ipassconnect 3.65 Release Notes

Similar documents
ipassconnect 3.51 Release Notes

ipassconnect Beta v User's Guide

ipassconnect 3.55 Release Notes

ipassconnect 3.66 User's Guide

ipassconnect 3.65 User's Guide

ipassconnect v3.74 User's Guide

ipassconnect 3.60 User's Guide

Instructions for connecting to winthropsecure

Setting Up Cisco SSC. Introduction CHAPTER

ipass Open Mobile 2.0.x for Windows User Guide

Open Mobile for Windows Release Notes

Aventail Connect Client with Smart Tunneling

Using VMware View Client for Mac

PMS 138 C Moto Black spine width spine width 100% 100%

Release Notes - Barracuda NAC/VPN Client for Windows

Wireless Installation Instructions for Windows Vista

ipass Open Mobile f or W indow s Release Notes

Troubleshooting End User Wireless Networks

ipassconnect 2.4 Client User Guide

Configuring the Client Adapter through the Windows XP Operating System

Configuring 802.1X Authentication Client for Windows 8

Removing Norton Internet Security or Norton Personal Firewall 2004 from Windows XP/2000 after Add/Remove Programs does not work

Using EAP Authentication

AT&T Global Network Client User s Guide Version 9.7

Securewireless Windows 7 Setup Guide

ipass Rel eas e No te s for W indow s

Configuring the Client Adapter through the Windows XP Operating System

Protected EAP (PEAP) Application Note

IMC inode Intelligent Client v7.0 (E0106) Copyright (c) Hewlett-Packard Development Company, L.P. and its licensors.

AT&T Global Network Client User s Guide Version 9.7

Business Connect Secure Remote Access Service (SRAS) Customer Information Package

Internet Access: Wireless WVU.Encrypted Network Connecting a Windows 7 Device

ipassconnect 3.1 for Mac OS X

Removing your ipass Mobile Broadband USB adapter from your computer Using and storing your ipass Mobile Broadband USB adapter

Instructions for connecting to the FDIBA Wireless Network (Windows Vista)

ipassconnect for Symbian User s Guide

AT&T Global Network Client for Mac User s Guide Version 2.0.0

Windows 8.1 and Windows 10 a) Connect to wireless network Click on the wireless icon in taskbar. Select detnsw and click on Connect.

NCR. Wi-Fi Setup Assistant. User guide

Windows 7 Configuration for ORU Wireless Networks

SAP GUI 7.30 for Windows Computer

ipass Open Mobile 2.10.x for Android Quick Start Guide

Pre-installation Installing a microsd card Installing the USB 598 USB adapter and Watcher software

Cisco CTL Client setup

Secure Single Sign On with FingerTec OFIS

ipass Open Mobile 1.2 for Mac User Guide

Release Notes for Cisco Aironet a/b/g Client Adapters (CB21AG and PI21AG) for Windows Vista 1.1

Configuring Remote Access using the RDS Gateway

ipass Open Mobile for Mac User Guide

ipass Open Mobile 3.0.x for Android Quick Start Guide

KYOCERA Net Admin Installation Guide

FinalCode Viewer User Manual

Dell SonicWALL Aventail Connect Tunnel User s Guide

NT 0018 Instructions for Setting Up UoE_Secure (XP)

Windows Download & Installation

Telephony Toolbar Enterprise. User Guide

ipass Open Mobile 3.1.x for Android Quick Start Guide

Install Certificate on the Cisco Secure ACS Appliance for PEAP Clients

APP NOTES Onsight Rugged Smart Camera Wireless Network Configuration

AmbiCom WL11-SD Wireless LAN SD Card. User Manual

AT&T Global Network Client for Mac User s Guide Version 1.7.3

Your use of AirUWS-Lite is subject to the University s IT Acceptable Use of Resources Policy.

