Enhancements & Bug Fixes:
Out-of-the-box support for ManageEngine SDP MSP ticketing system.
In PMP build 7500, as part of Active Directory integration (in Windows installations), when resource/user groups are imported from AD with spaces in group/OU names, the credential given for importing resources/users from the domain was written as a file name in the bin folder. This has been fixed.
New Features / Enhancements:
Ticketing System Integration: PMP provides the option to integrate a range of ticketing systems to automatically validate service requests related to privileged access. The integration ensures that users can access authorized privileged passwords only with a valid ticket ID. This integration also extends to PMP workflow, which helps in granting approvals to access requests against automatic validation of corresponding service requests in the ticketing system. PMP readily integrates with ManageEngine ServiceDesk Plus, ServiceDesk Plus On-Demand and ServiceNow and provides option for integrating any enterprise ticketing system.
Backend Database Upgrade: PosgreSQL, the backend database bundled with PMP upgraded from 9.2.1 to 9.2.4 .
Option to enforce users to provide reason while retrieving passwords from password history.
Option to export all certificate files with resource details.
Option to clear password flags for IBM AIX accounts after successful password reset.
Changes / Bug Fixes:
Bug Fixes & Enhancements
A SQL injection vulnerability identified in PMP has been fixed.
A clickjacking vulnerability identified in PMP web application has been fixed.
Earlier, when email notifications on change in access permissions had been disabled, two factor authentication could not be assigned in bulk. This has been fixed.
Earlier, disabling the option to receive email notifications (upon the occurrence of audit events) as daily digest did not take effect. This has been fixed.
Provision to view keyboard layout in other supported languages when launching remote RDP sessions from PMP.
Bug Fix
New Features & Enhancements:
Session shadowing: Total control on privileged sessions with support for 'session shadowing', which enables administrators to closely monitor administrative access and terminate suspicious activities.
ISO/IEC 27001:2013 compliance report: Automated, audit-ready compliance report for access control requirements of ISO/IEC 27001:2013.
Auto logon using other domain accounts: Provision to launch a direct RDP connection with target resources using any domain account that is owned by / shared to the user. In addition, users can opt to use the currently logged in AD account too to connect with the remote resource.
Support for configuring the port at which the Remote Desktop Service is running on the remote host. PMP will launch RDP sessions through the port specified.
Multi-language support now available for PMP mobile apps (iPhone & iPad) too.
Provision to check the validity of digital certificates (x.509 certificates) stored in PMP and to trigger alerts upon expiry.
Bug Fixes
A filename Denial of Service Vulnerability identified in PMP has been fixed.
Earlier, the HTTPONLY attribute had not been set in some cookies that were used to track a user's session. This has been fixed now. This ensures that it is not possible for the cookie to be accessed by scripting languages.
Earlier, when single sign on had been enabled, PMP agents were not working. This has been fixed.
Synchronizing offline data with DropBox failed due to some changes at DropBox end. Configurations in PMP have been changed to fix that.
Bug Fixes
Earlier, the batch or script file ReplicationPack.bat/sh used for replicating PMP database (with MySQL as back end database) was not working. This has been fixed.
In PMP 7101, product license expiry alert was being triggered erroneously in certain scenarios. This has been fixed.
New Features / Enhancements
MSP admins managing the resources of multiple clients can now replicate resource or user group structure and certain settings across all managed client organizations.
Option to enable /disable SSH session gateway, which allows launching remote terminal SSH sessions from browser.
Actions such as sharing resources, transfer ownership and access control configuration can now be performed from the search result view itself.
Bug Fix
Earlier, fetch and update of the scheduled task passwords on the target Windows 2008 servers failed in certain scenarios. This has been fixed.
Earlier, if the username for logging in to PMP contained non-ascii characters, authentication failed. This has been fixed.
Earlier, password reset operation through REST API was getting executed even when access control had been enabled for a resource. This has been fixed.
Earlier, in PMP MSP edition, Cisco IOS password reset was not working in client organizations. This has been fixed.
New Features / Enhancements
Cloud Environment Password Management:
Password Manager Pro now extends password management to cloud environments. Cloud managers can securely store, share, periodically change and control access to the management console or administration panel passwords of Microsoft Azure, Google Apps, Amazon Web Services and Rackspace accounts from PMP.
This move helps safeguard cloud platforms from attacks on administrative accounts and overcome information security concerns besides tracking privileged account activity in the cloud to meet various regulatory compliance requirements.
Four new resource types - Microsoft Azure, Google Apps, Amazon Web Services and Rackspace have been added in PMP.
