What's new in ManageEngine Password Manager Pro 12.0 Build 12005

Mar 28, 2022
  • Upgrade:
  • Apache Log4j has been upgraded from version 1.2.8 to 2.17.2.
  • Enhancements:
  • From this build onwards, we have enhanced our security checks against Path Traversal, Local File Inclusion, Stored XSS, Reflected XSS, and DOM XSS vulnerabilities.
  • From this build onwards, three new default query reports have been added under the 'Resources' category - Resources with Accounts, Resources with Types, and Resources with Ungrouped Passwords.
  • Bug Fixes:
  • Earlier, when the 'Windows Remote Desktop' option was disabled under 'Auto Logon Helper' for a particular resource type, the 'Record RDP Sessions' checkbox did not appear in the 'Add/Edit Account' wizard even when the 'RDP Console Session' option was enabled for that resource type. This issue has been fixed now.
  • Earlier, the 'Record SSH/Telnet Sessions' checkbox was not available for the 'Windows Domain' sync type. This issue has been fixed now.
  • Earlier, the 'SSH Port For Auto Logon' option was not visible in the 'Edit Resource' wizard for Network resource types such as Fortigate, VMware Vcenter, and Brocade. This issue has been fixed now.

New in ManageEngine Password Manager Pro 12.0 Build 12004 (Feb 23, 2022)

  • Customer Reported Issues:
  • From ManageEngine ADSSP build 6117 onwards, the integration with Password Manager Pro was broken. This issue has been fixed.
  • From build 12000 onwards, the administrators were unable to delete custom roles. This issue has been fixed.
  • From build 12000 onwards, when users newly configured ‘Purge Audit Records’ and the specified number of days was set to 0, to disable purging, Password Manager Pro removed all the audit records. This issue has been fixed now.

New in ManageEngine Password Manager Pro 12.0 Build 12003 (Dec 25, 2021)

  • Enhancement:
  • From build 12003, the API user host name has been modified to be case-insensitive.
  • Bug Fixes:
  • From build 12000, administrators were unable to import users through AD. The issue has been fixed.
  • From build 12000, the 'Password' field under 'Personal tab >> Custom Categories' that has to be hidden, was visible. The issue has been fixed.
  • From build 12000, while configuring replication, the login failed if the login name was in the format - 'domainnameloginname'. The issue has been fixed.
  • From build 12000, Password Manager Pro failed to load when the user logins via SAML SSO. The issue has been fixed.

New in ManageEngine Password Manager Pro 12.0 Build 12002 (Dec 4, 2021)

  • Security Fix:
  • We have fixed an authentication bypass vulnerability (CVE-2021-44525) that affects ManageEngine Password Manager Pro, versions up to 12001, and allows an adversary to gain unauthorized access to the application and invoke actions through specific application URLs.

New in ManageEngine Password Manager Pro 12.0 Build 12001 (Nov 27, 2021)

  • After installing build 12000 in non-English machines, users could not access Password Manager Pro. This issue has been fixed.

New in ManageEngine Password Manager Pro 12.0 Build 12000 (Nov 19, 2021)

