Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

What's new in this release

...

  • Enhanced identity management framework and OOTB support for identity governance scenarios:
    The identity management framework in WSO2 Identity Server 5.3.0 has been re-designed to add new scenarios and also added strong list of OOTB (out-of-the-box) support for key identity management use cases. Additionally, new restful interfaces to connect with account registration and recovery flows were also introduced.

  • Login session monitoring and termination:
    WSO2 IS now supports monitoring user sessions and authentication activities via alerts, and manual termination of user sessions for better security. For more information, see Terminating User Sessions

  • Rule-based provisioning:
    WSO2 IS 5.3.0 has the ability to adopt provision flow based rules that can be based on event(user, IdP, SP) information as well as environment(time, region) factors. For more information, see Rule Based Provisioning.

  • Engaging access control policies in the authentication flow:
    The WSO2 IS 5.3.0 allows you to configure and enforce XACML policies for access control in the authentication flow. For more information, see Configuring Access Control Policy for a Service Provider

  • Prompt for missing predefined attributes in the authentication flow:
    The user will be prompted for the missing attributes or claim values if a mandatory claim is missing at the point of login. For more information, see Configuring Claims for a Service Provider.
  • Integrated Windows Authentication for Linux and External Kerberos:
    In WSO2 IS 5.3.0, you can achieve Integrated Windows Authentication (IWA) with external Kerberos/NTLM Servers, with a WSO2 IS that is deployed on a Linux server. For more information, see Configuring IWA on Linux.
  • OAuth 2.0/Open ID Connect Enhancements: 
  • REST profile of XACML:
    WSO2 IS now adopts REST profile for XACML and JSON Profile of XACML specifications, which breaks the barrier of integrating with the WSO2 IS XACML engine (PDP) from restful applications (PEPs).  For more information, see Entitlement with REST APIs.

     

  • SAML 2.0 Enhancements:

  • Security Analytics:
    WSO2 IS now provides security alerts that give insight into current login sessions and notifies in real time if there are any suspicious login activities and abnormal sessions. For more information, see Managing Alerts.

...

Updated or newly introduced featuresThe date of the update
Updated Creating Users Using the Ask Password Option feature. This fix allows you to add special characters such as !#$%&'*+-=?^_  when updating a user's email address.Effective from the 13th of June 2017
Updated User Account Suspension feature.Effective from 13th of October 2017
Support to configure SAML 2.0 Web SSO to send query parameters that can be dynamically updated with each SAML request.Effective from 15th of January 2018
Updated adding an application certificate to a service provider. The WUM update provides an easier method of managing application certificates.Effective from 20th of January 2018
Enabling OAuth token encryption to encrypt OAuth2 access tokens, refresh tokens, consumer secrets, and authorization codes. Effective from 15th of February 2018
Hosting Authentication endpoint on a different server for the purpose of having custom theming and branding.Effective from 11th of May 2018

Support to do the following with regard to authentication handlers:

  • Disable an authentication handler at the system level.

  • Enforce required authentication mechanisms per resource.

  • Change the priority order of any authentication handler at the system level.
Effective from 14th of May 2018

Support to configure signing and digest algorithms for passive sts ws-federation single sign-on

Effective from the 8th of January 2019
Tip

This release is a WUM-only release. This means that there are no manual patches and any further fixes or latest updates for this release can be updated through the WSO2 Update Manager (WUM). For more information, see Getting Started with WUM.

...