AT&T Global Network Client Administrator s Guide 9.8.1

Freshservice Discovery Probe User Guide

Installation Guide. Version 2600

Installation and Configuration User's Guide

simplifying... Wireless Access

Troubleshooting CHAPTER

Waters Empower 2 Service Pack G

Access Connections 5.1 for Windows Vista: User Guide

UbiLive Home Edition 2.0 User Guide

FinalCode Viewer User Manual

Symantec pcanywhere 12.5 SP4 Release Notes

PEAP under Unified Wireless Networks with ACS 5.1 and Windows 2003 Server

IT Quick Reference Guides Connecting to SU-Secure using Windows 8

BROWSER-BASED SUPPORT CONSOLE USER S GUIDE. 31 January 2017

User Manual PDUTracker

Dell EMC License Manager Version 1.5 User's Guide

PerTrac Analytical Platform. SQL Version Setup Guide

Junos Pulse 2.1 Release Notes

Air-conditioner Network System Centralized Controller AG-150A AG-150A-A GB-50ADA-J

Connect to eduroam WiFi

ipass Open Mobile Quick Start Guide for Android

LE840/LE850. Printer Setting Tool Manual Technical Reference

Fiery Command WorkStation 5.8 with Fiery Extended Applications 4.4

User Databases. ACS Internal Database CHAPTER

Cisco CTL Client Setup

Configuring EAP-FAST CHAPTER

Johns Hopkins

Cisco s AnyConnect VPN Client (version 2.4)

How to connect to Wi-Fi

User Guide. (Network Version) 2008 Certiport, Inc. certiprep 1

Centralized Controller Model: AG-150A

Instructions for connecting to the FDIBA Wireless Network. (Windows XP)

Business NETVIGATOR Roaming

Pre-installation Installing Watcher software Configuring Watcher to work with ipassconnect

Accella Toolbar. User Guide. Release 20.0

Client Configuration Guide

HP Insight Remote Support Advanced HP StorageWorks P4000 Storage System

Wireless LAN Profile Setup

Transcription:

ipassconnect 3.65 Release Notes Version 1.0, October 2008 Version History Version Date Notes 1.0 October 2008 General release availability document Introduction This document contains the latest information on ipassconnect 3.65, including: New Features New Features Technical Requirements Resolved issues Known issues PEAP-GTC Support ipassconnect 3.65 now supports PEAP-GTC protocol thereby ensuring secured private enterprise network connectivity. In the client, this is being established with the support of One Time Password (OTP) tokens. All these parameters are supported in: Windows XP (Professional) Service Pack 2 and Service Pack 3. Windows Vista (All versions) Service Pack 1 Note: RSA Next Token is not supported in Vista platform only. Testing involved validation on both Standard and Administrative user account privileges. The authentication parameters have not been validated for Windows Vista Home edition. While connecting to a PEAP-GTC enabled hotspot, the server challenges the user with a response window. The user interface of ipassconnect client has been enhanced with this Provide Response dialog. ipassconnect 3.65 Release Notes 2008 ipass Inc. 1

Here, the challenge message is sent by the server and user is required to enter the response. Based on the response, the user is re-authenticated for valid credentials. Note: Please contact ipass Technical Consultant or Sales Engineer for any clarifications with respect to the server message settings. EAP-TLS EAP-TLS protocol provides secure certificate-based authentication for connectivity to private enterprise networks. This is now supported on both Microsoft Windows XP and Vista Operating Systems. Note: Previous releases of ipassconnect supported EAP-TLS on Windows XP platform. ipassconnect 3.65 Release Notes 2008 ipass Inc. 2