New RESTful APIs:
PMP already provides a good number of RESTful APIs, which help you to connect, interact and integrate any application with Password Manager Pro directly. Three new APIs have now been provided to add users, delete resources and approve/reject password access requests.
Share Resources from Home Tab & Global Search Results
Bug Fixes / Changes
JVM crash issue fixed: In PMP 7002 & 7003, JVM crash was reported in certain environments during AD authentication and windows password reset. This has been fixed.
When using SAML 2.0 for user authentication and single sign-on through federated identity management solutions, there was an issue when the web server certificate had been configured with a PKCS12 certificate. This has been fixed.
Earlier, there was an issue in migrating the back-end database from MySQL to PostgreSQL resulting in migration failure. This has been fixed.
The maximum characters count for BaseDN and Search Filter parameters for importing users from LDAP has been increased to accommodate a larger strings.
Changes & Bug Fixes
New Features & Enhancements
SAML 2.0 support: User authentication mechanism in Password Manager Pro has now been strengthened with SAML 2.0 support. Password Manager Pro now integrates with federated identity management solutions for single sign-on. Technically, Password Manager Pro acts as the SAML service provider, and it integrates with SAML identity providers. The new integration helps leverage the identity provider's authentication to access Password Manager Pro. Users who have deployed Okta, OneLogin or any other SAML identity provider can automatically log in to the Password Manager Pro application from the respective identity provider's GUI without supplying credentials, after configuring PMP with the identity provider.
Session Shadowing: Session recording capability has been extended to enable real-time monitoring of sensitive privileged sessions launched by users. Administrators may also terminate sessions in real time if any suspicious activity is found, giving admins complete control over privileged sessions.
Language Selection: PMP administrator can now select the language for all users in 'General Settings'. Password Manager Pro can be localized in Chinese, Japanese, Spanish, German, French, Polish.
Changes & Bug Fixes
Password Manager Pro now bundles JRE v7u51
For privileged session management, Password Manager Pro acts as the Gateway for launching Windows RDP and SSH sessions from the user's browser. These sessions are launched within a HTML5 compatible browser and the connection to the end devices are tunneled through the PMP server that acts as the session gateway, while also recording the session. In the latest versions of Chrome and Firefox, launching RDP sessions did not work. The screen closes immediately after launching the session. This has been fixed.
PMP v7001 was identified to be having directory traversal vulnerability. This has been fixed by updating the RDP gateway.
Earlier, when PMP was installed in other language boxes, audit trails were getting recorded in the respective language though the PMP web GUI was in English. This has been fixed.
In v7001, when PMP license key with no multi-language support was installed, PMP stopped recording audit trails after a server restart. This has been fixed.
Possibility for an XSS vulnerability (which can be triggered during authentication), was identified in PMP v7001. This has been fixed.
Earlier, when configuring PMP to run in FIPS 140-2 compliant mode, nss libraries were required to be downloaded. Now, PMP uses nss v3.12.4 and it comes bundled with that.
New Features & Enhancements
Provision to localize Password Manager Pro (introduced in 7.0) has been enhanced now. PMP can be localized in Chinese, Japanese, Spanish, German, French, Polish.
Provision to set any resource type as 'default type', which will remain the default selection in 'Add Resources' GUI
PMP supports a good number of resource types for remote password reset. You can filter the types and choose to display only the required ones in the 'Resource Type' drop-down in 'Add Resources' GUI.
Provision to create a link to a shared password and enable authorized users to quickly access that password as a pass card in the GUI
Bug Fixes, Changes
When using PMP with MS SQL server as the backend database, under "Admin", the option to manage encryption key was missing. This has been fixed.
In build 7000, the text field to search custom fields was not getting displayed in resources page. This has been fixed.
When sharing resources of the type 'File Store' with 'Modify permission, changing file was not working. This has been fixed.
Due to a typo in message display, the result for 'Verify Password' was being shown as 'Not in sync', when it was actually in sync. This has been fixed.
New Features & Enhancements
MSP Edition: A separate edition to help Managed Service Providers (MSPs) manage the passwords of each of their clients separately, from a single management console. Passwords can be securely shared between MSP administrators and their respective customers, making sure that users only get access to the passwords they own or ones that are shared with them. The solution offers the flexibility to entrust the control of the password vault to the MSP administrator, the end user or both, as desired.
Data Center Remote Access Management: Provision to launch secure, one-click SSH/Telnet access to remote devices in data centers with full password management. Typically, data centers limit direct access to remote devices via SSH connections due to security reasons and network segmentation. Instead, data center admins working remotely must first connect to a landing server and then "hop" to the target system. Administrators can now configure landing servers and their login credentials and then associate them with the resources being managed by Password Manager Pro. In turn, admins can launch a one-click connection with the remote resources without worrying about the intermediate hops. While the admin experiences a direct connection, Password Manager Pro automatically executes all of the intermediate hops in the background, establishing a connection with each landing server and finally with the remote resource.
