Host Access Management and Security Server - Release Notes

August 2018

Host Access Management and Security Server version 12.5.1 released with Reflection ZFE 2.3.1.

See what’s new and what’s been resolved since version 12.5 released.

What’s New

Host Access Management and Security Server 12.5.1 includes these features and upgrades (in addition to the features introduced in 12.5):

  • Added the ability to configure multiple DCAS servers and for use with Automated Sign-on for Mainframe.

  • Updated Open JDK to Azul Zulu 8u181.

  • Updated Apache Tomcat to 8.5.32.

  • Reminder: Management and Security Server requires 3.40 GHz (4 cores) and 8GB of RAM to run efficiently.

    While previous versions may have run successfully on less, we recommend you allot 8 GB of RAM for a successful installation.

NOTE:

  • The Metering Server can be installed on a separate server, using the automated installer. The Metering Server is no longer available as a deployable war file that can live on WebSphere or external Tomcat.

  • The Terminal ID Manager can be installed on a separate server, using the automated installer or the Administrative Console (Configure Settings - Product Activation). The Terminal ID Manager is no longer available as a deployable war file that can live on WebSphere or external Tomcat. See the Installation Guide for details.

Resolved Issues

  • SAML authentication (for Reflection ZFE clients). Management and Security Server supports a web proxy or load balancer when the device is configured to handle the Identity Provider's Response to a SAML Authentication Request.

  • SAML authentication (for Reflection ZFE clients). When Management and Security Server is configured for Debug logging, the list of hosts that are whitelisted for SAML is printed in the logging message.

Known Issue

  • Using Mozilla Firefox with SAML authentication (for Reflection ZFE clients). The SAML Download button does not return updated metadata when Firefox is the browser of choice.

    Specifically, changes to the Entity ID and the Assertion consumer service prefix URL are not represented in the SAML Service Provider metadata for MSS when Firefox is used to export the metadata via the Download button.

    Workaround: Download the metadata by using the URL (https://<hostname>/mss/saml2/sp-metadata). Or, use a browser other than Mozilla Firefox.

Resources

MSS Security Updates

MSS Installation Guide

MSS Administrator Guide (online Help)

MSS Product Documentation

Technical Resources, including documentation and technical notes

Product information, including the Management and Security Server (MSS) Add-Ons

Updated Cryptographic Modules in Host Access Management and Security Server