Kantega SSO Enterprise 6.4.x release notes

We are pleased to announce Kantega SSO Enterprise 6.4.

Note that changes introduced in Kantega SSO Enterprise 6.3 will trigger an update of config warning in the Configuration status page upon install. It will convert your settings for Disable Traditional Login and Disable Basic Auth to a new format.

 

Read the update notes for important information about this release if you’re updating from major versions 5.x or 4.x, and see the full changelog below.

 

 

Compatible applications

In general, the latest version of Kantega SSO Enterprise is compatible with the oldest version that has not been ended of life. See Atlassian’s End-of-life (EOL) policy to get an overview of versions and EOL dates.

Application

Compatible from Server version

Compatible from Data Center version

Application

Compatible from Server version

Compatible from Data Center version

Bamboo

7.2.1

8.0.1

Bitbucket

7.6.0

7.6.0

Confluence

7.10.0

7.10.0

Jira

8.12.0

8.14.0

Changelog

Changes in 6.4.1

Dec 9, 2022 15:20 CET

Changed behavior for visits to login.jsp for automatic redirect

Improvements

  • saml/OIDC kerberos Changed behavior for direct visits to login.jsp page in JIra regarding automatic sending to identity provider

  • Improved UX on Force login page (changed name from Forced SSO)

Changes in 6.4.0

Dec 7, 2022 19:00 CET

Nested groups Azure user sync, improvements and security patch

Features

  • Azure api connector We have added nested groups to the Cloud user sync for the Azure AD API Connector. This means that when a group is member of another group, the members of a “child group” will also get memberships to the “parent” group.

Improvements

  • saml/OIDC kerberos Reset captcha counter on SSO login.

  • api tokens Improved UX on API token main settings page

  • kerberos Improved UX on Kerberos for JSM page

Security patches

  • Patch apache-commons text to 3.9.0 to patch CVE-2021-37533 information exposure