PMP Speaks Your Language: Provision to get PMP working in your language. At present PMP can be localized in Chinese, Japanese, Spanish, German, French, and Polish languages.
Bulk Operation Support: Features like session recording, auto logon for web apps and password reset can now be configured in bulk for many devices at one go.
LDAP User Groups Synchronization: User groups in LDAP can now be automatically synchronized at periodic intervals with the user database in PMP.
Changes & Bug Fixes
When auto logon for web apps had been configured through PMP bookmarklet, certain web sites and application do not allow auto submission of credentials for automatic login. To handle such cases, provision has now been made only to auto-fill the details. Submission can be done by the users. This can be configured from Resource >> More Actions.
Email notifications sent from PMP for password retrieval and change events did not contain the reason field. This has now been fixed
Earlier, when PMP web interface is launched in Internet Explorer, the login name of the custom categories created as part of 'Personal tab' were not getting displayed. This has been fixed.
In PMP v6902, when access control workflow had been enabled, when a user checks-in a password after exclusive use, it was not being reset. This has been fixed now.
When using global search in PMP with PostgreSQL as backend database, extended ASCII characters typed as search strings were not getting displayed. This has been fixed.
Earlier, when PMP web interface is launched in Internet Explorer, there were problems in playing back the RDP sessions recorded by PMP. This has been fixed.
Earlier, there were issues in generating custom reports with User Audit as the base. This has been fixed.
Earlier, the alerts on the status of High Availability (in PMP with MySQL as backend database) were not being sent. This has been fixed.
Bug Fixes
In PMP v6903, when access control workflow had been enabled, when a password user checks-in a password after his usage, it was not being reset. This has been fixed now.
New Features / Enhancements
RADIUS / RADIUS-Compliant Authentication System for Two Factor Authentication: Option to leverage RADIUS server or any RADIUS Compliant two Factor Authentication system (like Vasco Digipass) for the second factor authentication.
RESTful APIs: PMP now provides RESTful APIs, which help you to connect, interact and integrate any application with Password Manager Pro directly. The APIs also allow you to add resources, accounts, retrieve passwords, retrieve resource/account details and update passwords programmatically.
Bug Fixes
At times, PMP login screen prompted users to enter the password again even when the password entered was correct. This has been fixed now.
Earlier, there were issues in alphabetically sorting the entries in Resource tab and Home tab (when using PMP with PostgreSQL as the backend database). This has been fixed.
When Access Control Workflow had been enabled, in certain environments, resetting of passwords of Netscreen devices after the end of the exclusive use period was not working. This has been fixed.
In PMP v6902, when a user fails to check-in a password at the end of his usage period, PMP resorted to automatic check-in of passwords, but the password was not being reset. This has been fixed now.
New Features / Enhancements
Google Authenticator for Two Factor Authentication
PMP now provides the option to leverage Google Authenticator, a software based authentication token developed by Google as the second factor of authentication. Already, PMP supports PhoneFactor, RSA SecurID and a one-time, randomly generated unique password as the second level of authentication for two factor authentication.
Exporting Resource Groups
Option to automatically export the resources belonging to specific resource groups by creating scheduled tasks. The data gets exported in the form of an encrypted HTML file.
Bug Fixes
In PMP build 6901, there were problems in starting PMP when installed as secondary server in High Availability architecture in Linux machines. This has been fixed.
New Features / Enhancements
Support for launching PMP web-interface in Internet Explorer 10
The implementation procedure for "Custom Listener", which enables providing your own implementation for Password Reset Listener, has now been simplified with the enhancements in the GUI. You need not have to edit the configuration files in PMP manually to enter the details about the implementation class. These details can now be provided through entries in GUI
Enhancements to bolster the overall security posture of the product
Bug Fixes
Earlier, when the administrator had restricted the users from viewing the passwords in plain-text when auto logon had been configured, in certain specific scenarios, there were issues in retrieving passwords even when auto logon had not been configured. This has been fixed.
Restrictions on the usage of weak ciphers in the product
New Features / Enhancements
PMP iPhone app is now available for download directly from App Store. Facilitates secure retrieval of privileged passwords and approval of access requests on the go. Provides offline access to privileged passwords too.
"Custom Listener", a new feature that enables you to provide your own implementation for Password Reset Listener. With the provision to have your own listener implementation class (instead of just letting PMP execute the listener script provided by you), Custom Listener offers complete flexibility to execute any post password reset follow-up action.
