Worksapce
- Fixed
- Improved stability and resolved minor concurrency issues, reducing runtime bugs and enhancing overall reliability
ADC
- Added
- Digital certificates are automatically loaded and published by SSL listeners without needing a reinit (step required for CA Manager)
Identity Link
- Added
- SPID cache IDP Entity Configuration
- Security headers for IDLINK pages
12.2.1
June 9, 2026
RAG
- Fixed
- BI Account creation
12.2.0
May 28, 2026
Core
- Fixed
- OPLON_INSTALL_CONTAINERS.sh now check for real container name
RAG
- Added
- Custom Temporary Connections
- Fixed
- ISO_8859_1 → UTF-8 conversion on pwd negotiation
Idetity Link
- Fixed
- Corrected SAML logout behavior against ADFS identity providers
- Improved error handling for Proxy logout, ensuring the correct message is returned
12.1.6
May 19, 2026
RAG
- Added
- RDP and VNC Sharp mode
- Enhanced
- Improved input handling on hybrid devices. Previously, touch input took precedence over the mouse, causing UI confusion
- Fixed
- Broadcast Copy/Paste
- Resolved an issue that prevented initiating a single user password change for Active Directory from the workspace interface.
Workspace
- Added
- [RAG] Search bar within the group form to make finding items easier
- SSL endpoint button to connect to the keystore
12.1.5
May 7, 2026
RAG
- Fix
- Enhanced copy paste stability on RDP connection
- Automatically focus the terminal on SSH connection
- Config file during first installation
- Added
- ClearType is now a custom user config
Workspace
- Added
- [RAG] Bind/Unbind a group from N resources. In "Secure Access" > "Settings", edit the module and access the "Group Details" view to manage resource associations via the Add and Delete buttons.
- [RAG] Directly open the Vault from the "Details" button of any user linked to a resource
- Switch between Compact and Default display modes via a new toggle button
12.1.4
April 22, 2026
Shared Folders
- Fix
- Resolved cookie issue that caused random 401 status code
Workspace
- Added
- Press Enter to search in RAG view
12.1.3
April 20, 2026
Workspace
- Fix
- API call between nodes
12.1.2
April 15, 2026
Workspace
- Fix
- Showing available memory on Linux systems
Shared Folders
- Fix
- Validating secret stuck in some conditions
- Minor bug fix
Trusted Connections
- Fix
- Minor bug fix
OSA
- Fix
- Defaulting username when missing in ssh connections
12.1.1
April 10, 2026
Core
- Enhanced
- increased module start timeout
- Changed
- kernel parameter vm.overcommit_ratio
12.1.0
April 2, 2026
Core
- Enhanced
- Auto install and auto update now work both with and without user input
Workspace
- Added
- ACME certificate generation now supports External Account Binding (EAB)
- Enhanced
- Improved frontend input update speed after every change
ADC
- Changed
- Fixed ALPN
RAG
-
Added
- Kerberos authentication support for SSH, SFTP and RDP
- (KNOW ISSUE!): RemoteAppRDP doesn't work with kerberos auth
- Button to restore/reset IntelliHide
- Progressive Web App (PWA) installer impelemented
- Kerberos authentication support for SSH, SFTP and RDP
-
Fixed
- SSH reload button does not reload ssh connections
- Make p2p and webdav objs shared between cluster
- Fix Autoscale on non vnc connection
Identity Link
- Fixed
- Duplicate rewrite rules variable modifying input value in some cases. Now variables are in state read-only for IDLINK page
- CIE & SPID: Fixed improper logout management in direct redirect cases (
/login-> 302 vs IdP). These providers do not support logout, so the flow has been corrected accordingly.
12.0.1
March 30, 2026
Core
- Enhanced
- Auto install and auto update now work both with and without user input
Workspace
- Added
- ACME certificate generation now supports External Account Binding (EAB)
- Enhanced
- Improved frontend input update speed after every change
ADC
- Changed
- A single listener can now handle both port 80 and port 443
RAG
- Added
- Button to restore/reset IntelliHide
- Progressive Web App (PWA) installer impelemented
- Fixed
- SSH reload button does not reload ssh connections
Identity Link
- Fixed
- Duplicate rewrite rules variable modifying input value in some cases. Now variables are in state read-only for IDLINK page
- CIE & SPID: Fixed improper logout management in direct redirect cases (
/login-> 302 vs IdP). These providers do not support logout, so the flow has been corrected accordingly.