Summary of 802.1X protocols supported in ipassconnect The following table contains list of 802.1X protocols supported by ipassconnect 3.65: 8021X Protocol Mode Live-Logon Win-Logon Windows XP Windows Vista Windows XP Windows Vista 8021X_MD5 Yes No Yes No 8021X_TLS Yes No Yes Yes 8021X_LEAP Yes No Yes No 8021X_PEAP_MSCHAPV2 Yes No Yes Yes 8021X_PEAP_TLS Yes No Yes No 8021X_PEAP_GTC Yes No Yes Yes 8021X_TTLS_MD5 Yes No Yes No 8021X_TTLS_PAP Yes No Yes No 8021X_TTLS_GTC Yes No Yes No 8021X_TTLS_CHAP Yes No Yes No 8021X_TTLS_MSCHAP Yes No Yes No 8021X_TTLS_MSCHAPV2 Yes No Yes No 8021X_FAST_MSCHAPV2 Yes No Yes No 8021X_FAST_TLS Yes No Yes No 8021X_FAST_GTC No No No No Token Authentication In order to ensure that the enterprise network access is secure, this release includes the feature of Token Authentication. Enterprise user s credentials would be authenticated with the use of tokens, thereby enhancing the overall security of the corporate network login process. Token Integration 1 : Corporate Networks supporting One Time Password (OTP) authentication, will now be able to use the Token Integration feature provided by ipassconnect 3.65. ipassconnect 3.65 allows for this authentication to be performed, using hard tokens (includes RSA token). The user interface of ipassconnect 3.65 client is enhanced to provide this desired functionality 1 Enabling Token Integrations requires ipass Professional Services assistance. Please contact your Account Manager for more information. ipassconnect 3.65 Release Notes 3

Enable Hard Token and Specify Authentication Parameters Perform the following steps to select Hard Token as the Token type. 1. On the Settings menu, select Token >Token Configuration. The Token Configuration dialog is displayed. 2. You can then select Hard Token as the token type by clicking the radio button. 3. In the Authentication Information section, specify the Username, choose the Domain and enter your password in the Passcode field. 4. Then click the OK button. Note: The Software Token feature will be available in a forthcoming release of ipassconnect. If the user tries connecting to a PEAP-GTC enabled hotspot with hard token enabled, then the server challenges the user for a response. Based on the response specified, the user is re-authenticated by the server. ipassconnect client user interface has been enhanced by introducing the Response dialog ipassconnect 3.65 Release Notes 4

The Username and Domain is displayed as non-editable fields on this window. New Splash Screen ipassconnect 3.65 introduces a new "Unified Mobility" corporate message on the splash screen. ipassconnect 3.65 Release Notes 5

Technical Requirements Minimum Hardware Requirements Pentium III processor or equivalent 512MB RAM for XP, and 1GB RAM for Windows Vista 500MB free disk space (the typical installer file size is currently around 29MB; a typical installation will occupy around 245MB) 16-bit color mode display Connectivity Device Requirements ipassconnect requires one or more connectivity devices installed, depending on your intended connection type: Wi-Fi - an NDIS v5.1-compliant 802.11b/g device and appropriate software drivers. Mobile Data - a supported Mobile Data device plus appropriate driver software. A complete list of supported Mobile Data cards can be found in the Mobile Data Configuration Guide, available from the ipass Portal. Ethernet adapter 56K v90/v92 modem GSM modem ISDN terminal adapter PHS 2.1 device Operating Systems Supported ipassconnect 3.65 is supported on the following platforms: Windows XP (Professional) Service Pack 2 and Service Pack 3. Windows Vista (All Editions) Service Pack1. Please note that the 802.1X authentication parameters have been validated for Windows Vista Ultimate, Enterprise and Business editions only. ipassconnect is supported only on 32-bit operating systems. ipassconnect is currently not certified for use on 64 bit machines. Microsoft Internet Explorer 6 or 7 must be installed. ipass strongly recommends installation of all Microsoft-recommended updates for your Operating System. ipassconnect 3.65 Release Notes 6

