IBM Tivoli Access Manager for Enterprise Single Sign-On 6.00 Rollup G Fix Pack 4 Release Notes

This document contains information about the fixes addressed by IBM Tivoli Access Manager for Enterprise Single Sign-On (TAM E-SSO) 6.00 Rollup G Fix Pack 4, as well as a list of known issues, if applicable. It also provides instructions for installing and uninstalling this fix pack.

Contents:

Issues addressed in this fix pack

This section contains the list of issues addressed in this fix pack with the corresponding tracking numbers:

Cumulative from Fix Pack 4

·         APAR IZ28923 (PMR: 67622,211,848)

s5533: Trace logging can now be configured to remain enabled during a reboot, enhancing the ability to diagnose startup issues.

No IBM APARS – Internal Defects Only

  • s4111, s4536, s4648: Installation of TAM E-SSO with TAM E-SSO Kiosk Adapter caused prompts for two separate authentications.
  • s5207: The third and fourth fields in the Retry Logon dialog box were masked when configured to display.
  • s5250: A Web application password change form detected third and fourth fields but did not inject credential into those fields.
  • s5275: A Java application template could not be created for an application using a non-standard control for the user name.

·          s5333: The Agent pre-filled the LDAP synchronization logon dialog box with an incorrect user name after a password change to a repository

  • s5366: The Agent did not begin to function for an extended period of time when using Windows Authenticator v2 and SSOGINA with Authentication Manager.
  • s5374: The Agent caused a browser page to scroll and display incorrectly when responding to the page. New settings have been added to control the Agent's interaction with Web pages.
  • s5498: The Administrative Console did not detect any fields during the creation of a Web template.
  • s5534: The Agent terminated unexpectedly when using Send Keys to inject a credential selected from the Logon Chooser.
  • a11355: The Administrative Console did not save provisioning modifications upon exit.
  • a11464: The Security tab of the Administrative Console displayed the default server as "04botwdom02."

 

Cumulative from Fix Pack 3

·         APAR IZ16825 (PMR: 65490,211,848)
s4943: The Agent did not inject the third or fourth field configured for a Change Password form in a Web template.

No IBM APARS – Internal Defects Only

  • s4436: The Agent did not respond to Web pages that displayed as modal dialogs or HTML applications.
  • s5182: The Agent did not respond to multiple sessions of SAP applications.
  • s5199, s5539: An SSOShell.exe failure during workstation shutdown caused display of the message, "The application failed to initialize because the Windows station is shutting down."
  • s5259: Java application and applet templates that were set up using SendKeys could not be edited.
  • s5350: The primary logon method did not work for LDAP in SSL mode.
  • s5422: The Agent did not retain the custom third field label when a Change Password form was also part of the application template.
  • a10345: Support for v-GO Shared Accounts Manager has been added to the Agent.
  • a11313: The Agent recognized a Change Password screen as a Logon screen when multiple forms were defined in an SAP application template.
  • a11382: The Agent did not respond to Java applications whose templates were configured to use matching.
  • a11384: When using Mozilla Firefox, the Agent did not respond to some Web applications whose templates were configured to use matching.
  • a11483: The Agent did not disconnect completely from SAP, causing erratic behavior.

 

Cumulative from Fix Pack 2

No IBM APARS – Internal Defects Only

  • s3812: TAM E-SSO failed to create a template for a password change in a Windows application because the Administrative Console could not detect the module name of the Password Change Window.
  • s4046: When added through the New Logon Wizard, the password of a template in the Domain Sharing Group was not validated against the authenticator's cached password.
  • a10877: TAM E-SSO did not recognize a correct password entry after an initial incorrect password entry on the LDAP synchronization dialog box.
  • a11020: After installing TAM E-SSO 6.0 Rollup G Fix Pack 1, the Agent ceased to restore credentials from an SSO backup file

 

Cumulative from Fix Pack 1

No IBM APARS – Internal Defects Only

  • s5115, s5116: Caching credentials in TAM E-SSO Kiosk Adapter with Xyloc caused credentials to corrupt.