Provision for remote password synchronization of VMware ESXi resources through VMware vCenter API.
Bug Fixes
Earlier, Active Directory User GUID check wan not included in AD authentication. This is included now.
Administrators and Password Administrators can now filter and view all the resources that are owned by them in the 'Resources Tab' by selecting the 'All owned resources' option.
Bug Fix
In builds 6800, 6801 and 6802, Password Manager Pro client session launched from Internet Explorer was getting terminated intermittently. This has been fixed.
Changes/Bug Fixes
In builds 6800 and 6801 with PostgreSQL as backend database, the global search did not show results properly for Password Users. This has been fixed.
Users who wish to migrate to PostgreSQL as the backend database from MySQL are now required to download PostgreSQL-9.2.1-Windows.zip (For Windows) / PostgreSQL-9.2.1-Linux.zip (For Linux) and then run the migration script.
Enhancements/Changes/Bug Fixes
Support for migrating data from PMP running with PostgreSQL as backend database to MS SQL server. Migrating data from MySQL to PostgreSQL is also supported.
Build 6800 did not get installed properly when attempted to install in Linux as root user. This has been fixed.
In build 6800, in some environments, the high availability status was not properly depicted. This has been fixed.
Enhancement/Change
Changes / Bug Fixes
While adding the domain account as a resource, PMP provides the option to select the resource groups for service account reset. For every Windows system present in those groups, PMP will find out the services which use this domain account as service account, and automatically reset the service account password if this domain password is changed. In PMP build 6700, when a Windows domain account was added, the resource groups selected for service account management were not getting saved. As a result, the service account reset for the resources that are part of the selected resource groups did not work. This has been fixed now.
New Features & Enhancements
Privileged Session Recording
Privileged sessions launched from Password Manager Pro can now be recorded, archived and played back to support forensic audits and let enterprises monitor all actions performed by privileged accounts during privileged sessions. Password Manager Pro enables recording of Windows RDP, SSH and Telnet sessions launched from the product.
Auto Logon for Web Apps
Option for enhanced auto logon to web applications by installing PMP bookmarklet on the browser bookmarks bar. PMP can be setup to auto-fill the login page of web applications with appropriate username/password information, to allow users to login to those apps with just a few clicks, instead of manually entering the information.
Manipulating Explorer Tree
Provision to allow admin users to manipulate the entire explorer tree structure in any manner as they wish. Once this is option enabled, PMP creates an organization wide, global explorer tree structure containing the names of resource groups under a root node. Any administrator in PMP would be able to create/edit the explorer tree structure of resource groups. The tree structure will be accessible to all admins, password admins and end users. Admins and password admins can add their resource groups anywhere into the global tree and the whole structure will be available for view to all the end users. If this option is disabled, users can modify only their portion of the tree.
Password Access Control Report
New report providing complete details about the password access control workflow scenario of your organization. List of resources for which access control has been enabled, resources for which access control is deactivated, resources for which the requests are automatically approved, list of password release requests approved/denied etc are depicted.
Changes / Bug Fixes
Earlier, when resources were imported from active directory, certain values like display name, description and location were not properly populated in PMP. This has been fixed.
Earlier, there were issues in adding additional fields (to enter password values) for resource types such as license store, file store and key store. This has been fixed.
Earlier, there were issues in editing the files that were added through custom fields. This has been fixed.
New Features & Enhancements
New Resource Types Support for Remote Password Synchronization
Super-Administrator as 'Break Glass Account'
Provision to keep the super-administrator role as a break-glass account for emergency access to passwords. Hitherto, any administrator could change the role of another administrator (not himself) as super-administrator. PMP now provides the option to prevent administrators from creating super-administrators. Super-administrator role can be used as break glass account as explained below:
Create a new administrator account in PMP and designate the new account as the Super-Administrator
The new super-administrator will login and enforce the option of denying other administrators from creating super-administrators
The login credentials of this super-administrator will be sealed and kept in a safe to be opened only for emergency access
PMP Agents
When PMP agent is deployed in target resources for remote password reset, the resource and all its accounts will be automatically added to PMP
Provision to configure synchronization for deletion of accounts in PMP when the corresponding account is deleted in the remote resource
Password History
New Browsers Support
Reports
Bug Fixes & Changes
PMP GUI has been given a facelift
Resources imported from Active Directory now contain DisplayName, Description, Location and other details
Provision to notify users when a resource/resource group is shared or share permission is changed
Earlier, when a file based additional field is created, Service Accounts could not be edited/saved with the Resource Groups for scanning. This has been fixed.