12.0.0
March 13, 2026
Core
- Added
- New JDK 25
- Automation of PostgreSQL setup in the OSA Analytics installation script
RAG
- Added
- Updated import logic to support Active Directory users and passwords
- Bulk connection for Trusted Connection and Shared Folders
- Enhanced
- Optimized import velocity and memory management for faster data loading
- Fixed
- Filemanager copy&paste path bug
- Accept button on "EULA Registration dialog" bug
- Close button on windows causing window to flicker
Identity Link
- Added
- Token brokering
- Added new Profile and Logout page
11.4.3
February 12, 2026
OSA
- Added
- Client Network Analytics: visible opening OSA Settings
Identity Link
- Enhanced
- SAML Single Logout (SLO)
Workspace
- Added
- New GUI for Identity Link
11.4.2
January 15, 2026
Identity Link
- Fixed
- userinfo and some minor issues on idtoken (openidprovider)
Core
- Fixed
- fixed license/ulicense.xml for webcache shc file upload
Trusted Connection
- Added
- upstreamAddress is now customizable (127.0.0.1, 127.0.0.2...)
OSA
- Fixed
- Small UI adjustment
Browser Isolation
- Added
- updated to 140 ESR and themes
- now all new link is open i a new tab
11.4.1
December 5, 2025
OSA
- Fixed×2
- fix bug on parsing scheduler
- fix creadentialAD not present
ADC
- Fixed×1
- Fixed autocomplete host/ad login
11.4.0
November 28, 2025
OSA
- Added×2
- Multiple impersonification added
- AD Passowrd Vault + Rotation
- Fixed×1
- Some UI adjustment on Trusted Connection and Shared Folders
ADC
- Fixed×3
- Fixed ulicense
- Small adjustment on browserbridge docker
Identity Link
- Enhancement×1
- JWT Rewrite Rule
11.3.1
November 7, 2025
OSA
- Added×2
- Functionality to set a time window for accessing resources (Access Schedule)
- New grid view of resources
- Performance (1 change)
- Enhanced keyboard handling and improved copy/paste
- Fixed×1
- The settings menu were partially hidden if there were too many groups assigned to the user
ADC
- Fixed×2
- Rewrite Rules Template
- In some cases, sending statistics to SIEM generates an error
11.3.0
October 22, 2025
Trusted Connection
- Added×1
- The Reliable Connection feature has been introduced. Create a connection to a service via a browser.
11.2.2
October 13, 2025
Identity Link
- Fixed×1
- Claims transformations regression
Core
Fixed×1 - TM installation
11.2.1
October 6, 2025
OSA
- Added×1
- Added compatibility with legacy Keyexchange algo for ssh connections
11.2.0
October 3, 2025
Identity Link
- Added×3
- OpenID Provider: changed logic for defining the value of the
subclaim - Added
tagparameter for identity provider identification - Added
REWRITE_CLASS_NandREWRITE_CLASS_PATH_Nparameters for JWT IDLink rewrite rule
- OpenID Provider: changed logic for defining the value of the
Shared Folder
- Added×1
- Introduced Shared Folders feature to allow users to share directories across accounts or groups, now only for windows
- Link to Shared Folders Documentation
11.1.0
September 9, 2025
RAG
- Added×1
- Implemented the new SSH, which includes a more responsive interface. The logs have been converted into videos and are available in the same way as RDP videos. In the Secure Access configuration, you can manage these videos in the same section as RDP videos.
- Fixed×1
- The automatic password change now correctly updates the password information for each host that contains the same Active Directory user.
