Version 2022.1.7.0 (February 15th 2022)

Version 2022.1.7.0 (February 15th 2022)

avatar

Database upgrade required

RDM and Devolutions Server Console 2022.1 are required to use this version

NEW FEATURES

  • BREAKING CHANGE .NET Framework 4.8 is now required
  • BREAKING CHANGE Devolutions Gateway now requires a license (unlicensed usage will show a warning)
  • BREAKING CHANGE HTTPS is strongly recommended, application encryption level will be removed
  • BREAKING CHANGE Initial OAuth support. Windows authentication is no longer supported with 2FA
  • BREAKING CHANGE When binding with an Active Directory Domain for authentication, a Domain Functional Level of at least 2012r2 is now enforced rather than simply listed in our requirements.
  • Core - Email notifications for temporary access
  • Core - Initial OAuth support
  • Core - Support for DVLS PAM entry
  • Gateway - License integration
  • Gateway - SSH connection support
  • PAM - Azure AD Provider
  • PAM - Local Windows Accounts Provider
  • PAM - PAM Dashboard in Remote Desktop Manager


IMPROVEMENTS

  • BREAKING CHANGE DWL has to be logged in separately
  • Core - "DNS Name" has been replaced by "Access URI"
  • Core - Added "Privileged Account" on the folder credential option
  • Core - Added a group filter in import AD Users dialog
  • Core - Added server and client IP address in syslog messages
  • Core - Added UserInfoHistory in the cleanup logs feature
  • Core - Don't accept domain with functional level too low
  • Core - Fixed an issue where user can't be imported if a domain was down
  • Core - Improved multi vault search performance
  • Core - Search results in passwords list
  • Core - Sort TAGS in the dashboard and tag selection dialog
  • Core - Support for new RDM file format (v2) to import
  • Gateway - Added option "Force using IP address for RDP connections"
  • Gateway - Added support for alternate hosts
  • Gateway - Support inherited Gateway
  • PAM - Added a password template at provider level
  • PAM - Added scan delta summary
  • PAM - Improved error message on synchronization status
  • PAM - Move all PAM Account at root level in a team folder
  • Web - Added a few SSH properties in Edit view
  • Web - Added a search bar in 'Privileged account credential' type selection
  • Web - Added a warning on entry deletion if a shortcut exist
  • Web - Added 'Assign All Vaults' button in users and user groups dialogs
  • Web - Added icon in PAM UI to help color blind people
  • Web - Added shortcut icon in vault tree
  • Web - Only admin user can submit a support ticket
  • Web - Rebranded Devolutions Authenticator to Devolutions Workspace
  • Web - Sort approvers in PAM checkout dialog
  • Web - Support DVLS PAM entry in web interface


FIXES

  • Core - DVLS Free doesn't support PAM
  • Core - Fixed an issue to display the right number of users in a license
  • Core - Fixed an issue where "Automatic User Creation" parameter was not saved
  • Core - Fixed an issue where "Prompt for comment" was not displayed with "Copy API key"
  • Core - Fixed an issue where a user without the view password permission could view the password
  • Core - Fixed an issue where changing the time for O365 caching was not saved
  • Core - Fixed an issue where custom user groups can not be created without custom authentication activated
  • Core - Fixed an issue where documentation view was wrong
  • Core - Fixed an issue where Duo returns invalid 2FA with a domain user
  • Core - Fixed an issue where entries with temporary access were not sent back to DWL
  • Core - Fixed an issue where export vault was not logged
  • Core - Fixed an issue where password in passwords list could be lost
  • Core - Fixed an issue where passwords in private vault were not available in web interface
  • Core - Fixed an issue where RDM connection to DVLS failed
  • Core - Fixed an issue where RDM was disconnected from DVLS
  • Core - Fixed an issue where some folders in vaults were not available in RDM
  • Core - Fixed an issue where ticket number was not saved in activity logs
  • Core - Fixed an issue where user was not able to login
  • Core - Fixed issue where date format was wrong
  • Core - Fixed Syslog message format to set the hostname with DVLS IP
  • Core - Include Local Account entries in password rotation reports
  • PAM - Fixed an issue where PAM checkouts failed with a non-admin user
  • Web - Fixed an issue where view attachment with pdf extension failed
  • Web - Fixed translation strings
  • Web - Several UI fixes
  • Web - Several UI fixes


Érica Poirier

All Comments (15)

avatar

KNOWN ISSUE FOR USERS OF Windows 2012R2, PAIRED WITH AD AUTHENTICATION

The server erroneously reports that the DOMAIN FUNCTIONAL LEVEL is to low for binding our authentication, this will be fixed quickly.