Bug Fix
New Features/Bug Fixes/Changes
Encryption Key Rotation: Provision to change the master encryption key either periodically as a best practice or at suspicion of key compromise. Fully automated steps to regenerate new key, decrypt all data with old key, encrypt them with new key and securely storing the new key.
User Preferences Setting: PMP users can now set individual preferences for what view should be loaded by default in the 'Home', 'Resources', 'Audit' and 'Reports' tabs in the web user interface.
New Features & Enhancements
No-Frills Auto Logon for Launching Windows RDP and SSH Remote Terminal Sessions
Leveraging the power of HTML 5, PMP 6.5 brings the first-in-class auto logon mechanisms for launching Windows RDP, SSH and Telnet sessions. While current solutions require inconvenient and insecure methods like end-point agents, helper programs at user desktop and browser plug-ins, the only requirement for PMP's cutting-edge solution is a HTML 5 compatible web browser. Users can launch highly secure and completely emulated Windows RDP, SSH and Telnet sessions from within the browser with a single click, not requiring any access to passwords
Being HTML 5 compatible, users can launch Windows RDP and SSH sessions also from browsers in their tablet devices like iPad
Provision for authenticating both with the local accounts as well as domain accounts for the launched Windows RDP sessions
A new sub-tab named 'Auto Logon' has been introduced in Home Tab for easily locating the remote accounts and quickly launch one-click sessions
Secure, Offline Access to Passwords with Auto Sync
Support for secure, offline access to passwords. Users will get an option to export the passwords in the form of an encrypted (AES-256 encryption) HTML file, which can be opened in browsers for offline access
Provision to automatically synchronize the exported HTML file to users' mobile devices through Dropbox. From a single action in PMP user interface, the offline file lands in the users' Dropbox app in their smart phones or tablet devices
Admins can configure PMP to automatically delete the exported files to users' Dropbox accounts after a set time period
Admins can configure all passwords that were exported to be automatically reset in the remote systems after a set time period
Support for remote password reset and verification of VMWare ESXi and HP iLO resources
Bug Fixes & Changes
The option to restrict the users from exporting passwords in plain-text has been moved from 'General Settings' to "Admin >> Customize >> Export Passwords - Offline Access" GUI. The option is also available in 'User' and 'User Group' tabs
Earlier, there were issues in displaying custom fields when creating/editing resources. This has been fixed.
In the GUI to create copies of resources/accounts and in the GUI to move accounts from one resource to another, the names of resources and accounts will henceforth be shown in alphabetical order
Earlier, in some specific scenarios (where authentication was required) there were issues in sending emails from PMP. This has been fixed.
Earlier, in the case of auto logon helper (browser plug-in deployment model) there was an issue in launching direct connection to target systems. This has been fixed.
Earlier, there were issues in launching PMP web-interface in Firefox 11. This has been fixed.
Automatic Approval in Access Control Workflow
Provision for automatic approval of password access requests. Users need not have to wait for approval by authorized administrators while going through the access control process.
RADIUS Server Authentication
RADIUS server can now be integrated with PMP for leveraging RADIUS authentication.
List of Super Administrators
List of all super administrators will be displayed in the information bar to all administrators, password administrators and auditors
Bug Fixes / Changes
Invoking auto logon helper in turn downloads a browser addon file. The SSL certificate that ensures trustworthiness of the addon has now been renewed.
Earlier, user group activity report was not displayed properly on the dash board. This has been fixed.
New Features / Enhancements
Dual encryption of passwords and files for extra security. Sensitive data are now encrypted once in the application (AES 256-bit) and once in database
PMP can now be set-up to run in FIPS 140-2 compliant mode where all encryption in PMP is done through FIPS 140-2 certified systems and libraries
Provision to prevent the execution of malicious code/script in the application to combat cross-site scripting
Password Activity Report enhanced with details on the list of resources for which access control workflow has been activated/deactivated and also the resources for which access control workflow has not been configured
New report depicting the resources / passwords that are not part of any resource group
Provision to check integrity of passwords of a resource group with support for integrity verification on-demand & scheduled
Bug Fixes / Changes
Earlier, two options were provided for managing encryption key in PMP - you were allowed to either leave it to be managed by PMP or move it to a secure location / external drive and manage it yourself. Now, the option of leaving it to be managed by PMP has been removed. PMP does not allow the encryption key to be stored within its installation folder. This is done to ensure that the encryption key and the encrypted data, in both live and backed-up database, do not reside together. It is strongly recommend that you move and store this encryption key outside of the machine in which PMP is installed - in another machine or an external drive.
Earlier, when exporting the personal passwords, the custom fields were not shown in plain-text. This issue has been fixed.
