chap-whats-new.xml revision 6ce3dabbba7e4e63677d017240c4bbb31d083469
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<?xml version="1.0" encoding="UTF-8"?>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!--
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! CCPL HEADER START
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster !
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! This work is licensed under the Creative Commons
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! Attribution-NonCommercial-NoDerivs 3.0 Unported License.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! To view a copy of this license, visit
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! http://creativecommons.org/licenses/by-nc-nd/3.0/
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! or send a letter to Creative Commons, 444 Castro Street,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! Suite 900, Mountain View, California, 94041, USA.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster !
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! You can also obtain a copy of the license at
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! src/main/resources/legal-notices/CC-BY-NC-ND.txt.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! See the License for the specific language governing permissions
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! and limitations under the License.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster !
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! If applicable, add the following below this CCPL HEADER, with the fields
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! enclosed by brackets "[]" replaced with your own identifying information:
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! Portions Copyright [yyyy] [name of copyright owner]
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster !
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! CCPL HEADER END
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster !
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ! Copyright 2011-2014 ForgeRock, Inc.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster !
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster-->
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<chapter xml:id='chap-whats-new'
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington xmlns='http://docbook.org/ns/docbook' version='5.0' xml:lang='en'
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xmlns:xsi='http://www.w3.org/2001/XMLSchema-instance'
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xsi:schemaLocation='http://docbook.org/ns/docbook
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster http://docbook.org/xml/5.0/xsd/docbook.xsd'
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden xmlns:xlink='http://www.w3.org/1999/xlink'>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden <title>What's New in OpenAM ${serverDocTargetVersion}</title>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden <important>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden <para>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden OpenAM ${serverDocTargetVersion} is a maintenance release
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden that resolves a number of issues, including security issues in OpenAM.
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden It is strongly recommended that you update to this release
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden to make your deployment more secure,
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden and to take advantage of important functional fixes.
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden ForgeRock customers can contact support for help and further information.
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden </para>
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden </important>
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden <itemizedlist>
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington <para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Before you install OpenAM or update your existing OpenAM installation,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster read these release notes.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Then update or install OpenAM.</para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <listitem>
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington <para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If you have already installed OpenAM, see <link
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:show="new"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:href="release-notes#update-from-earlier-release"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:role="http://docbook.org/xlink/role/olink"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ><citetitle>To Update OpenAM 11.0.0</citetitle></link>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If you are installing OpenAM for the first time, see <link
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:show="new"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:href="release-notes#install-fresh"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:role="http://docbook.org/xlink/role/olink"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ><citetitle>To Install OpenAM</citetitle></link>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </itemizedlist>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <section xml:id="product-enhancements">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <title>Product Enhancements</title>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <para>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden In addition to fixes,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster this release includes the following limited product enhancements.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <itemizedlist>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden <listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster OpenAM REST API now allows logout with a restricted token
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (<link xlink:href="https://bugster.forgerock.org/jira/browse/OPENAM-3484"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:show="new">OPENAM-3484</link>).
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Restricted token <literal>asString</literal> values now use a hash
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster in order to limit their size
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (<link xlink:href="https://bugster.forgerock.org/jira/browse/OPENAM-3414"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:show="new">OPENAM-3414</link>).
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington </para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <listitem>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <para>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The SAML 2.0 IDP Adapter interface now
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster includes a <literal>preSignResponse</literal> method
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (<link xlink:href="https://bugster.forgerock.org/jira/browse/OPENAM-3190"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster xlink:show="new">OPENAM-3190</link>).
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </para>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden <para>
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden This method makes it possible
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden to adjust the content of a SAML response
80849398a45dca1fb917716907d6ec99be6222c2Peter Major in order to add a custom SAML extension for example.
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden The method is called after the SAML Response object is created
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden but before the SAML Response is signed or encrypted.
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden </para>
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington </listitem>
80849398a45dca1fb917716907d6ec99be6222c2Peter Major
ce4d3fddc8fe2eddd68a20af9570b3cc63ece5abNeil Madden <listitem>
80849398a45dca1fb917716907d6ec99be6222c2Peter Major <para>
da6568101c99a4ec99c3b63f37fe358e07eee51eNeil Madden The default SAML 2.0 IDP attribute mapper implementation now
80849398a45dca1fb917716907d6ec99be6222c2Peter Major provides a way to Base64 encode binary attributes
80849398a45dca1fb917716907d6ec99be6222c2Peter Major (<link xlink:href="https://bugster.forgerock.org/jira/browse/OPENAM-2767"
80849398a45dca1fb917716907d6ec99be6222c2Peter Major xlink:show="new">OPENAM-2767</link>).
80849398a45dca1fb917716907d6ec99be6222c2Peter Major </para>
80849398a45dca1fb917716907d6ec99be6222c2Peter Major
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <para>
In order to have the default IDP attribute mapper
Base64 encode binary attributes when adding them to the SAML attributes,
use the <literal>;binary</literal> postfix for the attribute name,
as in the following example:
</para>
<literallayout class="monospaced">objectGUID=objectGUID;binary</literallayout>
<para>
This maps the local binary attribute <literal>objectGUID</literal>
to a SAML attribute called <literal>objectGUID</literal>
that is Base64 encoded.
</para>
<para>
The default IDP attribute mapper also supports NameFormat URI format
as shown in the following example:
</para>
<literallayout class="monospaced"
>urn:oasis:names:tc:SAML:2.0:attrname-format:uri|objectGUID=objectGUID;binary</literallayout>
</listitem>
<listitem>
<para>
The <literal>AttributeQueryUtil.getAttributeMapForFedlet</literal> method
now handles failure status codes received from the IDP
(<link xlink:href="https://bugster.forgerock.org/jira/browse/OPENAM-1749"
xlink:show="new">OPENAM-1749</link>).
</para>
</listitem>
</itemizedlist>
</section>
<section xml:id="product-documentation">
<title>OpenAM Documentation</title>
<itemizedlist>
<para>
You can read the following additional
<link xlink:show="new" xlink:href="http://docs.forgerock.org/en/openam/11.0.0/"
>product documentation for OpenAM 11.0.0</link>
online at <link xlink:show="new" xlink:href="http://docs.forgerock.org/" />.
</para>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/release-notes/"
xlink:show="new">OpenAM 11.0.0 Release Notes</link>
</para>
</listitem>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/install-guide/"
xlink:show="new">OpenAM 11.0.0 Installation Guide</link></para>
</listitem>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/upgrade-guide/"
xlink:show="new">OpenAM 11.0.0 Upgrade Guide</link></para>
</listitem>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/admin-guide/"
xlink:show="new">OpenAM 11.0.0 Administration Guide</link>
</para>
</listitem>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/dev-guide/"
xlink:show="new">OpenAM 11.0.0 Developer's Guide</link>
</para>
</listitem>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/reference/"
xlink:show="new">OpenAM 11.0.0 Reference</link>
</para>
</listitem>
<listitem>
<para>
<link xlink:href="http://docs.forgerock.org/en/openam/11.0.0/javadoc/"
xlink:show="new">OpenAM 11.0.0 Javadoc</link>
</para>
</listitem>
</itemizedlist>
</section>
</chapter>