Viewer

  SelfReg Changelog

File: Changelog_selfreg.txt
Size: 11 KBytes
MD5: 66624AAC94384F9ECF2BC4CF81719A62

1.1.11
    - This update is required for WebADM version >= 1.7.6.
    - Prevent key import not matching the configured key size for SpanKey.
    - Added support for SpanKey DSA with 2048 and 4096 bit keys.
    - Fixed several wrong file permissions.

1.1.10
    - Added support for Client policy -based access restrictions.
    - Added support for SpanKey count-limited keys.
    - Added SSH Public Key import with copy/paste for SpanKey registration.
    - Users cannot self-configure SSH key expiration or max use.
    - Fixed 'Close' buttons sometimes not closing/blanking correctly.
    
1.1.9
    - Added support for WebADM v1.7 (it does not work with previous versions).
    - Hide the OTP PIN prefix input.
    - Added German translations.

1.1.8
    - Added support for FIDO2 with TPM chips (ex. Apple MacBooks).
      > This option requires OpenOTP v1.4.2.
    - U2F / FIDO2 registration choice is now automatic (based on client policies).
    - Fixed Token registration when Soft Token expiration time is set to '0'.
    - OTP prefix change is now avaialbe when OTP prefix is enabled in client policies.
    - User is guided to the Token enrollment when only one Token can be registered.
    - Menu is greyed for all items which cannot be self-registered.
    - Auto logout when a focussed registration item has been chosen.
    
1.1.7
    - Added support for FIDO2 (CTAP and WebAuthn enrollemnts).
      > You need OpenOTP v1.5 with this version of the Self-Service.
    - Fixed Trusted U2F Devices feature not working on Chrome version >= 66.
    - Setting Allowed Self-Registration 'U2F' is replaced by 'FIDO'.
      > You may need to adjust and re-apply your configuration in WebADM!
    - Added the 'FIDO Device Management' setting section.

1.1.6
    - Fixed SelReg requests for group not founding the right matching domain list.
    - Fixed OpenOTP login login test starting 2 auth requests with Internet Explorer.
    - The SelfReg request Manager method returns the registration URL instead of
      a TRUE boolean on success.
    - Added support for client side enrollemnt with OpenOTP v1.3.11-1.
    - Removed SMSHub custom URL, username and password settings (not needed anymore).
    - Removed SMS SenderNumber and email SenderAddress settings.
      > The SMS sender number is now configurable in SMShub only.
      > The email sender address is configured via the 'org_from' in webadm.conf.
    - Bug fixes with the Link Mode when configured in the user settings.
    - Fixed incomplete token names with QRCode enrollments.
    
1.1.5
    - Added support for WebADM v1.6 (this version does not run on previous WebADM).
    - Added support for access restrictions based on a client policies.
    - Added SpanKey enrolment setting 'Allowed SSH Key Types' to limit the type of
      SSH keys to be self-enrolled.
    - Removed OpenOTP Application Passwords without expiration (OpenOTP v1.3.7).
    - Fixed non working per-user and group policies for AllowRegister,
      AllowTokenTypes and DefaultTokenType.
    - Fixed registration email not beeing sent from the Manager method.
    - Added an optional 'expires' parameter to the manager method.
    - Added support for OTP List registration.
    - Updated OpenOTP Token logo.

1.1.4
    - Removed SMSC configurations (SMSHub is now required for SMS features).
    - Fixed an issue with Yubikey registration with YubiCloud.
    - Added support for newer RCDevs software Token.
    - New RCDevs Token logo image.
    
1.1.3
    - Added multilingual support (French translation for now and more to come).
    - Better support for PKI user authentication via WAProxies.
    - Removed SMSCount and MailCount user statistics (for OpenOTP v1.3.3-2).
    
1.1.2
    - Added support for upcoming U2F on Firefox and Orpera browsers.
      > You need OpenOTP v1.3.2 with this version of SelfReg.
    - Added support for the new OpenOTP Push Login methods.
    
1.1.1
    - Added a new enrolment workflow with RCDevs Software Authenticator.
    - Google Authenticator Token icon is replaced by RCDevs Authenticator.
    - Added an option to download both the PEM and PPK SpanKey private keys
      bundled in a ZIP file.

1.1.0
     - Added support for RCDevs SpanKey Server.

1.0.18
     - Uses the new WAPI framework from WebADM v1.5.0.
     - Added product categorization for WebADM v1.4.5.
     - Complete facelift with new design and login workflows.
     - Added an OTP validation with HOTP and TOTP QRCode registration.
     - Added brute-force attack protection with source IP address blacklisting.
     
1.0.17
     - Remove resynchronization for Yubikeys which is not necessary.
     - Removed the ability for end-users to self-send enrolment requests.
     - Many general user experience enhancements.
     
1.0.16
     - Users can optionally set friendly names or short descriptions for U2F devices.
     - U2F uses embedded javascript and does not require the Google Chrome extension.
     - Sending requests through the Manager method is audited in the Manager SQL log.
     - Added support for WebADM user_level configurations in webadm.conf.
     - Changed the Yubikey registration image to include Yubikey Nano.
     