Earlier, through 'Admin >> Server Settings', when the PMP server port alone was changed, it threw an error. This has been fixed
UTF-8 encoding support in MS SQL server
New Features / Enhancements
MS SQL Server as Backend Database
Support for MS SQL server as the backend database in PMP.
High Availability Support with MS SQL Server
AES 256 Encryption
Remote Password Reset of LDAP Servers
Remote password reset support for LDAP servers belonging to the types Microsoft Active Directory, OpenLDAP, Oracle Internet Directory and Novell eDirectory
Password Reset Schedules
PMP Agents
Prior to 6400, some of the communication between PMP server and agents was initiated by the server, which required the agents to keep a TCP port open. To eliminate this risk and the need to manipulate firewall rules to allow traffic to a non-standard port on the agent side, the communication model is changed where the agents always initiate communication with the server. The agents periodically check for tasks by opening a secure connection with the server and no longer need to have a port open in the system they are installed.
LDAP - PMP User Database Synchronization
Whenever new users get added to the LDAP, provision to create synchronization schedules and automatically add the users to PMP and keep the user database in sync.
Active Directory
Support for using the same user credential to import information from multiple domains, based on the privileges and trust setup in AD.
Copy Resources
Copy/Move Accounts
Configuring Server Settings, SSL Certificates through GUI
Custom SSH/Telnet ports
Instant Backup
Performance Enhancements
Changes / Bug Fixes
Earlier, there was an option to send notifications to users after importing them from Active Directory. This option has now been removed.
Earlier, in LDAP user import, the OU and other details entered were not persisted. Now, the details are saved and displayed
Earlier, while creating scheduled tasks for custom reports, the option to send the report to the users specified under 'other users' did not take effect. This has been fixed.
Earlier, the password reset of Ubuntu resources did not work when 'sudo' had been used. This is fixed
In Internet Explorer, there was an issue in auditing the reason entered by the users for retrieving a password using auto logon helper. This has been fixed
Earlier, there were issues in editing the properties of resource groups. This has been fixed.
The issue in generating AD user schedules report as a PDF has been fixed
The issue related to exporting personal passwords as XLS has been fixed
In PMP build 6400, the share permissions to the user groups imported from Active Directory did not take effect. This has been fixed.
In certain scenarios, generating the 'User Access Report' as a PDF did not work. This has been fixed
Earlier, when password access control had been enabled, in certain scenarios, when a user made a request to access a password, there were issues in sending email notifications for approval to the administrators. This has been fixed.
Earlier, in High Availability set up with MySQL, when the slave database was restarted, PMP raised an alert stating High Availability was not alive. Now, in scenarios like this, PMP will double-check the status before raising the alert
In personal password management, the issue related to deleting the personal categories has been fixed
Changes & Bug Fixes
Vulnerability related to the printing of sensitive data in mysql binlogs has been fixed by bundling MySQL 5.1.50
Earlier, there were problems in displaying the Active Directory synchronization schedule in GUI. This has been fixed
Earlier, in certain cases, the 'Edit User' provision for the users imported from LDAP did not work. This has been fixed
Earlier, when SMTP settings were modified, the details were saved, but GUI did not reflect the changes. This has been fixed
Earlier, when setting High Availability and Live Backup, DNS lookup for secondary server / slave database threw error in certain environments. This has been fixed.
Earlier, when multiple administrators were selected to approve password access requests in Access Control Workflow, there were issues in sending email notifications for approvals. This has been fixed.
Earlier, there were some issues when authentication was required for configuring SMTP mail server settings. This has been fixed.
Previously, password integrity check for Windows local accounts (which were not present in administrator group) did not work. This has been fixed.
Earlier, when synchronization schedule had been created for resource import from active directory, newly added user accounts were not imported. This has been fixed.
Earlier, audit trails pertaining to failed password reset events for certain resources were not recorded. This has been fixed now.
New Features / Enhancements
PhoneFactor Authentication
ManageEngine has partnered with PhoneFactor, the leading provider of phone-based two-factor authentication for two-factor security for Password Manager Pro. Already, PMP supports RSA SecurID authentication and generating a one-time, randomly generated unique password as the second level of authentication for two factor authentication.