Maurice

avatar

Is there somewhere where we can get more detail on some of these changes? I'm particularly interested in some of the gateway changes.

avatar

we’re preparing a webinar, we’ll have a few videos by our amazing Yann, and Stephanie is writing up stuff for blogs

The IP vs host name was to force NTLM i believe (or prevent Kerberos)

The alternate host feature is to be able to use the same entry using both a principal AND alternate name, it’s useful especially for mobile workers that can use one name from within the internal network, and fallback to the alternate name when outside the network

just let me know what else you’d like to know

Maurice

avatar

Yep, support for alternate hosts is a terrific enhancement. Your example is a good one (internal vs external), although as an extension to this, it would be great if alternate hosts could be set to use remote desktop gateway which isn't required for internal connections.

What's the inherited gateway option? We've had our Gateway set up on a folder level with all connections underneath inheriting since gateway was released and it's worked brilliantly. The only bug there is the "connect if unable to ping/scan" option doesn't work and just acts as though it's set to "always connect"

avatar

Where can I find more information about the PAM feature?

Thank you.

avatar
KNOWN ISSUE FOR USERS OF Windows 2012R2, PAIRED WITH AD AUTHENTICATION

The server erroneously reports that the DOMAIN FUNCTIONAL LEVEL is to low for binding our authentication, this will be fixed quickly.



Hi, we just updated our Domain Function Level to 2016, but Windows Authentication is still not working, are there any other adjustments that we have to make?

sebastian

avatar

@sjames

Indeed, we could a have blog just on this feature, it allows the admins of the solution to truly keep a single entry that corresponds to a single endpoint, and RDM can do its magic and :

  1. hide the complexity
  2. Improve productivity
  3. elevate security


One sets up the gateway at the top of their hierarchy and sets desired entries to use the inherited settings. You can even modify your basic default settings to specify that option for all new entries.

One of the changes that the team felt was necessary was to trim down that dropdown when one chooses a gateway. Some choices were truly exclusive to VPNs and it caused confusion. The original "inherited' model was missing handling of the alternate host I believe.

Maurice

avatar

@sebastianmair, we do have a few complaints in that area, its best to open a case at service@devolutions.net

Maurice

avatar

@sjames,

Just to add a bit more information, here is the connection options that we support for Devolutions Gateway
forum image

So now, we support "Connect if unable to ping/port scan" and it should behave as expected. The connection will be a direct connection if you are locally and the Devolutions Gateway will be used if you are remote.

Don't hesitate if you have other questions

Best regards,

François Dubois

avatar

@jgamarra

  • PAM - Azure AD Provider
    • Discover and manage Privileged Accounts (PA) in AzureAD (aka Office365). You can therefore have dedicated accounts that are task oriented, while also controlling access and having full visibility about their usage. (we feel that Azure's PIM is not the best solution for managing our own infrastructure, but I wont get into that for now)
  • PAM - Local Windows Accounts Provider
    • Control LOCAL accounts for non-domain joined machines. Some of our customers have critical servers and/or public facing ones that are NOT joined to a domain. You can therefore create PAs and have the passwords totally managed by our solution.
  • PAM - PAM Dashboard in Remote Desktop Manager
    • Long overdue, our own PAM was less exposed in RDM then others on the market. That new dashboard allows you to do most of your operations directly from within RDM. We intend to push this much further in the coming release.


That's it for the major additions, the rest are little improvements.

Maurice

avatar

@all, our events page will be updated today, but our webinar for this release of DVLS is as follows

Devolutions Server 2022 Roadmap & New and Improved Features
Get tickets to Devolutions Server 2022 Roadmap & New and Improved Features, taking place 16/03/2022 to 16/03/2022.

?c=1&o1=ro&url=https%3A%2F%2Fquiin.s3.us-east-1.amazonaws.com%2Fevents%2Fpictures%2F000%2F329%2F207%2Foriginal%2Fhopin-dps-roadmap

Maurice

avatar
@sjames,

Just to add a bit more information, here is the connection options that we support for Devolutions Gateway
forum image

So now, we support "Connect if unable to ping/port scan" and it should behave as expected. The connection will be a direct connection if you are locally and the Devolutions Gateway will be used if you are remote.

Don't hesitate if you have other questions

Best regards,


Thanks @François - we did the upgrade last night and have implemented the 'connect if unable to ping/port scan' option. This works brilliantly and has resulted in a significant performance boost for us as now only some connections need to route across the gateway instead of all of them.

Appreciate this feature a lot!

avatar

Hi Devolutions

Is there more Information how to use this improvement:

  • Core - Initial OAuth support


I want to use AzureAD with OAuth to authenticate our users but can't find any documentation.

Kind regards

avatar

Hello,

The procedure is still the same as before (for now) to enable the authentication to O365 in DVLS: https://kb.devolutions.net/dps_azure_configuration_guide_365.html

The OAuth part is managed by DVLS and RDM, no additional configuration is needed on your end, except configuring the Access URI during the installation/upgrade to 2022.1: https://kb.devolutions.net/kb_dvls_accessuri.html

Best regards,

Richard Boisvert

avatar

Hello,

A new version 2022.3.4.0 has been released last week. (https://forum.devolutions.net/topics/38326/version-2022340-november-10th-2022) What updates are you waiting for ?

Best regards,

François Dubois