Identity Server 2026.1 Release Notes
Release highlights
At the core, this IDS 2026.1 release, with SSO 10.0 and CustomerID 7.0 is a complete Runtime update. The full release and all updated service components have been updated to Java 21. Additionally, all applications or elements which use Tomcat benefit from the update to Tomcat 10.1. For CustomerID, we have completed the runtime modernization by adopting Spring Boot, taking advantage of its superior web application packaging and embedded web server capabilities. This also helps unify the management of third-party libraries in use.
We would like to point out that there are deployment changes to CustomerID 7.0. The installation and upgrade pages should be reviewed prior to performing the upgrade. Please open a Service Desk ticket with our Support department if you run into any questions.
CustomerID /Heath - API 1.0 removed
Updating CustomerID to 7.0 provided the opportunity to improve deployment and management functions. A side-effect of this is the removal of Health Rest API 1.0 In its place are four endpoints, which provide improved monitoring capability for the application. Please ensure you review Health and Monitoring with Actuator. Default ports utilized can be found from the linux.config and win32.config CustomerID files.
That said, at the core, the update to IDS 2026.1 has no impact on existing LDAP or PostgreSQL schemas. Similarly, the API and UI functionality remains consistent between SSO 9 and SSO 10, and between CID 6 and CID 7. We always recommend you update to the latest SSO 9.8 and CID 6.7 prior to migration to SSO 10 and CID 7; this prevents any unanticipated changes should your operating environment contain older or unsupported versions of the Identity Server. (You do not need to be on the latest patch version, so SSO 9.8.0 or SSO 9.8.2 will both upgrade to SSO 10 according to the offered documentation).
Contents
- 1 Release highlights
- 2 Change log
- 2.1 SSO 10.0.0
- 2.1.1 New Features
- 2.1.2 Improvements
- 2.1.3 Corrections
- 2.2 CustomerID 7.0.0
- 2.2.1 New Features
- 2.2.2 Improvements
- 2.2.3 Corrections
- 2.3 Identity Platform Modules
- 2.1 SSO 10.0.0
- 3 Deviations
- 3.1 SSO
- 3.2 CustomerID
Change log
SSO 10.0.0
New Features
Improvements
IDS-4489 - SSO has been updated to Java21 and Tomcat 10.1. Core functionality of the application, from LDAP Schemas to API/UI has been maintained. This runtime update will ensure CVE management and capability to create additional features into this essential application.
Corrections
CustomerID 7.0.0
New Features
Improvements
IDS-5013 - CustomerID Long term support and coder updates. Migrating CustomerID away from Wildfly and utilizing SpringBoot ensures a security focused management of potential CVEs and aids in the long term supportability of the application.
Corrections
IDS-2683 - There was a known issue with API 2.0 and API 2.1 where list organisation would not return organisations with URL encoded characters in their names. This has been corrected.
Identity Platform Modules
CertAP (Certificate Authentication Provider) - CertAP has been updated to Java21.
SAML SP for Java - SAML SP for Java is available for use with SSO 10.0.
Metadata Updater - Metadata Updater is available for use with SSO 10.0.
Swedish BankID - Swedish BankID adaptor is available for use with SSO 10.0.
As a reminder, as noted in IDS 2025.1 SAML SP for ASP.NET installation guide - SSO while this adapter can continued to be utilised, Ubisecure no longer supports SAMP SP for ASP.NET module. If you are utilising this module on older Identity Platform versions and wish to upgrade the .NET in your environment, please contact Support for a suggested solution.
Please ensure you review the updated System Recommendations page and are aware of the 3rd Party License page.
Please review the change log if you are upgrading your system from a prior version to IDS 2026.1: Identity Platform
Deviations
The following deviations are found within Identity Platform and are expected to be corrected over time. For a listing of known issues found on Identity Platform please see: Considerations, limitations and known issues
SSO
Ticket number | External description |
|---|---|
IDS-561 | There is a known issue where SSO does not check the mappingURL value when creating or editing an inboundDirectoryMappings when using the SSO REST API. Directory Mappings are possible to be created, but then not opened or edited. |
IDS-1030 | There is a known issue where running the CertAP setup.cmd in a windows environment will post errors of missing linux tags. While these errors are unsightly, they can be safely ignored. This issue will be corrected in a future release. |
IDS-1629 | There is a known issue resulting in unclear error messages. When a user is configured without a phone number and SMS OTP method is added to their profile result in one of two error messages. If the SMS OTP is the only authentication method enabled, the message will be “The user account is disabled”. If there are other authentication methods enabled, the message will be “Access to the requested resource is denied”. |
IDS-1648 | This is a known issue that only is only present with password2. User is presented with a popup "Update: Invalid account Status" if one of the previous three passwords are used when asked to update their password. There is no known work around. |
IDS-1662 | The use of the following special characters when making any search will result in an internal sever error 500 and a stack trace. Symbols: + = # ; , < > Work around, administrators should not use the special symbols when naming users or searching for users. |
IDS-1893 | There is a known issue if you use OpenID authentication, a user cannot access SAML or Ubilogin web applications. Work around use any other non-OpenID authentication method. If OpenID is required, then use OAuth 2.0 application. |
IDS-2090 | There is a known issue where the SSO management UI will not filter results correctly if the filter expression is short, contains incorrect filter expressions and there are Scandinavian characters included. |
IDS-2244 | There is a known issue when using special characters within SSO management API in persistentID name mapping that may result in incorrect side or policy id values being returned. Recommended work around, do not use special characters, like “=” “,” “#” in site and policy mapping names. |
IDS-2260 | There is a known installation issue when using SSO Password reset. Using the installation instructions for password reset tool requires an administrator to run tomcat update. This occasionally results in an empty context.xml file being created which causes SSO to fail when being restarted. Workaround, repeat the run tomcat update step which will create a correct .xml file and SSO will restart. |
