PortWise 4.6 Release Notes
PortWise 4.6 Release Notes
6
RELEASE NOTES
Contacting PortWise
For information about support, training and other services in your area please visit our website
http://www.portwise.com.
NEW FEATURES
The following features are highlighted in PortWise 4.6
IDENTITY FEDERATION
PortWise has extended its support for Identity Federation to include support for both SAML v2 and Microsoft
ADFS (Active Directory Federation Services). With Identity Federation, an organisation’s users may access re-
sources at external organizational domains after logging in to the user’s home domain. Logon credentials are
passed to external resources in SAML assertions to enable inter-domain Application Single Sign-On.
PORTWISE.COM | INFO@PORTWISE.COM
01
PORTWISE 4.6
RELEASE NOTES
PASSWORD MANAGEMENT INTEGRATION FOR IBM TIVOLI LDAP AND IBM RACF
PortWise 4.6 includes new authentication mechanisms that fully integrates with IBM Tivoli and RACF user
directories. PortWise can now completely reuse user and group information and interact with the catalogue’s
policies for password management to enable user password set/reset through PortWise.
PORTWISE.COM | INFO@PORTWISE.COM
02
PORTWISE 4.6
RELEASE NOTES
ENHANCED FEATURES
PortWise 4.6 contains over 100 enhancements through-out the product suite.
INSTALLATION
Installing PortWise is straigth forward and easy. Just run the appropriate installer for your operating system
and the setup wizard will guide you through the tasks. Please study the release notes and the PortWise 4.6
documentation prior to installing. You will also need a valid license file. If you are upgrading your existing
PortWise 4.x installation please study the upgrading documentation prior to an upgrade.
License
Portwise 4.6 requires a valid license. If you are upgrading from an existing installation you will be able to start
the system on an earlier PortWise 4.x license but will not have access to all features. Please contact your resel-
ler or PortWise to obtain a PortWise 4.6 license.
Upgrading
You can install PortWise 4.6 on any previous PortWise 4.0 or PortWise 4.5 release. For upgrades from earlier
releases please contact PortWise support. Please note that upgrades from PortWise 4.6 betas are not suppor-
ted. NOTE: You must upgrade all components to the same version.
PORTWISE.COM | INFO@PORTWISE.COM
03
PORTWISE 4.6
RELEASE NOTES
REQUIREMENTS
Hardware Requirements
A full installation of PortWise 4.6 includes five different services;
• PortWise Administration Service, the central management console for all other components.
• PortWise Access Point, the gateway beween users and applications.
• PortWise Policy Service, the authoriztion engine which determines what users may access.
• PortWise Authentication Service, the OTP server which authenticates users.
• PortWise Distribution Service (add-on to PortWise Authentication Service), used to distribute
Port Wise Mobile ID clients
NOTE: It is only the PortWise Administration Service that is mandatory to install, you then select the
services you need. Also note that the service can be deployed on one or multiple servers.
NOTE: Log files can generate large amounts of data, thus consuming vast amounts of hard
disk space. It is advisable to provide as much hard disk space as possible.
Performance
It is possible to deploy each of the PortWise services on separate servers, or to combine some or all of the
services on a single server. However, to increase performance you need to increase the amount of RAM in ac-
cordance with the number of PortWise services that are running on a single machine.
Note that for security reasons, it is strongly recommended that the PortWise Access Point is installed on a se-
parate machine on a DMZ. Only install the PortWise Access Point on the same machine as the other PortWise
services for demonstration or test purposes.
PortWise allows available memory to be most efficiently used by Java-based services (i.e. all services ex-
cept PortWise Access Point) through tuning of Java heap sizes. For details, please refer to the technical note
TN2070 Performance & Optimization.
PORTWISE.COM | INFO@PORTWISE.COM
04
PORTWISE 4.6
RELEASE NOTES
Server for PortWise Administration Service, PortWise Policy Service, and PortWise Authentication Service:
• Single Intel Pentium III, Pentium 4, or Xeon 1 GHz processor or higher
• 1 GB of RAM
• Hard disk drive with at least 40 GB of free space
Platform Requirements
Requirements for operating systems and directory services are listed below
Contact PortWise for support on additional platforms such as Solaris and Debian. PortWise 4.6 is also availible
as a VMware Virtual Appliance
Directory Servers
PortWise 4.6 is fully LDAP v3 compliant but has been tested and verified with;
PORTWISE.COM | INFO@PORTWISE.COM
05
PORTWISE 4.6
RELEASE NOTES
• LDAP
• RADIUS
• RSA SecurID
• Secure Computing SafeWord RemoteAccess
• X.509 certificates / PKI
• SAML (Web Browser SSO profile with HTTP Redirect and HTTP POST bindings)
• ADFS (WS-Federation Passive Requestor Interoperability Profile)
Please refer to the PortWise Administrator for the full range of authentication products.
Browser Requirements
PortWise Administrator
Browser requirements for the PortWise Administrator are listed per operating system in the table below.
NOTE: The requirements apply to the Web interface that constitutes the
PortWise Administrator, not the PortWise Administration Service.
PORTWISE.COM | INFO@PORTWISE.COM
06
PORTWISE 4.6
RELEASE NOTES
PORTWISE.COM | INFO@PORTWISE.COM
07
PORTWISE 4.6
RELEASE NOTES
PortWise Web
Browser requirements for PortWise Web authentication method are listed per operating system in the table
below.
