Blog
IdentityIQ 8.3p5 is now available
Author
doug_spelce
SailPoint
IdentityIQ 8.3p5 is now available
This release includes security fixes, important server and connectivity enhancements, new connectors, changes in connectivity platform support, documentation updates, and general quality and performance improvements. Additional information can be found in the identityiq-8.3p5-README.txt file accompanying the release.
Highlights
- In SailPoint's ongoing commitment to security, this release contains a fix for a previously reported CVE (Common Vulnerabilities and Exposures): CVE-2024-10905. More information about the CVEs in IdentityIQ is located in SailPoint's Security Advisories.
- The 3rd-party libraries in the IdentityIQ Server layer and a subset of connector bundles are updated to newer versions as part of an ongoing commitment to improve the quality and security of the product. The impact on custom connectors, rules, or other customizations which directly or indirectly use these libraries must be validated to ensure compatibility.
- The Java system property org.apache.catalina.connector.RECYCLE_FACADES set to true is now supported to utilize enhanced security settings on Tomcat, preventing the UI errors generated in earlier IdentityIQ versions. This setting is not required but is the default in Tomcat 9.0.90 and later, and it may be optionally set for Tomcat 9.0.89 and earlier. Refer to Tomcat documentation for more information.
- IdentityIQ deployments to JBoss EAP 7.4.0 may encounter IndexOutOfBoundsException warning messages in the server log. These warnings stem from a JBoss issue with the updated version of the Google Guava library included to address IdentityIQ security vulnerabilities. The warnings do not impact the success of the deployment and can be safely ignored. Updating to JBoss EAP 7.4.6 or above will eliminate the warning messages.
- If you are leveraging IQService before and after scripts, you must configure the TLS along with the client authentication for IQService to continue execution of these scripts. Before upgrading IQService in your environment, ensure you have completed the necessary prerequisites for TLS and client authentication configuration.
- For Mainframe Connectors, SailPoint no longer supports DES and 3DES encryption, so existing integrations using DES or 3DES will no longer function. Instead, SailPoint recommends using TLS encryption to secure communication between Mainframe integration components.
- The Oracle NetSuite Connector will exclusively support WSDL v2023 with Token-Based Authentication (TBA) for any new application configured. Support for basic authentication and pass-through authentication will no longer be available for any new application configured after this release. For existing applications of the Oracle NetSuite connector configured using WSDL v2019, support will continue until the end of 2024. However, starting in 2025, only the latest version of WSDL (v2023) and TBA authentication will be supported.
New Connectivity
- The SailPoint integration with AWS IAM Identity Center enables centralizes user access management for multiple AWS accounts. It integrates seamlessly with various AWS Identity Center, enabling streamlined provisioning and management of user accounts within the IAM Identity Center's identity store.
- The SailPoint SAP Cloud Identity Access Governance (IAG) integration enhances the management of user access and compliance within SAP systems. It allows customers to leverage SailPoint as a central hub for initiating access requests across their SAP landscape, including SAP IAG, ultimately streamlining the request process and strengthening governance.
- The SailPoint SAP BTP Cockpit Cloud Foundry connector enhances security and compliance for SAP BTP applications and services by effectively managing user access and entitlements (role collections) across BTP Global Accounts, Directories, and Sub Accounts.
- SailPoint’s SAP Ariba integration provides a comprehensive SAP Cloud integration that enables businesses to significantly improve security and compliance within SAP Ariba procurement and sourcing processes. This integration facilitates streamlined governance of user identities, entitlements such as roles and groups, and the automation of JML workflows for security and compliance requirements across Ariba parent and child realms.
- The SAP Commerce Cloud integration (Hybris) offers access management of SAP Commerce "Employees" type users, group entitlements, and rich attribute collection as supported by SAP.
- SailPoint's integration with SAP Integrated Business Planning (IBP) enhances security and compliance for businesses using IBP by simplifying the management of user identities and entitlements, including roles, catalog IDs associated with roles, and groups. It also automates user onboarding, movement, and offboarding processes to ensure compliance with security requirements.
- The SailPoint SAP Identity Directory connector aligns with SAP's reference architecture and empowers businesses to elevate security and compliance measures for applications integrated with SAP Cloud Identity Services (CIS). By leveraging centralized governance capabilities, this integration streamlines the management of user identities and entitlements (groups), ensuring that stringent security and compliance requirements are met across all SAP Cloud applications linked to SAP CIS.
- SailPoint announces the HealthStream CredentialStream connector, which connects to the HealthStream CredentialStream system and extends a deep level of management to provider data along with facilities, specialties, and credential/license information.
- SailPoint announces the SailPoint Workiva connector, which securely connects with the Workiva system and provides governance capabilities for the Workiva users.
Enhanced Connectivity
- The Microsoft Active Directory connector now supports gMSA as a Service Account using Simple Authentication and Security Layer (SASL) protocol.
- The Atlassian Data Center connector now supports Personal Access Token (PAT) authentication for the service account configured on the application and auto refresh of the tokens when PAT is set as the authentication type. In absence of Atlassian APIs to read all accounts, the connector now supports reading accounts from file exported from the end system for Atlassian Data Center 10.x.