  • Enhancements:
  • The internal security framework has been upgraded to the latest version to reduce the occurrence of vulnerabilities and improve overall security.
  • The PostgreSQL server has been upgraded from version 9.5.21 to 10.18.
  • The Apache Tomcat server has been upgraded from version 8.5.32 to 9.0.54.
  • The Rubyrep tool has been upgraded from version 1.2.0 to 2.0.1.
  • Password Manager Pro has now migrated to the OpenJDK platform, version 1.8 .0_252.
  • In addition to supporting the JTDS JDBC driver to connect to the SQL server, Password Manager Pro now supports Microsoft JDBC driver, version 8.4.1.
  • We have implemented a patch integrity verification, which will henceforth require importing an SSL certificate (available as a downloadable file) whenever the product is upgraded using the PPM fileIt is only a one-time operation.
  • Password Manager Pro allows users to add accounts via the Windows Domain agent when the account filter is provided using regex patterns.
  • Henceforth, if an administrator restricts a user from setting up the encryption passphrase for their personal passwords (under 'General Settings'), the user can set up an 'encryption key' for their personal passwords from the 'Personal' tabThey are also free to choose between whether to store or not store the encryption key or use Password Manager Pro's encryption key.
  • It is now possible to move the RESTAPI users to the client, and the supported client organizations with complete access can manage resources and accounts.
  • The six system-created audit schedules - 'Resource Audit Purge Schedule', 'Resource Audit Digest Schedule', 'UserAudit Purge Schedule', 'UserAudit Digest Schedule', 'TaskAudit Purge Schedule', and 'TaskAudit Digest Schedule' have been merged into a single schedule - 'Audit Purge and Digest' Schedule.
  • The system-created scheduled task 'Audit Update Schedule' has been renamed as 'Dashboard Chart Activity Schedule'It is available under 'Admin >> Manage >> Scheduled Tasks'.
  • Previously, when the 'Purge Audit Records' option was enabled, all the audit records older than the specified number of days were purgedFrom build 12000 onwards, users can choose to retain or delete audit records based on the operation type.
  • From now on, MSP admins will be able to replicate audit operation type settings and audit purge settings across all client organizations.
  • New REST APIs
  • This release comes with a bunch of new REST APIs for the following operations: Associate a resource to a resource group, Dissociate a resource from a resource group, Fetch resource groups associated with a resource, Delete a resource group, and Fetch ResourceGroupID.

New in ManageEngine Password Manager Pro 11.3 Build 11301 (Sep 24, 2021)

  • Enhancement:
  • Two new agents have been introduced in build 11301 - C# agent for Windows/ Windows Domain and Go agent for Linux. Password Manager Pro will henceforth allow users to restrict user accounts that are added via agents (new agents only) during account discovery, using regex patterns.
  • Bug Fixes:
  • Earlier, the agent key validity could be set only up to 24 hours. Now, the agent key validity can be set up to 999 hours via system properties.
  • Earlier, Windows Firewall settings prevented multiple agent discovery in machines. This issue has been fixed now.
  • Earlier, while choosing the database, lengthy database connection names were only half visible in the UI. This issue has now been fixed by adding a tooltip with the full database name.
  • From build 11200, users imported via AD were unable to login into Password Manager Pro using local authentication. This issue has been fixed.

New in ManageEngine Password Manager Pro 11.3 Build 11300 (Aug 13, 2021)