Smart Card Authentication
Custom Reports
Support for creating customized reports out of the canned reports and audit reports. You can specify custom criteria and create customized reports as per your needs
Changes & Bug Fixes
Hitherto, when synchronization schedule had been enabled for importing users from Active Directory, changes in email addresses in Active Directory did not get updated in PMP. This has been fixed now
Earlier, as part of automated password integrity check, PMP made three attempts to verify the passwords on target systems. This led to lockout scenarios due to the IT policy related to failed login attempts. This has been changed now and PMP attempts to check password integrity only once
Option to import resources from Active Directory with fully qualified domain name (fqdn) as the DNS name of the resource
Verify password feature did not work for SYS accounts in Oracle 10g. This has been fixed
Support to populate old password, when attempting to change the password of HP UX resources
Option to specify the time period in minutes up to five digits while granting exclusive access to passwords (when enabling access control workflow)
Earlier, in 'All Passwords' UI, at times, password field was displayed as undefined. This issue has been fixed
Earlier, when entering a reason for password retrieval had been made mandatory, in some cases, copy to clipboard did not prompt reason column. This has been fixed
New Features / Enhancements
SIEM Integration
Provision for generating SNMP traps and Syslog messages upon the occurrence of any activity/event - be it password access or modification or any other activity performed in the PMP application. The traps/syslog messages can be sent to the SIEM tools, which can thoroughly analyze these events, correlate them with other network events and provide informative, holistic insights on the overall network activity.
Two Flavours of APIs for A-to-A Password Management
Completely revamped provisions for Application-to-Application Password Management, which help eliminate hard-coded passwords in enterprise environments. PMP provides two flavors of the API - a comprehensive application API based on XML-RPC over HTTPS and a command line interface for scripts over secure shell (SSH), using which any enterprise application or command line script can programatically query PMP and retrieve passwords to connect with other applications or databases.
Local Service Account Password Rese
Enhancements in Bulk Password Reset
Reports
Bug Fixes / Changes
Earlier, after carrying out a search operation, if one accessed the 'Enterprise Passwords' tab, while an empty page was shown in Firefox, a warning page came up in Internet Explorer. This issue has been fixed now
Earlier, in Password Request-Release workflow, when the time limit for administrator approval was set as '0' indicating indefinite time period, the approval time period ended after some time. This has been fixed now
Earlier, in certain cases, Windows remote password reset and password integrity verification failed. It has now been fixed
Earlier, while implementing concurrency control in Password Request-Release workflow, the maximum time period up to which the password was to be available exclusively for a particular user was specified in hours. This has been changed to minutes to enable granting of exclusive privilege less than one hour
Earlier, the view length of entries (passwords/resources) in PMP web-interface was not user-specific. It has been made user-specific now.
Entries in password explorer tree in the 'Home Tab' are now sorted alphabetically
Provision to control 'Manage Share' permissions for criteria-based resource groups
Earlier, Single SignOn worked only with NTLM-v1. Now, it works with NTLM-v2 through integration with a third party library named 'Java Enterprise Security Provider Authority' (Jespa), which provides advanced integration between Microsoft Active Directory and Java applications
Earlier, MD5 algorithm was used for hasing the PMP user passwords for local authentication. Now, SHA 512 is being used.
Earlier, when Single Sign-On was enabled, audit entries related to user login to PMP were not recorded. This issue has been fixed now
Earlier, in certain cases, scheduled tasks were not being executed. This issue has been fixed now
Earlier, help documentation for Application-to-Application Password Management through XML-RPC API dealt only with using XML-RPC in Java. Now, the procedure for using it in other programming languages added.
New Features / Enhancements
Nested Resource Groups
Password Explorer
Remote Password Synchronization for Juniper Netscreen Devices
Templates for Customizing Email Notification Content
Export Passwords of Resource Groups
Bug Fixes & Changes
MySQL version upgraded from 5.0.36 to 5.079
Earlier, when there were large number of passwords, loading of the dashboard took some time. This has now been optimized
Earlier, there were issues in carrying out password synchronization / verification using a single account in Linux. This has been fixed.
Earlier, when Active Directory authentication was enabled, there were problems in logging in to PMP using the local authentication when a AD user was deleted. This has been fixed.
Earlier, when a resource group name contained a single quote, the hierarchical arrangement of resource groups were not properly shown. This has been fixed now.
Earlier, when the 'Personal Password' option was disabled for a Password User, the Password Explorer view became hidden. This has been fixed now.
So far, no cipher was explicitly mentioned for encrypting the connection between the two MySQL database instances, used in high availability and live backup scenarios. Now this connection is also AES encrypted by choosing the DHE-RSA-AES256-SHA cipher for the SSL channel.
The JDBC connection between the JRE (Java(TM) Runtime Environment) and the MySQL database is now encrypted by default, to eliminate the need to set it up separately.
All user input submitted in the user interface are centrally validated to check for and discard harmful inputs that could cause scripting attacks like cross-site scripting (XSS) irrespective of case of the scripting content.