IDS-2790 | There is a known issue with sending in invalid formatted request to introspection endpoint returns stack trace including server version number. This can be mitigated by following our Security considerations for using reverse proxy and customising error pages with HAProxy Security considerations for production environments - SSO |
IDS-3092 | There is a known issue where Administrators are unable to alter password encoding through the SSO management UI. There is no known UI work around. |
IDS-3625 | There is a known issue where an ERROR 500 message with stack-trace is shown in the browser if there is no valid encryption key available in SSO. Mitigation use reverse proxy to catch all 500 error with user friendly information Security considerations for production environments - SSO |
IDS-3665 | There is a known issue where the authorisation endpoint may become corrupted if a URL contains "%20" in URL encoded format. |
IDS-3971 | There is a known issue which results in a non-impacting stack trace being logged when updating metadata using ManagedScheudledExecutorService for SAML 2 AP. There is no known work around to this non-impacting log event. |
IDS-4202 | There is a known issue where attributes forwarded from an external authentication method are not available after the access token has been refreshed. No known work around is available at this time. |
IDS-4644 | There is a known issue where the use of special characters within a users name, like “)” for example “Bud)”, will break the user mapping view. Work around, do not permit special characters within user names. |
IDS-4669 | There is a known issue where the status refresh does not update entryTtl for dynamic session objects. There is no known work around at this t |
IDS-4733 | There is a known issue within SSO which could permit XML expansion from an external entity. Additionally, there is a known issue within SSO which could allow for header injection. Both items will be corrected in an upcoming patch, SSO 9.4.1. |
IDS-4967 | There is a known issue where SSO may leave IO Streams in an improperly closed state which results in a diag log warning when SSO server is shut down as the LDAP Connection thread could not be shut down. |
IDS-5031 | There is a known issue within TOTP as nextFactor for OIDC which will result in user access denied if the user has not selected an OIDC method of authentication first. The work around is to instruct users to select existing ODIC authentication first, with TOTP as MFA. |
IDS-5314 | There is a known issue where it is not possible to create an authentication method with unicode characters in the name. |
IDS-5534 | There is a known issue where an administrator requested UAS/info will receive a stack track HTTP 500 in response. There is no work around at this time. |
IDS-5424 | There is a known issue when using a single master for LDAP replication will under high enough load or long enough duration cause a failure in the two node single master LDAP setup. It is recommended to reboot ldap on a periodic basis. |
CustomerID
Ticket number | Description |
|---|---|
IDS-1373 | There is a known issue in CustomerID when a new user is created in a non-virtual organisation, the invitation can contain a role when no role has been approved for that user. |
IDS-1509 | There is a known issue where a new user being invited to a virtual organisation the CustomerID administrator cannot approve the user; an internal server error occurs. |
IDS-1706 | There is a known issue with null values (DbAssignable.set and DbAssignable.isNull) which may result in NullPointer exceptions when using REST calls. This impacts Roles, Mandates and Invitations. |
IDS-2312 | There is a known issue in approval view where changing technical name of an organization to include Scandinavian letters doesn't work. |
IDS-2703 | There is a known issue where a role name with different case can be created which results in one LDAP entry and two SQL entries. |
IDS-2816 | There is a known issue which will create an unhandeled exception if the users SMTP server cannot be resolved. This issue will cause a database collision issue which may prevent the same email address from being used, as it already exists within the database but not in a fully created form. |
IDS-2876 | There is a known issue if user is rejected from UI error is logged "Error when trying to get approval request with ID: null". A stack trace is logged. This stack trace can be safely ignored. |
IDS-2934 | There is a known issue in CustomerID within Mandates, where no renotify email is sent to new user to register using mandate invitation. Admin user sends mandate from Admin UI to new user that is not registered to the system. Email is sent correctly, but no renotify is sent to register to the system.Mandate expires correctly also and email is sent that mandate was expired. |
IDS-2941 | There is a known issue where a NPE will occur if an administrator is viewing an ORG2PER mandate from the CustomerID management UI. |
IDS-3058 | There is a known issue where in change password application of CustomerID where the return URL is missing a forward slash (returns "https:/" not "https://") resulting in failed redirect if the cancel button would be enabled. |
IDS-3765 | There is an issue with JDK 11.0.15 that prevents Wildfly from working |
IDS-5191 | There is a known issue where a user entry remains in LDAP in a broken state when the a user invitation expires after the user registration has started. |
IDS-5278 | There is a known issue if user status is locked, because of entering incorrect authentication details multiple times, CID UI shows user account status locked. However, REST API does now show status as locked. It still shows the status as enabled. |
IDS-5373 | There is a known issue with users with non standard characters where the user account will not be created when using UI, but is permitted to be attempted with API, but is still prevented from using non-standard characters with email addresses. Specifically “é”, work around is to omit using this character. |
IDS-5505 | There is a known issue with CustomerID logout which can result in a HTTP 405 method not allowed error page. There is no work around at this time. |
IDS-5565 | There is a known issue that occurs during registration with email confirmation enabled, that the email address is not validated and allows any kind of value. Results in sending confirmation code to an invalid email address, and invalid value being saved into the database. Ensuring there is a properly formatted email address will prevent this error from occurring. |
IDS-5611 | There is a known issue during registration where a user can use the browser back button in specific screens which would permit them to bypass specific approval conditions. There is no work around at this time. |
IDS-5617 | There is a known issue when using Mandates, where a user1 can send a mandate delegation forward to an additional user2, then user1 account is deleted resulting in broken user2 configuration. There is no work around for this at this time. |