PORTWISE.COM | INFO@PORTWISE.COM
08
PORTWISE 4.6
RELEASE NOTES
Client Requirements
Runtime requirements and supported platforms for PortWise clients are listed below.
PortWise Web
Runtime requirements for PortWise Web authentication method are listed per operating system in the table
below.
• Red Hat Linux Enterprise 5.0 Sun Java Runtime Environment 1.1.8 or later
• SUSE Linux Enterprise Server 10 Sun Java Runtime Environment 1.1.8 or later
PORTWISE.COM | INFO@PORTWISE.COM
09
PORTWISE 4.6
RELEASE NOTES
PortWise Mobile ID
Runtime requirements for PortWise Mobile ID are listed per operating system in the table below.
Red Hat Linux Enterprise 5.0 Sun Java Runtime Environment 1.5.0_12 or later
SUSE Linux Enterprise Server 10 Sun Java Runtime Environment 1.5.0_12 or later
PORTWISE.COM | INFO@PORTWISE.COM
010
PORTWISE 4.6
RELEASE NOTES
NOTE: PortWise Access Point 4.6 IS NOT backward compatible with pre PortWise 4.6 Access Clients.
Users running pre PortWise 4.6 Access Clients will be asked to automatically upgrade their client.
PortWise is working on a solution for backward compatibility.
Dynamic Tunnels
Statics Tunnels
• Red Hat Linux Enterprise 5.0 Sun Java Runtime Environment 1.1.8 or later
• SUSE Linux Enterprise Server 10 Sun Java Runtime Environment 1.1.8 or later
PORTWISE.COM | INFO@PORTWISE.COM
011
PORTWISE 4.6
RELEASE NOTES
RESOLVED ISSUES
The following issues found in previous release have been resolved in PortWise 4.6.
#17776 The tabs are not displayed on edit tunnel resource network pages
#17780 Manage Users - admin should warn if user has more than one unique user atrribute
#17836 DNS forwarding with or without authentication
#17882 Can’t add two access rule items of different types to an reusable access rule
#17897 User session search is case sensitive
#17914 Citrix standard resource uses wrong cookies
#17957 Incorrect default value for group-search-rules (Active Directory)
#17965 Manage User Import - Imported users missing search rule in link
#17983 The search limit displaying users and groups should be configurable
PORTWISE.COM | INFO@PORTWISE.COM
012
PORTWISE 4.6
RELEASE NOTES
#18063 Manage Assessment - Admin displays ‘match’ when it should be ‘wildcard match’
#18077 Active Directory authentication method does not support userPrincipalName
#18078 Encoding towards RADIUS server is fixed
#18108 Standard Resources Filters do not accept variable input fields
#18109 Adding port 2598 to Citrix Standard Resource
#18110 When searching for a user session the search is case sensitive
#18115 Too long server certificate strings breaks line in admin
#18256 Not possible to delete DNS name from Access Point
#18260 F-secure can not be alone as antivirus
#18482 Impossible to add more than one pair of Mirrored Access Points
#18491 Sorting Resources is not supported
#18526 It doesnt work to list user sessions using ‘All’ mechanisms
#18537 Back-button re-creates session and grants access in Admin
#18553 Invalid time range in charts used in reporting
#18558 Can not remove user if Directory Link is broken
#18568 MenuItems without resource gives internal error in save web resource root
#18569 Citrix Standard Resource does not work
#18628 Delegated Super Administrator can not see Manage User Storages
#18647 Can not see notification by SMS in list although configured SMS channel
#18071 Setting expiry time for passwords/PIN to 0 does not turn of expiry
#18073 PortWise Web Authentication Client renders double buttons
#18382 Policy Server stops responding possibly after Storage write problem
#18787 Incorrect branding for mID
PORTWISE.COM | INFO@PORTWISE.COM
013
PORTWISE 4.6
RELEASE NOTES
PORTWISE.COM | INFO@PORTWISE.COM
014
PORTWISE 4.6
RELEASE NOTES
KNOWN ISSUES
Known issues in PortWise 4.6 are listed below. Brief descriptions and possible workaround are provided for
each known issue
RSA_DES_CBC_SHA
RSA_EXP_DES40_CBC_SHA
RSA_EXP_DES_CBC_SHA
RSA_EXP_RC2_CBC_40_MD5
RSA_EXP_RC2_CBC_56_MD5
RSA_EXP_RC4_40_MD5
RSA_EXP_RC4_56_MD5
RSA_EXP_RC4_56_SHA
RSA_RC4_128_MD5
RSA_RC4_128_SHA
4. Single Sign-on for Terminal Server does not support RDP over SSL
The RDP client must not be configured to use SSL encryption in order for Single Sign-on to work.
When utilizing the PortWise Access Client to provide RDP access, the SSL encryption is taken care of
by the Access Client.
5. It is not allowed to run tunnelled server/client applications on the same machine as the Access
Point
The Access Point can not provide a tunnel interface to applications that reside locally on the Access Point
machine.
PORTWISE.COM | INFO@PORTWISE.COM
015
PORTWISE 4.6
RELEASE NOTES
PORTWISE.COM | INFO@PORTWISE.COM
016
PORTWISE 4.6
RELEASE NOTES
PORTWISE SUPPORT
Registering your product entitles you to technical support. Terms may vary depending on the country of
residence. For more information, refer to the technical support at http://www.portwise.com/support, or
contact your local sales representative
PORTWISE.COM | INFO@PORTWISE.COM
017