11.0.14
September 1, 2025
Identity Link
- Enhanced×1
- New variable added: NORMALIZE_CLAIMS_VALUE (see documentation at https://archive.oplon.net/it/docs )
RAG
- Added×1
- Added automatic password change for Active Directory users
11.0.13
August 14, 2025
Identity Link
- Enhanced×1
- Added a skew for checking the SPID response issue instant
11.0.12
August 11, 2025
Identity Link
- Fixed×1
- SPID is using a wrong certificate on request
11.0.11
August 6, 2025
Identity Link
- Enhanced×1
- CIE file management
- Fixed×2
- Blank page displayed when clicking the browser's back button during login with an identity provider
- Removed the character in the signature of a SAML request as it is not accepted by some identity providers
11.0.10
July 28, 2025
Identity Link
- Fixed×1
- Error logs and graphics according to SPID rules
11.0.9
July 22, 2025
Identity Link
- Fixed×1
- The Sub field of User Info is now set correctly
11.0.8
July 10, 2025
RAG
- Added×2
- Import host list from csv
- Added new Active Directory parameter (Referral)
- Fixed×1
- Soket SIEM was not being closed in some specific cases
Core
- Changed×2
- instScratch always performed during installation and update
- CHROOT will be asked during the first installation
ADC
- Changed×1
- automatic reload licence without restart
- Fixed×2
- Play recorded video fail in some cases
- Geolocalization whitelist fail in some cases
Identity Link
- Added×1
- OpenID Connect Provider
11.0.7
June 12, 2025
ADC
- Fixed×1
- Blacklist propagation problem via api/SeerBox resolved
- Changed×1
- MFA User is now available in Syslog
IdentityLink
- Fixed×1
- Hidden chars (CRLF) removed from SPID metadata
11.0.6
May 28, 2025
OSA
- Fixed×1
- Logout now accepts all types of account
Worksapce
-
Performance (1 change)
- Loading variables optimized
-
Fixed×1
- WAF rules form
-
Added×1
- New Rewrite class: CertBlock5
Core
- Added×1
- Thread name at workspace executors
11.0.5
May 20, 2025
RAG/WAG
- Added×2
- New Connection Acknowledge Message parameter to customize the message displayed when a session is registered
- Option to make the Connection Acknowledge Message parameter mandatory
BrowserIsolation
- Added×1
- Multilanguage support (English, Italian, German)
- Fixed×2
- Fixed issue when hiding a single tab
- Fixed general UI issues
Analytics
- Added×2
- New variable UNIFIED_CLAIMS_n (transforms JWT response keys)
- Syslog for SIEM (OSA only)
CORE
- Performance (1 change)
- Virtual threads that were causing 100% CPU usage
11.0.4
May 13, 2025
Identity Link
-
Fixed×3
- authentication for IDP's without sign attribute
- duplicated DOM on Chrome during popstate
- template
-
Performance (1 change)
- Webauthn enhance db file (only Platform)
11.0.3
May 5, 2025
ADC
- Added×1
- enable/disable attribute in Modules -> General start parameter
Identity Link
- Fixed×1
- SPID template
11.0.2
April 16, 2025
Identity Link
- Added×1
- SPID
Workspace
- Fixed×1
- Interface freez in cluster resolved
11.0.1
February 18, 2025
Identity Link
- Added×2
- WebAuthn local storage
- WebAuthn with Active Directory
WebCache
- Fixed×1
- Template with duplicate OA_INTERACTION, OA_PERFROMANCE, OA_ERROR tables
Certification Manager
- Fixed×1
- Use of digital certificate during creation
MFA
- Fixed×1
- Purge query parameter
Core
- Changed×1
- From Thread to Virtual Thread Emmbedded application server workers
ADC
- Changed×2
- Geolocation files have been updated
- Template Browser Isolation, WebAuthn
11.0.0
February 18, 2025
Core
-
Added×1
-
New openjdk 21.0.1
-
New SNMP model to enable SNMP set the definitions: -DTCO_SNMPListenerAddress and -DTCO_SNMPListenerPort with valid values
eg.: -DTCO_SNMPListenerAddress=0.0.0.0 -DTCO_SNMPListenerPort=161
-
License management is now dynamic. It is no longer necessary to turn off and on instances to update the license.
Startup behavior: If the license has expired or violates limits such as CPU release memory etc, the module does not start.
During operation: During operation for all modules except the ADC module, it is possible to update the license either by sizing (CPU memory limits etc.) or by updating the expiration. For the ADC instead, if the license expires or violates the limits the ADC module performs a shutdown. This behavior is necessary to avoid that some features are disabled such as: 2FA, Firewall, WAF etc., which could compromise the security of the system.
It is therefore recommended to update the licenses in time before they expire.
