NetIQ SecureLogin 8.0 Service Pack 2 (SP2) Release Notes

December 2014

NetIQ SecureLogin 8.0 Service Pack 2 (SP2) includes new features, improves usability, and resolves several previous issues.

Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure that our products meet all your needs. You can post feedback in the NetIQ SecureLogin forum on NetIQ Communities, our online community that also includes product information, blogs, and links to helpful resources.

The documentation for this product and the latest Release Notes are available on the NetIQ Web site in HTML and PDF formats on a page that does not require you to log in. If you have suggestions for documentation improvements, click comment on this topic at the bottom of any page in the HTML version of the documentation posted at the NetIQ SecureLogin documentation page. To download this product, see the NetIQ SecureLogin Product Upgrade Web site.

NOTE:For the latest version of this Release Notes, see the NetIQ SecureLogin documentation page.

1.0 What’s New?

This release includes the following enhancements and fixed issues:

1.1 Wizard Enhancements

The Application Definition wizard includes the following enhancements:

Adding Application Definition for the Web Applications that Have the Same Parent Domain

If two or more web applications have the same parent domain, but use different credentials then, you can add application definition for each web application by using the Add Application option. When you add the application definition for the first web application, SecureLogin saves the application definition for that domain. So, when you need to add application definition for subsequent web applications that have the same parent domain, you must perform the following steps:

  1. Right-click SecureLogin icon on the system tray and then click Add Application.

  2. Drag the Choose icon to the application’s login window.

    A screen with the single sign-on options is displayed.

  3. Specify the URL in the Modify application URL field and then continue with the wizard settings.

    This creates another application definition with the same parent domain but different credentials. You can add two or more application definitions that share the same parent domain.

Single Sign-on to a Non .NET Application/ Windows application Using .NET Worker (UI Automation Worker)

You can now single sign-on to a non-.NET application/ Windows application by using the .NET worker. To enable single sign-on, you must set the Allow single sign-on to Windows applications using DotNet automation worker preference to Yes. After you set the preference to Yes, launch any non-.NET/ Windows application to view the list of single sign-on options. To configure application definition for the application select the Yes, I want to single sign enable the screen using the wizard. (.NET) option from the list of single sign-on options.

NOTE:For the changes to be effective, restart SecureLogin after making changes to any of the .NET preferences.

Single Sign-on Available for Multiple Events of a Windows Application

A new option, Events is added under the Matching criteria tab to configure application definition for all the required events. If a Windows application includes multiple events that results in credential prompts, you can configure the settings for each event from the Matching criteria tab.

To enable single sign-on for multiple events you must add the application definition for each window by using the Add Application option.

Controlling the Cancel Actions for Re-authentication

A new checkbox, Enable action when user cancels to enter their credentials is added under the Re-authentication tab of the Add Application Definition wizard. This enables you to select the cancel action only when it is required.

1.2 Support for Newer Versions of Mozilla Firefox Browser

In addition to Mozilla Firefox browser versions 19 to 28, this release supports Mozilla Firefox browser versions 29 to 34.

1.3 Software Fixes

This release of NetIQ SecureLogin includes the following enhancements and software fixes that resolve several previous issues:

iManager Does Not List SecureLogin Under the Roles and Tasks Pane

Issue: Installing SecureLogin plugin in an iManager server does not display the SecureLogin option in the Roles and Tasks pane. This issue is only seen when iManager is installed on an Open Enterprise Server.

Fix: With this release of NetIQ SecureLogin, when you install the SecureLogin plugin, iManager displays SecureLogin in the Roles and Tasks pane.

Enabling the Password Protection for SecureLogin in a Standalone Mode Results in Continuous Prompts for the SecureLogin Credentials

Issue: In a standalone mode, if you enable the Password protection to System Tray Icon preference, then SecureLogin displays continuous prompts for credentials and you cannot login to SecureLogin.

Fix: With this release, NetIQ SecureLogin does not include the preference for password protection when you install SecureLogin in a standalone mode.