- The Atlassian Data Center for Service Desk Integration now supports Personal Access Token as an authentication method.
- The Box connector now aggregate and provision tracking codes as additional attributes in the account schema.
- The SailPoint Coupa connector now supports aggregation and provisioning of invoicing-user details.
- The Epic SER connector now supports aggregation of multivalued attributes.
- The Google Workspace (formerly G Suite) connector now supports aggregating tags and labels for configured projects.
- The SailPoint Integration Service (IQService) now supports communicating over Internet Protocol version 6 (IPv6). It is now mandatory to configure the TLS and client authentication in order to further enhance the security posture of IQService, especially if you are leveraging IQService before and after scripts.
- The Mainframe IBM RACF, Mainframe ACF2, and Mainframe Top Secret connectors are enhanced to read the 'prependBeforeVal' or 'appendAfterVal' attribute from the attributes map of AttributeRequest in the provisioning plan. It will then prefix/append it to the value of the attribute before passing, it to the SailPoint connectors for Mainframe ACF2, RACF, and Top Secret. This allows the pre/post scripts to access meta data of the provisioning request for each attribute.
- The Microsoft Entra ID (formerly, Azure Active Directory) now supports the following:
- Azure extension attributes and Directory (Entra ID) extension attributes, which store the custom attribute information coming through Active Directory (i.e. onPremisesExtensionAttribute).
- Update operation for multivalued extension attributes.
- Managing Administrative Units as entitlements. For more information, refer to the Administrative Units section in the connector guide.
- Applying group membership filters during account aggregation for memberships belonging to the group object type. For more information, refer to the connector guide around Aggregation, Filter, and Partitioning Settings.
- Managing custom security attributes for Microsoft Entra ID users.
- The Microsoft Dynamics 365 for Finance and Operations connector now supports create, delete, and update of accounts.
- The Oracle NetSuite connector has been enhanced to support WSDL v2023 with Token-Based Authentication (TBA). Please note that support for basic authentication and pass-through authentication will no longer be available for any new application configured after this release.
- The SAP Ariba integration now supports SCIM-based aggregation for high data volumes and adds enhancements for supporting Purchasing Unit ID support.
- The SAP Concur connector has been enhanced to support "Test Employees" and "BI Managers" attributes.
- SAP GRC connector/integration:
- The SAP GRC connector has been enhanced to integrate with SAP IAG, using the SAP GRC system as a bridge. This configuration helps you request user and entitlement provisioning, remove user access, and perform risk analysis of user requests in IAG for connected SAP Cloud systems.
- SailPoint's SAP GRC integration now features a streamlined connection with the SAP ARA Service, facilitating comprehensive Segregation of Duties (SoD) checks and risk analysis through the GRC platform. This improvement enables IdentityIQ managers to identify and correct potential risks proactively before submitting provisioning requests directly via GRC integration. Risks that are identified are marked as Policy Violations, equipping managers with the insights needed to take proactive action or collaborate with key stakeholders, including Requesters, Role Owners, and Risk Owners.
- The SAP GRC integration has been improved to exclude certain systems linked to GRC from user aggregation, provisioning, and attribute update operations.
- The SAP HANA Database Connector now supports multiple SAML (Security Assertion Markup Language) Providers for aggregation and provisioning operations.
- The integration of SAP S/4HANA Public Cloud is enhanced to support the creation of business users, enable API-based aggregation of roles, and manage attributes for these users. This empowers our customers to fully leverage the integration for seamless user lifecycle management, entitlement management, and effective CRUD (Create, Read, Update, Delete) operations.
- The SAP SuccessFactors connector supports aggregation of account as per selected time zones.
- The Workday Accounts Connector now supports implementer accounts, managing Student Accounts, aggregating integration user accounts, and aggregating custom fields for OrganizationRole Group.
- The Workiva connector now supports Group Filter which can be used to filter groups during Group aggregation.
- The Zendesk connector now supports the “Bearer Token“ authentication type.
- The Zendesk for Service Desk Integration now supports the “Bearer“ authentication type.
New Platform Support
- The HCL Domino connector now supports HCL Domino version 14.0.
- The RACF LDAP connector now supports z/OS 3.1.
- The SAP Direct connector is now certified with the SAP ERP Enhancement Package 8 (EHP) for continuous support and seamless integration, and supports SAP S/4HANA 2022 On-Prem SP/FP Stack 04.
- The SAP GRC connector now supports SAP GRC Access Control 12.0 SP26.
- The SAP HR/HCM connector now offers support for SAP Enterprise Central Component (ECC) 6.0 with Enhancement Package 8 (EHP8), and now supports the SAP S/4 HANA 2023 on-premise version.
- The Oracle Database connector now offers support for version 23ai.
- The Oracle E-Business connector now supports Oracle E-Business Suite (EBS) version 12.2.12.
- The Oracle ERP – Siebel connector supports Siebel CRM version 24.X.
- The Oracle PeopleSoft ERP connector now supports PeopleSoft ERP version 8.61.
- The Top Secret connector now supports z/OS 3.1.
- The PeopleSoft HCM connector now supports PeopleTools version 8.61.05.