-
ADC
- Fixed×1
- Proxy location evaluation. Preview: node defined endPointsGroupingParams and sslCertificatesManagement
10.12.3
January 21, 2025
RAG
-
Performance (1 change)
- Improved Mobile Responsiveness (now follow 100dvh)
-
Changed×1
- On Screen Keyboard button always visibile
Browser Isolation
- Changed×1
- Decreased min width on mobile devices (>150px)
10.12.2
December 20, 2024
RAG
-
Added×1
- Custom params for host, app and collection
-
Fixed×2
- Virtual Drive fix .part files bug on upload
- fixed grid view now showing correct number of resources
-
Performance (1 change)
- UX/UI improvements with pinch2zoom gesture
Workspace
-
Added×2
- Default value for SAN
- Subject key identifier and authority key identifier
-
Fixed×1
- Certificate view
ADC
-
Performance (1 change)
- Improved performance in h2 POST method
-
Changed×2
- Set default iproxy for Platform to run Oplon Seucre Access
- Setting host timezone to container
Adapter for Matomo
-
Performance (1 change)
- Parallel request to the same matomo url (keymap changed from MatomoUrl to IDSITE)
-
Changed×3
- Delete bulk if matomo returns 500
- Delete CANCELLED folder
- Sanitize document_title
10.12.1
November 21, 2024
RAG
-
Performance (1 change)
- Small UX/UI Improvements
-
Fixed×1
- Fix "paste button" on firefox
-
Changed×2
- Full screen button now on left bar
- Trim username
-
Added×1
- Custom param
Workspace
- Fixed×1
- Regression in ACME certificate renew
Adapter for Matomo
- Performance (1 change)
- Generic enhancement
10.12.0
November 6, 2024
RAG
-
Performance (3 changes)
- UX/UI improvements
- UX/UI improvements for mobile devices
- Increased support for mobile devices
-
Added×3
- New Virtual Keyboard (OnScreenKeyboard/Textbox) only for VNC/RDP
- New settings for mobile devices
- New Gridview
Browser Isolation
-
Added×1
- Added new tab
-
Removed×2
- Automatic translation
- Unnecessary warning
10.11.7
October 25, 2024
ADC
-
Performance (3 changes)
- Waf Rules regular expression evaluation enhancement
- Security improvements: TLS 1.2/1.3 enabled by default for :4444 and OSA
- Security improvements: deprecated weak cipher for TLS (3DES, CBC)
-
Fixed×1
- Error in black list Ip Regular expression evaluation
RAG
- Added×1
- New Settings for VNC Connection => autoscaling (enable/disable)
10.11.6
October 11, 2024
Workspace
-
Performance (1 change)
- Import PEM enhancement
-
Fixed×1
- TLSv1.2 TLSv1.3 set as default ssl protocols
RAG
- Fixed×1
- Problem during Password Bulk Import
10.11.5
October 3, 2024
Workspace
- Added×1
- Added support to EC SSL certificates.
ADC
- Fixed×2
- Listener Http1 protocol over http2 listener regression
- Node defined rewrite rule. Fixed xml validation
Core
- Changed×1
- In the new virtual appliances there are new policy files for gray test assessment
RAG
-
Fixed×1
-
Credential list view
-
Added×1
- import RAG password from EXCEL
10.11.4
September 23, 2024
Workspace
- Changed×1
- TLSv1.2 TLSv1.3 setted as default ssl protocols
ADC
- Performance (1 change)
- Http2 tunnel optimization
10.11.3
June 24, 2024
RAG
- Changed×3
- Show resource info for a single Windows
- Upload shows feedback on complete
- Remove session credentials for user
Workspace
- Added×1
- Legacy flag in export certificates function
ADC
-
Added×1
- New parameter defaultHeaders
-
Performance (1 change)
- Improved threads cpu usage in http2 balancing
Core
- Added×1
- New ALERT message type ALERT. This message type must be used to notify application problem messages. This message not increment the errors number like ERROR or FATAL
10.11.2
June 24, 2024
ADC
-
Changed×1
- Preview node defined rewrite rule
-
Fixed×1
- Waf Adapter. Fixed query string parameter analysis
Workspace
- Added×1
- Enable flag in inventory, for nodes and clusters
RAG
-
Fixed×1
- Scroll-X RDP window
-
Added×1
- New classes utility for SSO Webapps
- Multiuser for webapps
Analytics
- Performance (1 change)
- Auto add domains to Matomo enhanced
WebCache
- Fixed×1
- Fata exporting aggregator
10.11.1
June 24, 2024
RAG
- Added×1
- RDP Drive Redirection
Browser Isolation
- Fixed×1
- Trimming whitelisted site
Analytics
-
Changed×1
- Improve download information
-
Added×1
- Auto add domains to Matomo
ADC
- Fixed×1
- Shared object counting visualization bug
10.11.0
June 14, 2024
RAG
- Added×1
- Browser Isolation (check documentation for more info)
Analytics
- Performance (1 change)
- Improve AnalyticsCollector Chrome/Chromium based browser compatibility
10.10.5
May 13, 2024
Workspace
- Added×1
- New api /japi/firewall/ip
ADC
-
Fixed×1
- Rewrite classes: Fixed issue in endpoint tags evaluation.
