Versione 2.23.3
This release introduces enhanced user sign-up controls, expanded SAML 2.0 encryption configuration, and updated cryptographic and database components.
Administrators can now restrict self-service user registration to specific email domains, providing greater control over who can create accounts. SAML 2.0 applications now support configurable assertion and key encryption algorithms, improving interoperability with a wider range of identity providers and service providers.
The release also improves configuration consistency by automatically updating authentication method references, cleans up related Environment Links when configurations are deleted, strengthens certificate resource handling, updates the certificate-to-JWK conversion to use the shared ECDSA implementation in ITfoxtec.Identity and includes the latest PgKeyValueDB driver.
New Features and Improvements
User Sign-up Restrictions
- Added support for restricting user sign-up in Login authentication methods to specific email domains.
- Administrators can configure a list of allowed domains for Create User.
- When domain restrictions are enabled, the sign-up flow requires the user identifier to be an email address.
Configurable SAML 2.0 Response Encryption
Added support for configurable response encryption algorithms for SAML 2.0 applications.
- Authentication response encryption now supports separate:
EncryptionAlgorithmKeyEncryptionAlgorithm
- This enables FoxIDs to interoperate with SAML implementations that require explicit configuration of both assertion data encryption and key encryption algorithms.
Supported algorithms include:
- AES-CBC
- AES-GCM
- RSA-OAEP
- XML Encryption 1.1 RSA-OAEP
Existing configurations remain fully compatible by continuing to use the current defaults:
- AES-256-CBC for assertion data encryption
- RSA-OAEP for key encryption
Configuration Improvements
When an authentication method is renamed, the new name is automatically updated in claim transforms, claim transform tasks, and applications that reference it in Allowed Authentication Methods.
Environment Link cleanup
- Related Environment Links are removed automatically.
- Deleting an environment removes all associated Environment Link connections.
- Deleting either the application side or the authentication method side of an Environment Link also removes the corresponding linked configuration.
Cryptography Improvements
- Updated certificate-to-JWK conversion to use the shared ECDSA implementation provided by ITfoxtec.Identity.
- Improved certificate resource handling by consistently disposing temporary certificate instances after use, reducing the risk of native handle and resource leaks during certificate validation, metadata generation, and token processing.
Dependency Updates
- Updated the PostgreSQL driver PgKeyValueDB to version 3.4.4.
Bugs Resolved
Create User
- Fixed an issue where the phone country code could be used during user creation when a phone number was not required in the Create User UI.
- www.foxids.com/foxids:2.23.3 Limitato
- www.foxids.com/foxidscontrol:2.23.3 Limitato
- FoxIDs-2.23.3-linux-x64.tar.gz Limitato (168,5 MB)
- FoxIDs-2.23.3-win-x64.zip Limitato (190,0 MB)
- FoxIDs.DirectoryConnector.ActiveDirectory-2.23.3-win-x64.zip (49,2 MB)
- FoxIDs.CosmosDbToPostgreSQLMigrator-2.23.3-linux-x64.tar.gz Limitato (59,1 MB)
- FoxIDs.CosmosDbToPostgreSQLMigrator-2.23.3-win-x64.zip Limitato (58,2 MB)
- FoxIDs.MasterSeedTool-2.23.3-linux-x64.tar.gz Limitato (59,1 MB)
- FoxIDs.MasterSeedTool-2.23.3-win-x64.zip Limitato (58,2 MB)
- FoxIDs.SeedTool-2.23.3-linux-x64.tar.gz Limitato (59,1 MB)
- FoxIDs.SeedTool-2.23.3-win-x64.zip Limitato (58,2 MB)