Languages ipassconnect 3.65 supports the following languages: English French Korean Chinese (Traditional) German Brazilian Portuguese Chinese (Simplified) Japanese Spanish Please note that ipassconnect 3.65 has been validated for English, German and French languages. Location of Log Files: Note the location of the ipassconnect log files; this conforms better to Microsoft guidelines and avoids problems associated with management of log files within the %PROGRAMFILES% folder structure: Windows XP C:\Documents and Settings\All Users\Application Data\iPass\log Windows Vista: C:\ProgramData\iPass\log In both cases, the log files are located in "hidden" folders and so, depending on the configuration of Windows Explorer, the user may not see them while browsing the file system. To view these folders, perform the following steps: 1. Open Windows Explorer->Tools->Folder Options->View (for windows Vista this step will be Windows Explorer-> Organize -> Folder and Search Options->View) 2. Select Show hidden files and folders option. Limitation The phonebook is not getting updated when the system date is modified to a future value. It happens due to the periodic update process which runs in the background, irrespective of whether the user exits the client or launches it. Note, the user is informed about this process by "Phonebook Update is already running" message. ipassconnect 3.65 Release Notes 7

Resolved Issues The following issues have been resolved in this release. The numbers in parentheses indicate relevant bug numbers where applicable. Installation Connectivity ipassconnect now informs users without administrative privileges that they cannot perform the product installation with relevant messages. In Windows XPP platform, if the user is logged in the normal mode, then the following message is displayed "Setup cannot continue because you do not have local administrative privileges". Similarly, in Windows Vista platform, if the user with incorrect administrator credentials tries installing ipassconnect then any one of the following messages are displayed. "Unable to logon Failure: unknown username or password". "Logon Failure: unknown username or password". Un-installation of ipassconnect now deletes all the registry entries. Previously, it was observed that un-installation of ipassconnect, did not delete ipassconnectengine entry from Microsoft Windows Services. With this fix, the required entry is being deleted as expected. While installing the client in standard mode, on Windows Vista, even with the right administrative credentials provided, application was displaying the error registration of Periodic Update failed. In this release, this issue has been resolved. If the user tried connecting to the same Wi-Fi network repetitively, and then cancelled, the application previously remained in an unresponsive state. This fix now allows the application to connect successfully to the same Wi-Fi network repetitively. On Windows Vista, users can now initiate a new Wi-Fi connection even if a prior Wi-Fi connection made through the OS is still active. Client does not display engine module error on trying to re-connect to a modem connection, after decreasing the system time (time zone related change). In the phonebook control, Sniffed Ethernet services no longer display as "identifying" indefinitely. The required status messages, with respect to the connection, are now being displayed as expected. ipassconnect now correctly detects and terminates the Internet connection, in response to the user unplugging the Ethernet cable. Post-connect actions are no longer displayed twice, for user defined connect actions, while ipassconnect 3.65 Release Notes 8

connecting to Personal Wi-Fi or WPA access points. Memory leakage issues related to ipassconnectengine.exe and ipassconnectgui.exe files which were observed in previous releases have been fixed in this version of ipassconnect. The ipass client has been configured to allow SSIDs of a maximum of 32 characters. Third Party Applications ipassconnect now successfully connects and logs on to the system when the Sygate Personal Firewall (v5.5) or McAfee Antivirus (v8.0i) services are stopped in Live Logon mode. Updates ipassconnect can now read the Proxy Auto Config files, defined locally in the system with Internet Explorer 7. The issue is resolved on installing the KB933566 security update for Internet Explorer 7 from Microsoft support site. For more information please visit any one of these URL s: http://support.microsoft.com/kb/933566 or http://www.microsoft.com/downloads/details.aspx?familyid=c2191703-8cbd-4959-9f84-e13f21173926&displaylang=en While performing software upgrade the client was not displaying appropriate error message when the user clicked on ipassconnect desktop icon or launched ipassconnect (98079) With this fix, the following warning message - Please do not re-launch ipassconnect while update is in progress is displayed The ipccheck software update utility now runs in the user context; this enables the utility to read the IE proxy settings required to upgrade the ipass client software. Erroneous warning messages are no longer displayed when the user does a Phonebook update on ipassconnect. ipassconnect 3.65 Release Notes 9