Installation instructions

To help ensure a satisfactory installation of this fix pack:

  1. Ensure that TAM E-SSO 6.00 Rollup G is installed.
  2. Read these release notes entirely.
  3. Back up all data. IBM strongly recommends that you back up data prior to the installation of any software.
  4. Close all IBM software.

To install this fix pack using the installation wizard:

  1. Double-click the IBM_TAM_ESSO_6G_FP03_AGENT.MSP and follow the on-screen instructions.
  2. Double-click the IBM_TAM_ESSO_6G_FP03_CONSOLE.MSP and follow the on-screen instructions.

To install this fix pack manually:

  1. Copy ssoShell.exe to [INSTALLDIR].
  2. Copy support6.dll to [INSTALLDIR].
  3. Copy InMemShr.dll to [INSTALLDIR]\Plugin\StorageMgr.
  4. Copy TextStorage.dll to [INSTALLDIR]\Plugin\StorageMgr.
  5. Copy syncmgr.dll to [INSTALLDIR]\Plugin\SyncMgr.
  6. Copy ldapsync.dll to [INSTALLDIR]\Plugin\SyncMgr\LDAP.
  7. Copy mobility.dll to [INSTALLDIR]\Plugin\BackMgr.
  8. Copy chs_ssohelp.chm to [INSTALLDIR]\Lang\chs\Help.
  9. Copy deu_ssohelp.chm to [INSTALLDIR]\Lang\deu\Help.
  10. Copy eng_ssohelp.chm to [INSTALLDIR]\Lang\eng\Help.
  11. Copy esp_ssohelp.chm to [INSTALLDIR]\Lang\esp\Help.
  12. Copy fra_ssohelp.chm to [INSTALLDIR]\Lang\fra\Help.
  13. Copy ita_ssohelp.chm to [INSTALLDIR]\Lang\ita\Help.
  14. Copy jpn_ssohelp.chm to [INSTALLDIR]\Lang\jpn\Help.
  15. Copy kor_ssohelp.chm to [INSTALLDIR]\Lang\kor\Help.
  16. Copy ptb_ssohelp.chm to [INSTALLDIR]\Lang\ptb\Help.
  17. Copy appmgr.dll to [INSTALLDIR]\Plugin\LogonMgr.
  18. Copy appmgr.vrs to [INSTALLDIR]\Lang\Esp\Res.
  19. Copy appmgr.vrs to [INSTALLDIR]\Lang\Ptb\Res.
  20. Copy appmgr.vrs to [INSTALLDIR]\Lang\Kor\Res.
  21. Copy appmgr.vrs to [INSTALLDIR]\Lang\Jpn\Res.
  22. Copy appmgr.vrs to [INSTALLDIR]\Lang\Ita\Res.
  23. Copy appmgr.vrs to [INSTALLDIR]\Lang\Deu\Res.
  24. Copy appmgr.vrs to [INSTALLDIR]\Lang\Fra\Res.
  25. Copy appmgr.vrs to [INSTALLDIR]\Lang\Chs\Res.
  26. Copy appmgr.vrs to [INSTALLDIR]\Lang\Eng\Res.
  27. Copy ssobho.exe to [INSTALLDIR]\Helper\IE.
  28. Copy ldapauth.dll to [INSTALLDIR]\AUI\LdapAuth.
  29. Copy msauth.dll to [INSTALLDIR]\AUI\MSauth.
  30. Copy SSONP.dll to [INSTALLDIR]\AUI\MSauth.
  31. Copy ssogina.dll to Windows\System 32.
  32. Copy ssosapho.exe to [INSTALLDIR]\Helper\SAP.
  33. Copy ssomozho.exe to [INSTALLDIR]\Helper\Moz.
  34. Copy jho.jar to [JAVAINSTALLDIR]\lib\ext.

where
[INSTALLDIR]
is the directory where you installed
TAM E-SSO.
and
[JAVAINSTALLDIR] is the directory where you installed your Java Runtime Environment.

Known issues or considerations

You cannot uninstall this fix pack. If for any reason you must uninstall the fix pack, you must uninstall the TAM E-SSO product and reinstall. For more information on uninstalling TAM E-SSO, see the TAM E-SSO Installation and Setup Guide.