All user input submitted in the user interface are centrally validated to check for and discard harmful inputs that could cause scripting attacks like cross-site scripting (XSS) or SQL injection.
When password policies contained a special character in the policy name, there were issues getting the policy work after editing it. This has been fixed now
Earlier, the 'verify password' operation failed for Linux and HP-UX target systems in certain environments. This has been fixed
Earlier, the custom fields for accounts did not support special characters in name. This has been fixed
Earlier, administrators were permitted to allow exclusive password access to a user for a maximum of 99 hours. Now, it has been modified to enter three-digit figures (in hours)
In PMP 6001, while carrying out high availability setup, there were issues in creating the replication pack. This has been fixed
Earlier, in PMP high availability set up, the /mysql/data folder was growing in size. This has been fixed
New Features / Enhancements
Password Access Control Workflow
Support for password request-release workflow to enforce enhanced access control in the product. The user, who requires a password, will have to 'request the release' and one or more administrators will authorize the request. Password will be made available for the exclusive use of the user for a stipulated period of time. It will be automatically reset thereafter and the user will thereby forfeit the access.
Two-Factor Authentication
Option to enforce users to identify themselves with two unique factors through two successive stages before they are granted access to PMP web-interface. While the existing authentication mechanism of PMP (native authentication / AD / LDAP) will be the first authentication factor, the second authentication factor could be either a unique password generated by PMP and sent through email or RSA SecurID one-time token, which changes every sixty seconds. For RSA part, PMP has entered into a technology partnership with RSA, The Security Division of EMC (NYSE: EMC).
Firefox 3 Plug-in
Flash 10 Support
Remote Password Reset
Password Policy
PMP Login GUI
If you have users from various domains, the PMP login screen will list-down all the domains in the drop-down. For ease of use, you may specify the domain used by the largest number of users or the frequently used domain in "General Settings". Once you do so, that domain will be shown selected by default in the PMP login GUI
New OS Support
Changes/Bug Fixes
Importing Resources
Resource Type
Active Directory Integration
When users are imported from domain, by default, email notification is sent to all the imported users. Now, an option has been provided to disable the Email notification.
Earlier, if the password of the users imported from Active Directory contained special characters such as &, %, authentication failed. This has been fixed.
Reports
PMP carries out periodic checks to ascertain if the passwords stored in the system and the ones in the actual resource are in sync with each other. The results are presented as 'Password Integrity Report'. Earlier, the integrity check was being done at 1 AM everyday. Now, an option has been provided to configure the integrity check timing.
Single SignOn
Usage of Single Quote in Email Address
New Features / Enhancements
Remote password synchronization for Oracle DB Server and Sybase ASE
On demand check for Password Integrity
New Resource Creation in A-to-A Password Management
Support for non-English characters
Use of 'sudo' for Privilege escalation
Agent-based password reset
Audit Views
Changes & Bug Fixes
New Features / Enhancements
Changes/Bug Fixes
New Features / Enhancements
Remote password synchronization for MySQL servers and HP ProCurve devices
PMP in two editions
Reports in .xls format
Changes / Bug Fixes
New Features / Enhancements
Remote password synchronization for Cisco devices, MS SQL servers
Helper for automatic login to target systems
SSL connection with external identity stores
Windows Scheduled Task Password Reset
Alerts for audit events
Activity, integrity and compliance Reports
Performance Improvements
Changes & Bug Fixes
New Features / Enhancements
High Availability Support
Uninterrupted access to passwords by deploying redundant PMP server and database instances
A-to-A, A-to-DB Password Management
Support for Application-to-Application/Database password retrieval and management by deploying 'Password Management APIs'
Windows Service Account Reset
Support for automatically resetting the passwords of associated windows service accounts when the domain account passwords are reset through PMP. Optionally the windows services could be restarted remotely to force the password change immediately
Password Reset Listener
Support for invoking a custom script or executable as a follow-up action to Password Reset action in PMP
Super Admin Support
Any administrator could be made as a 'Super Administrator' with privilege to view and manage all resources in PMP
Encryption Key Management
Provision for securely storing the unique encryption key (generated during PMP installation) somewhere outside PMP and instructing PMP to read it accordingly
Importing Users/Resources from Active Directory
Resource Type Customization
In addition to adding custom fields it is now also possible to remove built-in fields for the various resource types
Notification for Passwords Out of Sync
When the passwords present in PMP differ with those in the actual resource, notifications (informing the out of sync) could be sent to desired recipients
Dashboard Reports
Changes & Bug Fixes
New Features / Enhancements
Bug Fixes
Changes
Bug Fix
New Features / Enhancements
Bug Fixes
Limitation
New Features / Enhancements
Changes
Bug Fixes