Alternate Credentials ipassconnect configured with Alternate Credentials works as expected, when the user tries to connect to the Internet by double-clicking on one of the available SSID 2 s. Enabling Alternate Credentials Policy does not prevent the ipassconnect client from using USER-DEFINED actions. ipassconnect client configured with Alternate Credentials uses different authentication parameters for authenticating inner and outer tunnels. Kindly note that the Alternate Credentials feature set has Limited Availability. Please contact your ipass Technical Consultant for any further information regarding the availability and applicability of this feature. User interface Localization The following button labels have been abbreviated in Portuguese (Brazilian) to accommodate them within the button boundary limits: Palavra-chave to Pal-chave Propriedades de Discagem to Prop. de Disc. Adicionar Marcacao to Adic. Marc. The dial string is now disabled, if the user selects Smart Redial checkbox in Dial-up Connection settings dialog. Changes to the Default Country option in the Login Information dialog are automatically updated in the ipassconnect main dialog. The default country name is now visible in the main dialog. The time counter option for PEAP-GTC enabled hotspots of ipassconnect is working as expected. The Home Broadband option is displayed properly on the ipassconnect main dialog for all the countries. This option was not working as expected, for the Korean version of Windows XP Service Pack2 and Service Pack3. 2 SSID: Service Set Identifier ipassconnect 3.65 Release Notes 10

Known Issues The following are the known issues in this release. The numbers in parentheses indicate relevant bug numbers where applicable. Connectivity In Provide Response dialog, currently it is observed that the client succeeds to connect even when the same One Time Password (OTP) token is entered twice. This occurs if the password is entered after 30 seconds of the dialog launch. In Provide Response dialog, if the user enters invalid password multiple times, ipassconnect fails to connect to the internet. However, the Connection status dialog pops up and the user is not able to close this dialog by clicking on Close [X] button. ipassconnect does not connect to an EAP-TLS enabled POP on Microsoft Vista, with machine certificates. 802.1X Ethernet POPs using EAP-TLS are not supported on Vista. In Live Logon mode ipassconnect currently fails to connect to PEAP-TLS enabled hotspot,, since it is not using the appropriate certificate credentials. It is observed that for PEAP-GTC enabled hotspots ipassconnect is displaying the message Connection established in the Connection status dialog multiple times. This happens, when the user connects to the internet and leaves the system idle for 30-40 minutes. For PEAP-GTC enabled hotspots in Windows Vista Connection Status messages are not in the correct sequence. However, all the other messages related to the Connection status are being displayed as expected. On specifying incorrect password in the Provide Response window of a PEAP-GTC enabled hotspot, the client is currently not displaying an error message indicating that the connection attempt has failed. However, Windows immediately displays the message Windows cannot connect you to SSID for this failed connection. If the client tries to connect to a PEAP-GTC enabled hotspot, wherein there is no server certificate installed in the Trusted root store and VerifyServerCert setting in config.ini file is set to yes, Server Certification failed message is not being displayed. Altering the focus of the tab, in the Connection Status window from Cancel button to Disconnect, and then hitting the Enter key on the keyboard, is resulting in - An invalid argument was encountered error message. ipassconnect 3.65 Release Notes 11

Application Updates GUI Support Note: The phonebook is not getting updated when the system date is modified to a future value. On trying to update manually, the message Phonebook update is already in progress is displayed but, the phonebook does not actually get updated. Software update is not happening if ipassconnect is configured with secure proxy settings. When ipassconnect client installed, does not have a connection to the phonebook update server (pb.ipass.com), and the user selects the option Update ipassconnect Software, the message The Software is up to date is being displayed incorrectly. The Provide Response Window does not timeout (as per the default setting) and return to the Response window dialog, while connecting to a PEAP-GTC enabled hotspot. Support services for Alternate Credentials or Token Integration is provided by the ipass Professional Services team. Support tickets received by the Customer Care team for these services will be escalated to the Professional Services team for further assistance and case ownership. E N D O F D O C U M E N T ipassconnect 3.65 Release Notes 12