Version 5.1.3 bug fixes
Installation
Multi-account installation in macOS and Linux
Enhancements have been applied to multi-account installations in macOS and Linux. Now, when a connection is set up in a locked session, it will automatically be disconnected when other users open their own sessions. Each workstation allows only one connection at a time.
There is no longer any need to ask individual users sharing macOS and Linux workstations to shut down their connections after use.
These enhancements were already operational in Windows.
Saved connections
Saved OpenVPN connections
Special characters in the names of new saved OpenVPN connections prevented saved connections from being loaded. To prevent this issue from occurring, special characters can no longer be entered when new OpenVPN connections are added.
Importing saved connections
An error message now indicates that saved connections failed to be imported when the user selects a .book file on which they do not have read privileges. Previously, the Stormshield SSL VPN client would shut down unexpectedly.
Exporting saved connections
An error message now indicates that saved connections failed to be exported when the user selects a .book file on which they do not have write privileges. Previously, the Stormshield SSL VPN client would shut down unexpectedly.
Migration of the address book to saved connections
During an update from version 4 of the Stormshield SSL VPN client to version 5.1.3, address book entries that contain a space in the "Firewall address” field are now correctly converted in saved connections. Previously, the space would be kept, preventing the Stormshield SSL VPN client from loading saved connections after the migration of the address book.
Multifactor authentication (OTP)
Connection expiry
When the connection is about the expire (key renegotiation), the window that prompts the user to enter a new OTP will now remain visible. Previously, the window would disappear, and the user would need to wait until the connection expired in order to reconnect.
Hardening of the Stormshield SSL VPN client
System
On shared workstations, the graphical interface instance of a user's Stormshield SSL VPN client is no longer able to communicate with the graphical interface instances of other users.
Single sign-on
When a connection is set up with single sign-on, information about the cookie that is sent between the service and the Stormshield SSL VPN client graphical interface is now limited to metadata (IP address, expiry date, etc.).
Direct OpenVPN connection
The exchange protocol that is used for setting up a direct OpenVPN connection has been enhanced. Users can no longer specify a path to another OVPN file. Now, only the contents of the loaded OVPN file are used.
Logs
Log levels
The log level values that are accepted by the exchange protocol between the service and the Stormshield SSL VPN client are now restricted to values that are accepted by the Stormshield SSL VPN client graphical interface.
Log amount
The amount of logs that are saved in the system logs in macOS and Linux, and in Windows event logs, has been reduced to retain only those that may be necessary for troubleshooting. Previously, the amount of logs that were generated would saturate hard disks on some machines.