Version 2.22.10
Summary
This release delivers significant enhancements across federation protocols, claim transforms, authentication token handling, logging, and the Control Client user experience.
The headline feature is the addition of WS-Federation support for both authentication methods and application registrations, including interoperability with AD FS and Microsoft Entra ID. The release also improves claim transform usability and diagnostics, adds support for issuing refresh tokens from authentication methods to applications, and introduces more detailed Home Realm Discovery (HRD) trace logging.
Additional improvements ensure that the Control Client test applications remain reliable for long-term use, while NuGet package updates address known vulnerabilities and strengthen overall platform security.
New Features and Improvements
WS-Federation Support
- Added WS-Federation support for authentication methods and application registrations.
- Supports metadata import and export, SAML 1.1 and SAML 2.0 tokens, sign-in and sign-out flows, token encryption, and claims mapping.
- Compatible with AD FS and Microsoft Entra ID.
Claim Transform Enhancements
- Claim transforms now support querying users by User ID using the
sublookup claim. - Updated descriptions and help text throughout the claim transform UI.
- Added colours, summaries, and default-expanded sections to improve usability and troubleshooting.
Authentication and Token Improvements
- Added support for exposing a refresh token from an authentication method in a
refresh_tokenclaim. - The
refresh_tokenclaim can now be issued alongside anaccess_tokenclaim to applications.
Home Realm Discovery (HRD)
- Added more detailed Home Realm Discovery trace logging to simplify troubleshooting.
SAML 2.0 Improvements
- New SAML 2.0 application configurations now include phone and email claims by default.
Control Client Improvements
- Improved the Control Client test applications to ensure reliable operation and compatibility over the long term.
Security and Dependency Updates
- Updated NuGet packages to address known vulnerabilities and improve overall platform security.
User Experience Improvements
- Updated email templates to include more detailed and meaningful text.
Bugs Resolved
SAML 2.0 Certificate Management
- Fixed an issue where removing a SAML 2.0 certificate did not immediately update the UI.
- The same certificate can now be re-added immediately after removal, either by file selection or drag-and-drop.
SAML 2.0 NameID Handling
- Resolved an issue where an external SAML 2.0 NameID could be overridden by a claim transform, resulting in incorrect logout requests.
- Fixed an issue where SAML 2.0 did not correctly select an alternative identifier claim when the NameIdentifier claim was unavailable. FoxIDs now correctly falls back to UPN, Email, or Name.
- www.foxids.com/foxids:2.22.10 Eingeschränkt
- www.foxids.com/foxidscontrol:2.22.10 Eingeschränkt
- FoxIDs-2.22.10-linux-x64.tar.gz Eingeschränkt (168,5 MB)
- FoxIDs-2.22.10-win-x64.zip Eingeschränkt (189,8 MB)
- FoxIDs.DirectoryConnector.ActiveDirectory-2.22.10-win-x64.zip (47,7 MB)
- FoxIDs.CosmosDbToPostgreSQLMigrator-2.22.10-linux-x64.tar.gz Eingeschränkt (59,1 MB)
- FoxIDs.CosmosDbToPostgreSQLMigrator-2.22.10-win-x64.zip Eingeschränkt (58,2 MB)
- FoxIDs.MasterSeedTool-2.22.10-linux-x64.tar.gz Eingeschränkt (59,1 MB)
- FoxIDs.MasterSeedTool-2.22.10-win-x64.zip Eingeschränkt (58,2 MB)
- FoxIDs.SeedTool-2.22.10-linux-x64.tar.gz Eingeschränkt (59,1 MB)
- FoxIDs.SeedTool-2.22.10-win-x64.zip Eingeschränkt (58,2 MB)