SecureLogin Does Not Display the Citrix Published App option During Installation

Issue: During installation, SecureLogin does not display the Citrix Published App option in the Custom Setup page. So, you cannot create the Citrix published applications Channel in Citrix server.

Fix: With this release, the Citrix Published App option is included under Citrix on the Custom Setup page.

Single Sign-on is Not Possible for Novell Client

Issue: SecureLogin does not allow single sign-on to the Novell Client application.

Fix: With this release, you can single sign-on to Novell client by using the Add Application option.

iManager Displays an Error When Adding a Group Under Configured Groups

Issue: In iManager when you update the fields under Advanced Settings in the Manage SecureLogin SSO page and leave the Concurrent Schema fields empty, iManager displays an LDAP error. Hence, you cannot add a group.

Fix: With this release of NetIQ SecureLogin, the users can add a group in Configured Groups even when the Concurrent Schema fields are not specified.

Microsoft Management Console Displays an Error When Launching the Properties Page of a User Object

Issue: In Microsoft Management Console (MMC), when you launch the properties page of a user object SecureLogin displays the Cannot instantiate script broker error message. This error occurs even before you select SecureLogin Manager. This happens if SecureLogin is not running.

Fix: With this release of NetIQ SecureLogin, an appropriate error is displayed only when you launch SecureLogin manager and do not have SecureLogin running.

SecureLogin Does Not Display the Trusted Domains

Issue: If you install SecureLogin in an LDAP Credential Provider mode on a computer that is part of an Active Directory domain, SecureLogin does not display the trusted domains on the login screen.

Fix: With this release, SecureLogin displays the trusted domains to log in to the computer.

Fast User Switching Feature is Not Supported in Active Directory Application Mode (ADAM)

Issue: When SecureLogin is installed in the ADAM mode, SecureLogin does not support the fast user switching feature.

Fix: With this release, the fast user switching feature is supported for ADAM. All the action triggers for Active Directory mode are applicable for ADAM mode as well.

SecureLogin Does Not Recognize the Group Settings and Applications

Issue: SecureLogin does not display single sign-on options for the configured groups in eDirectory because It does not recognize the applications and policies that are saved in the configured group.

Fix: With this release, this issue is resolved and SecureLogin displays the single sign-on options.

SLManager Displays an Error When Importing the .esx File

Issue: You can export the .esx file by using SLManager, but you cannot import the .esx file.

Fix: With this release, you can import and export the .esx file by using SLManager.

2.0 System Requirements

For more information about hardware requirements, supported operating systems, and browsers, see the Quick Start Guide.

3.0 Installing or Upgrading to SecureLogin 8.0 SP2

You can either upgrade from the previous versions of SecureLogin or perform a new installation. For more information on upgrading from previous release, see Upgrading SecureLogin. For more information on installing SecureLogin, see NetIQ SecureLogin Installation Guide.

4.0 Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

4.1 Cannot Single Sign-on to .NET Applications

Issue: You cannot single sign-on to a .NET application even if you configure the application definition. This issue occurs if the preference for Windows worker is set to No. (Bug 900297)

Workaround: To workaround this issue perform the following steps:

  1. Right click the SecureLogin icon from the system tray and select Manage Logins.

  2. Select Preferences from the left pane.

  3. Set the value to Yes for the following Windows preferences:

    • Start the Windows 32bit (WinSSO32) monitor/automation worker.

    • Start the Windows 64bit (WinSSO64) monitor/automation worker.

  4. Restart SecureLogin.

4.2 SecureLogin Displays an Error When Logging in to Novell Client

Issue: If you install SecureLogin in eDirectory mode and attempt logging in to Novell Client, SecureLogin displays a NICI error. This happens only when you upgrade from NetIQ SecureLogin 8.0 SP1 to this release and if during the SecureLogin setup process, you select NetIQ eDirectory with LDAP instead of NetIQ eDirectory with Novell Client.(Bug 906349)

Workaround: To workaround this issue perform the following steps:

  1. Log in to the computer by using the Computer Only Logon option.

  2. Click Control Panel>Programs>Programs and features.

    The Uninstall or change a program page is displayed.