-
Added×1
- Template rewrite rule LBLHTTPBasicAuthentication: Added REALM parameter
10.10.4
March 26, 2024
Workspace
-
Added×1
- New api /japi/status/endpoints
-
Fixed×1
- Issues in rewrite rules visualization
-
Performance (1 change)
- Endpoints view performance enhancement
ADC
- Added×1
- New prefetch incoming connections double queue
10.10.3
March 11, 2024
RAG
-
Performance (1 change)
- Improve Azure Active Directory supports
-
Changed×1
- OSA LOG now available without Oplon Analytics
-
Fixed×1
- Small UI fixes
Radius server
- Changed×1
- Fortigate dictonary updated
10.10.2
March 27, 2024
RAG
- Fixed×1
- New file/folder not showing when chrooting Windows environment
10.10.1
March 18, 2024
ADC
- Fixed×1
- Fixed a regression in destination port evaluation during proxy redirection
10.10.0
March 13, 2024
WAF
- Added×1
- New Adapter
RAG
-
Added×4
-
Enable/Disable File Manager flag
-
It is possible to create a resource that only has the file manager among the accesses (accessible via the file manager menu)
-
New File Editor detached from the window (accessible from the left bar), the previous one is still accessible from the Window
-
Closing And/Or Saving Multiple file at the same time
-
Changed×5
-
File Manager have been moved on the left bar, now has its own menu
-
File Manager now can open multiple resources at the same time, thanks to Tabs view
-
Download/Upload/Hypercopy icons have been moved on the left bar (they can show the states globally)
-
File editor now can open multiple file at the same time, thanks to Tabs view
-
RDP Drive Redirection (collection only): For RDP connections, possibility to do File Managing without SFTP
-
Fixed×1
-
Bug fixing, UI/UX Improvements
-
Removed×1
-
Right menu
10.9.7
February 13, 2024
ADC
- Fixed×2
- Default redirection URL in proxyLocation evaluation. The new system parameter LBL_BLANK_PROXY_URL_DEFAULT is added to restore the default redirection URL evaluation before this fix. eg: -DLBL_BLANK_PROXY_URL_DEFAULT=true
- "clear password" didn't trigger save and reinit
RAG
- Fixed×1
- UseImpersonification with AD
10.9.6
February 7, 2024
ADC
- Small fixes and improve stability
10.9.5
January 24, 2024
RAG
- Fixed×1
- Missing parameters in Collection (enable/disable copy&paste)
10.9.4
January 19, 2024
RAG
-
Added×2
- Self-service change password for Active Directory
- Implemented Collection with load-balancing-info
-
Fixed×1
- AD/Session Credential
10.9.3
January 19, 2024
RAG
- Fixed×1
- Missing front end parameter for TS connection broker (load-balancing-info)
- Unnecessary AD warning
10.9.2
December 6, 2023
ADC
- Fix×1
- HTTP2 two issues have been fixed. The first issue occurred if the endpoint connection was disconnected during a stream. The second issue occurred while waiting for the "settings" http2 frame, and it doesn't arrive from the client. The useful waiting time is (3 seconds). In both cases, when the events occur the system responds with an HTTP2 goAway.
10.9.1
November 29, 2023
ADC
- Added×1
- Ldap service healthcheck added
MFA
- Fixed×1
- Timeout timing with ACM