1.0.15
     - This version is designed for WebADM v1.4 and is not compatbile with v1.3.
     - Added support for WebADM 1.4 admin roles for admin pages and manager methods.
     - The 'Allow Unused Tokens Only' setting is removed and enabled by default.
     - Added support for the %USERID% variable in user message templates.
     - Added support for OATH tokens supporting MD5 algorithm (ex. RedHat FreeOTP).
     - Added support for Plivo online SMS service (http://www.plivo.com).
     - Support form and Token download URLs are hidden if not configured.
     
1.0.14
     - Added support for OpenOTP v1.2 and FIDO U2F device management.
     - Send Registration links can be send to group members (via group actions).
     - Changed Allowed Token Types and Default Token Type settings to be more specific.
       > You need to re-configure these settings if they were enabled.
     - User IDs are replaced by common names (LDAP CN value) in user messages.
     - Simplified the OTP and TiQR authentication test.
     
1.0.13
     - OTP inputs do not display the OTP password (required for protecting OTP PIN).
     - Added support for TiQR 1.0.7-2 with re-designed TiQR+LDAP workflow.
     - Added support for TiQR v1.1 and RSA cryptography.
     - Added support for OpenOTP 1.1.5 and Application Passwords.
     - Item to be enroled can be selected be an administrator or a Manager API call.
     - Added a PKI login feature which bypasses OTP and TiQR authentication.
     - With OTP PROXY mode, OTP Type is changed to TOKEN after Token enrolment.
     
1.0.12
     - Application does not need SMSHub anymore to send SMS registration links.
       > You need to reconfigure the SMSC connection for SMS enrolment.
     - Added support for several Tokens enrolment with Google Authenticator.
     - Added issue URI parameter for Google Authenticator.
     - Added compatibility with WebADM per-application session timeouts
     - Added Yubikey registration with WebADM Inventory (simply by pressing the Yubikey).
     - Added support for YubiCloud-based Yubikey enrolment.
     - Added a setting to prevent a user from enroling Tokens already used by another user.
     - The Default Token Type HARDWARE is replaced by HARDWARE-OATH and HARDWARE-YUBIKEY.
       If you had configured HARDWARE, please change to one of the options after upgrade.
     - Added actions to de-activate and re-activate registered Tokens.
     - Added support for OpenOTP Software Token Expiration and auto re-enrolement process.
     - Added support for OpenOTP/TiQR LoginEnabled configuration.
     
1.0.11
     - New aplication architecture designed for WebADM v1.2.6.
     - Registration links can be sent via SMS when SMSHub Server is installed.
     - Added simple Hardware Token registration with serial numbers. This registration
       mode is highly recommended when dealing with large amounts of Hardware Tokens.
     - Added support for expired LDAP passwords.
     - Changed OTP and TiQR texts to be more user-friendly.
     - OpenOTP and TiQR settings are disabled when application is not present.
     - Email and SMS are sent to all user address and mobile numbers.
     - Added support for WebApp authentication requiring user certificates.
     - Multiple minor other enhancements.

1.0.10
     - Added support for OTP Prefix (PIN) management with OpenOTP v1.1.1.
     - All PIN code values are displayed as bullets.
     - Adapated HTML for WebADM 1.2.5-1 rendering.
     - Input length validations for new password, OTP prefix and PIN code.
     
1.0.9
     - Added support for OpenOTP v1.1 with multi Token and new Fallback methods.
     - Added the possibility to un-register a Token.
     - The Allow Register setting can restrict self-registration to specific Tokens.
     - Added an option to limit the self-registration to one application only.
     - Added support for users with multiple mobile numbers or email addresses.
     - Added a 'Default Token Type' setting to set the default token type in the token
       registration form.
     - Fixed a problem when working in inline mode.
     - Fixed a problem with the mOTP PIN reset.

1.0.8
     - Updated for WebADM 1.2.
     - Added support for WebADM 1.2.x Manager interface.
     
1.0.7
     - Default domain supported.
     - Added a script (bin/register) to send self-registration requests in bulk.
     - Added a setting to configure the registration mail subject.
     - Display enhancements.
     - Added "Allowed Token Types" setting allowing to restrict the types of
       Tokens which can be registered.
     - Uses the WebADM-1.1.3 mail sending system for registration requests.
     - Simplified user interface.
     - Compliance with TiQR Server 1.0.1.

1.0.6
     - Added support for TiQR Service.
     - Many enhancements.
     
1.0.5
     - Update required with WebADM-1.1.1.
     - Added RADIUS Proxy OTP Type support.
     - Added SHA256 and SHA512 key registration support for TOTP/OCRA Tokens.
     - Added support for OpenOTP 1.0.11-1.
     - Added a setting to set OpenOTP logintest URL if not local.

1.0.4
     - Added OATH OCRA support.
     - SelfReg now displays Token infos like in SelfDesk.
     - SelfReg now allows Token download, resync and test like in SelfDesk.
     - Fixed button display with Google Chrome.

1.0.3
     - Added user-initated self-registration.

1.0.2
     - Added Google Authenticator support with QRCode registration.
     - OpenOTP Token register enhancements.
     - Added QR Barcode-based Token key registration.
     - Added default email expiration time setting.
     
1.0.1
     - Uses the new WebADM UI framework.

1.0.0
     Initial SelfReg release.
     Requires WebADM >= 1.0.5.