  3. Right-click NICI U.S./Worldwide 2.77.2.0 (x64) and then click Repair.

  4. Restart the computer and login to Novell Client.

4.3 Emergency Access Does Not Work After Upgrading to SecureLogin 8.0 SP2

Issue: If you are working on SecureLogin 8.0 SP1 or earlier versions and you are upgrading to this release, the Emergency Access feature does not work. This happens because Client Login Extention (CLE) 3.7.3 or earlier is not supported on SecureLogin 8.0 SP2. (Bug 903769)

Workaround: To use the Emergency Access feature you must upgrade the Client Login Extension version to CLE 3.8.

4.4 Cannot Single Sign-on After Upgrading to SecureLogin 8.0 SP2

Issue: When you upgrade from SecureLogin 8.0.1 or earlier to this release, it does not display the options for single sign-on. This happens if the datastore version that is set for a container does not match with the datastore set for the user in that container. (Bug 903068)

Workaround: Perform the following steps to workaround this issue:

  1. Delete the user datastore version and close SecureLogin.

    The datastore version is updated to the version that is set for the container.

  2. Clear the cache and start SecureLogin.

4.5 When Launching a Web Application on an Internet Explorer 11 Browser, SecureLogin Does Not Display the Single Sign-on option

Issue: In Internet Explorer 11, if the Enable Enhanced Protected Mode option is enabled in the settings and if you are using the Windows 8.1 Operating System, the single sign-on feature does not work.(Bug 908767)

Workaround: From the Internet Explorer 11 settings, disable the Enable Enhanced Protected Mode option.

4.6 Selecting .NET Single Sign-on Option Displays an Error Message

Issue: When you select the Yes, I want to single sign enable the screen using the wizard. (.NET) option, SecureLogin crashes and it displays the NetIQ SecureLogin Stopped Working error message. This issue occurs randomly when the computer is not updated with all the Windows operating system updates.(Bug 910453)

Workaround: To workaround this issue install all the Windows updates.

4.7 The Edit Wizard Option Does Not Work When an Application Definition is Configured with .NET Worker

Issue: When you edit the Application Definition for a Windows application by using Edit Wizard, the Application Definition wizard does not recognize Identify Screen and displays an error. Hence, you cannot edit the application definition by using the wizard. This issue occurs when the application definition is added by using the .NET worker.(Bug 907097)

Workaround: To workaround this issue, add the application definition again and delete the previous application definition for that application.

4.8 SecureLogin Does Not Display the Appropriate Single Sign-on option

Issue: When you select Add Application for an existing Windows application, SecureLogin does not display the appropriate single sign-on options. Instead, it displays the single sign-on options for a new application definition. This issue occurs for a Windows application when the application definition is created by using the .NET single sign-on option.(Bug 907101)

Workaround: To workaround this issue select the single sign-on option, Yes, I want to single sign enable the screen using the wizard. You can delete the existing application definition from the Application Definition wizard and create a new application definition for that application.

4.9 Changing the Auditing Preferences in iManager Does Not Update the Changes in SLManager

Issue: In iManager, when you change the Auditing Preferences for a user, the changes are not replicated on SLManager and SecureLogin. This issue occurs because the preference change in iManager does not synchronize with SLManager and SecureLogin.(Bug 900416)

Workaround: To workaround this issue, manually update SLManager with the changes for the Auditing preferences.

4.10 Cannot Log in to Parent Domain Through LDAP Credential Provider

Issue: When you login through LDAP credential Provider to a computer that is in a child domain, SecureLogin does not display the trusted parent domain. This issue occurs only on Windows 8.1. (Bug 900413)

Workaround: To view the trusted parent domain, an administrator, who is a user in both child and parent domain, must login to the child domain for the first instance. After the administrator logs in to child domain and logs out, SecureLogin displays the trusted parent and child domains for the later instances.

5.0 Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information website.

For general corporate and product information, see the NetIQ Corporate website.

For interactive conversations with your peers and NetIQ experts, become an active member of our community. The NetIQ online community provides product information, useful links to helpful resources, blogs, and social media channels.