 |
|
New releases 2026 May
|
Welcome everyone.
We are pleased to inform you that Soffid new releases are now available and we have updated our download page with new versions of the Soffid components.
Please note that in Soffid 4, you will only find the Console and Syncserver on our enterprise download page. Starting with this version 4, Addons and Connectors must be downloaded directly from the internal marketplace on the Licence and plugins page. For more information, please consult our online documentation.
Below is the list of the components and changes made since the previous version was published. |
|
Soffid 4
|
|
Console 4.0.58 (from 54)
Searches were not working on the custom object pages, nor via the SCIM web service. |
The database update service from version 3 to version 4 was not working for the SQL Server database. |
The database update service from version 3 to version 4 failed when an agent did not have the Usage attribute defined. |
When the Console was configured as the service provider for Soffidâs identity provider, it generated unused SAML paths in the metadata.xml file. |
One of the indexes in the account table had an incorrect name (it was not being applied). |
Some indexes in the database were not being created because their names exceeded the permitted length. |
Users of the SCIM web service must now have the new âwebservice:userâ authorisation. New feature |
An error that had already been handled in the code, indicating that a host searched for by IP address could not be found, has been ignored in the log. |
Users who do not have the SOFFID_ADMIN role will no longer see the details of errors in the Console; instead, an identifier will be displayed so that administrators can look it up in the log. New feature |
The SCIM web service was displaying folders to which the SCIM user did not have access. |
New headers have been added to improve the security of web requests. |
The console log has been shortened when the syncserver is not active. |
|
|
Syncserver 4.0.35 (from 34)
New feature to clear the account password when the account is disabled and set the last password when the account is enabled again. New feature |
|
|
Federation addon 4.0.29 (from 24)
New feature to set a custom list of holder groups for each service provider. New feature |
When a user attempted to log in via ESSO and the login failed, if the âesso-failed-loginâ issue type was enabled, the issue would not be created and would not be logged. |
In the Identity Provider configuration, in the attribute âTLS PublicKeyâ, the âUpload PKCS12 fileâ button did not move forward to the PIN step. |
The PAM session would not start if the account belonged to the identity provider |
Hide certain OIDC attributes in an OpenID POST response, as they were not part of the standard. |
When a user was created in Soffid via self-provisioning by the Identity Provider, an error was thrown if the user had no additional attributes. |
When a user connected to the Identity Provider via ESSO, if the machine had an IP address that could not be resolved by the DNS resolver, an error occurred. |
For users who use ESSO and permission elevation, shared accounts are now cached on the Windows machine to speed up access and prevent service disruption when there is no internet connection. |
The Kerberos login has been modified because it sometimes fails. |
The service providers' impersonation functionality failed because a library update was missing. |
New headers have been added to improve the security of web requests. |
|
|
LDAP plugin 4.0.5 (from 4)
A maximum number of results has been added (it is a very high value). |
|
|
REST plugin 4.0.6 (from 4)
The âSimple tokenâ authentication option has been migrated to Soffid 4 |
New libraries have been added to properly support non-standard HTTP methods such as PATCH. |
|
|
SAP plugin 4.0.2 (from 1)
Changes to support to set the domain password when enabling an account. New feature |
|
|
Shell plugin 4.0.2 (from 1)
The âTestâ button in the âAttribute mappingsâ for this agent did not work in Soffid 4 |
Deleting files caused an infinite loop in Soffid 4, resulting in an error |
On the Exchange agent's âBasicsâ page, the âExchange versionâ attribute had a syntax error, and an error message was displayed when attempting to save. |
|
|
Windows plugin 6.0.14 (from 12)
During Kerberos authentication, the Active Directory agent could not find the account, even though it existed. |
When Active Directory had child domains, the agent could not find the accounts. |
The process for connecting to Active Directory via HTTP has been updated because it was sometimes causing errors. |
|
|
CSV plugin 4.0.0 (new)
Migration to Soffid 4 of the agent âCustomizable CSV fileâ. New feature |
|
|
PAM (only in Docker Hub) 1.4.90 (from 88)
The handling of clicks in HTTP browsing has been improved. |
Web sessions now operate using the TZ (GMT) time zone. |
The launch of Google Chrome-style HTTP sessions was failing because variables containing hyphens were not being handled correctly. |
During a PAM session, if the network connection was lost, the PAM session would terminate; the reconnection method has been improved to minimise this behaviour. |
The rendering engine has been switched to XWindows because it produces more reliable results and offers better performance. |
Security fix: the ORC pattern used for screen text reading did not have sufficiently restrictive permissions. |
When a PAM session was started in kiosk mode, some environments such as AKS did not allow the use of internal sandboxes; now, their use is automatically configured depending on whether or not they are permitted. |
In RDP-type PAM sessions, if a connection cannot be established, it will retry by forcing TLS authentication. |
In PAM sessions, if you switched applications very quickly after using the âGet clipboardâ option, an error would occur or an incorrect value would be retrieved. |
|
|
Soffid 3
|
|
Console 3.6.74 (from 73)
Security error: permission elevation in Windows connections allowed more permissions to be granted than the user actually had. |
Allow quick searches using file type attributes (searches are activated in the metadata page) or within the workflow searches. |
|
|
Syncserver 3.6.47 (from 46)
Error when attempting to configure a sync server that was already configured. |
When renaming a user account that was disabled, this change was not being synchronised. |
The service exposed for the ESSO module has been modified to sort devices by their identifier. |
|
|
Federation addon 3.6.90 (from 89)
When an external identity provider returned the âLevel of authorisationâ attribute, the attribute calculator did not record the correct value in Soffid. |
|
|
BPM addon 3.2.5 (from 4)
Some texts have been translated. |
|
|
LDAP plugin 2.8.6 (from 5)
The pagination configured in the LDAP agentâs âQuery page sizeâ attribute was not being applied. |
|
Thank you very much for your time, and see you next month!
Best regards,
The Soffid Team |
©Copyright Soffid 2025 |
 |
|