Delinea Documentation - Secret Server - 11.3.0

Secret Server: 11.3.000001 Release Notes (GA)

Release Dates and Notes

Early Access: October 4, 2022 (On-Premises)

General Availability: October 25, 2022 (On-Premises)

Note: The following release notes apply to both EA (11.3.000000) and GA (11.3.000001). The bug fixes that only apply to GA are prefaced with GA only.

Note: The protocol handler version for this release is RDPWin_6_0_3_23.

New Features

Additional Custom Logo Variations

You can now upload more custom interface logos. This includes an optional larger logo for the login page. Each logo includes alternative images for light and dark modes. This results in six logo variations.

The settings are available in the configuration preview. Enable the configuration preview and then locate the new settings in the Administration > Configuration > General > User Interface area.

Advanced Session Recording Agent

The advanced session recording agent (ASRA) MSI is now self-contained and based on .NET Core, which does not need a .NET SDK installed; however, installing an ASRA from the advanced session recording page using the installer still requires that the .NET Framework redistributable components are installed.

To install or deploy the agent without the framework, follow the customization steps here: Task 3: Customizing the Installer

Configurable Global Banner

You can now configure a multipurpose global banner for all users. You can use it for maintenance, security, or policy notifications. You can set the severity level, text, a hyperlink, and an in-theme color, which is determined by the severity.

The settings are available in the configuration preview. Enable the configuration preview and then locate the new settings in the Administration > Configuration > General > User Interface area.

Classic User Interface

We enhanced the new UI experience, and all new features only appear in that UI. The classic UI is deprecated and no longer maintained. For this release, the classic UI is disabled by default but temporarily still available. You can enable it at Administration > Configuration > General > User Interface settings. As of the next minor release, the classic UI will be permanently removed.

Disaster Recovery Synchronization Improvements

We improved the disaster recovery (DR) feature to synchronize additional items, including:

This enables replication of the permissions structure to the replica server, providing a readily available standby with permissions in place.

Event Pipeline Enhancements to Sending Emails

Users can now select an inbox email template in the event-pipeline send-email tasks. This gives the user access to event-pipeline and inbox tokens within the predefined email template.

Once the event pipeline is triggered, it sends an inbox notification and processes any inbox rules. The inbox rules send an email to the task recipients.

Protocol Handler Process Tracking

We renamed launcher settings from "Record Multiple Windows" and "Record Additional Processes" to "Track Multiple Windows" and "Track Additional Processes." These are now both used for process tracking, regardless of whether recording is enabled. This improves session termination, either triggered or automatic, applying to child and specified processes, per the launcher settings.

Refreshed Administration Page

We updated the administration page with a new categorized view where users can pin commonly used items to a list. To pin an item on the new administration page, hover over or focus it, revealing a pin icon. Click the icon to add the item for quick access.

Session Monitoring Page

We converted the session monitoring search page to the new UI. The functionality remains essentially the same; however, we removed role restrictions on filters. We also optimized both the front- and back-ends.

SFTP Tunneling

Added an SFTP tunnel setting to the SSH proxied process launcher for use with SFTP client custom launchers. This was tested with FileZilla and WinSCP.

SSH Cipher Suite Configuration

We added a configuration page that sets the Secret Server SSH ciphers used when making SSH connections for various tasks, such as heartbeat, password changing and discovery. This does not apply to SSH password changers using the "Legacy" runner type. This is at Administration > SSH Cipher Suite Configuration.

With this feature, users can set availability and application order for key exchange, MAC, and encryption algorithms via an easy-to-use list. To use the list, go to the configuration page for the site, and enable the SSH cipher suite setting.

Enhancements

Alerts, Auditing, and Logs

Authentication, Login, and Directory Services

Backup, DR, and HA

Dashboard and UI

Encryption, Passwords, and Certificates

General

Heartbeats

Launchers and Protocol Handlers

Localization

Remote Access and Proxies

Reports

Secrets, Policies, and Templates

Session Recording

Teams

Users, Groups, Roles, and Permissions

Web Password Filler

Bugs

Access Requests, Checkout, Secret Workflows, and Doublelocks

Alerts, Auditing, and Logs

API and Scripting

Authentication, Login, and Directory Services

Background Services

Backup, DR, and HA

Bulk Operations

Cloud

Dashboard and UI

Discovery

Distributed Engines and Site Connectors

Encryption, Passwords, and Certificates

Event Subscriptions and Pipelines

Folders

General

Heartbeats

Import and Export

Launchers and Protocol Handlers

Licensing and Activation

Localization

Remote Access and Proxies

Remote Password Changing

Reports

Secrets, Policies, and Templates

Session Recording and Monitoring

Ticketing System

Users, Groups, Roles, and Permissions

Web Password Filler

Future and Recent Deprecations

Note: This section describes planned future deprecation of feature or platform support in Secret Server.