  • New Features:
  • Renewal of Certificates
  • A 'Renew' option has been newly added under 'Certificates >> Certificates' that allows users to initiate the renewal of Self Signed, Root Signed, Microsoft CA Signed, and Agent-signed certificates, and also the certificates issued by the third-party CAs. Upon renewal, the renewed certificates will automatically inherit the deployed servers and their credentials.
  • Discovery from UNC Shared Path for Windows, Linux, and Mac OS
  • Password Manager Pro now supports SSL certificate discovery from UNC (Universal Naming Convention) shared paths for Windows, Linux, and Mac OS machines. Use this feature to discover SSL certificates stored in a folder path within a server that is accessible by Password Manager Pro. After the discovery, Password Manager Pro will consolidate the newly-discovered SSL certificates in its certificate repository. This option is available during scheduled certificate discovery as well.
  • Certificate Discovery in DMZ Machines using the KMP Agent
  • It is now possible to discover the SSL certificates from directories in remote machines that are not directly accessible by Password Manager Pro—all through the KMP Agent. This option is available during scheduled certificate discovery as well.
  • Browser Deployment of Certificates
  • Users will now be able to deploy SSL certificates in browsers from Password Manager Pro for the following server types: Windows, Linux, and MacOS.
  • SSH Key Association using "Elevate to root user" Option
  • This release comes with a new "Elevate to root user" option. Now, as a security measure, it is possible to restrict users from directly accessing root users by disabling the root user login. Enabling this option elevates a user login from a non-root user to a root user and associates keys to all other users on the server.
  • RestApi
  • The new REST API, 'Deploy Certificate', has been added.
  • SSL Certificate Rediscovery
  • Password Manager Pro now allows you to rediscover SSL certificates from the same source using the server details entered during the previous discovery operation.
  • Integration with Buypass Go SSL and ZeroSSL
  • Password Manager Pro now integrates with Buypass Go SSL and ZeroSSL—two certificate authorities that use the Automatic Certificate Management Environment (ACME) protocol to provide free, secure SSL certificates. Users can now request, acquire, create, deploy, renew, and automate the end-to-end management of SSL/TLS certificates issued by Buypass Go SSL and ZeroSSL, all directly from the Password Manager Pro web interface.
  • Integration with ManageEngine Mobile Device Manager (MDM) Plus
  • Password Manager Pro now integrates with ManageEngine Mobile Device Manager (MDM) Plus. This integration uses ManageEngine MDM APIs to discover and deploy SSL certificates to and from the mobile devices managed by your MDM server. Password Manager Pro then lets you filter the discovered SSL certificates based on the OS type such as iOS, Android, Windows, Chrome OS, Mac OS, and Apple tvOS. It is also possible to export reports of the MDM certificates managed in the Password Manager Pro repository within a selected period. Additionally, you can schedule periodic generation of MDM certificate reports.
  • Manager Pro allows you to globally modify the access level of the shared certificates.
  • New REST API's, 'Share SSL Certificate to User', 'Share SSL Certificate to User Group', 'Share SSL Certificate Group to User', 'Share SSL Certificate Group to User Group', 'Revoke SSL Certificate from User', 'Revoke SSL Certificate from User Group', 'Revoke SSL Certificate Group from User', 'Revoke SSL Certificate Group from User Group', 'Create SSL Certificate Group', 'Delete SSL Certificate Group', 'Edit SSL Certificate Group', 'Generate an Agent Install Key', have been added.
  • Enhancements:
  • Users can now view all the certificates associated with a particular agent by clicking the 'Host Name' of the agent listed under Certificates >> Certificates >> Windows Agents'.
  • Now, users can discover certificates issued by a particular 'Microsoft Certificate Authority' just by entering the MSCA name in the text box provided, during discovery. Remember, this additional option will be available for Password Manager Pro installations in Windows server machines only.
  • Now, it is possible to add the Wildcard name in the SAN field while creating a CSR or a self-signed certificate. With the Wildcard certificates, one can secure an unlimited number of subdomains for a registered base-domain.
  • Earlier, Certificate Expiry Notification emails sent to the email addresses specified in additional fields followed a fixed format. Now, the customization settings configured for notification emails in 'Admin >> SSH/SSL Config >> Notification Settings' will be applied to the emails sent via email addresses in the additional fields as well.
  • Password Manager Pro now supports scheduled SSL discovery and MS Certificate Store Discovery tasks with the KMP agent.
  • Previously, the certificates due for expiry in 10 days or less got automatically renewed. Now, users will be able to customize the number of days to auto-renew the certificates before they expire.
  • From now on, during CSR signing of SSL certificates using the KMP agent, it is possible to specify the Agent timeout value, in seconds.
  • Henceforth, users will be able to select specific Certificates or Certificate Groups while generating the 'SSL Certificates Report' Schedule type (under 'Admin >> SSH/SSL Config >> Schedules >> Add Schedule').
  • Users will now be able to add and edit the deployed servers list under 'Certificates >> Certificates >> Multiple Servers (icon)'. Newly added servers will be mapped with the latest certificate version in the certificate repository.
  • Password Manager Pro now supports IP range discovery for MS Certificate store discovery ('Certificates >> Discovery >> MS Certificate Store') using the PMP service with the domain Admin account. This allows administrators to discover certificates across networks.
  • Password Manager Pro now supports 'Load Balancer' Certificates discovery for Citrix devices. From build 11300 onwards, Password Manager Pro also supports scheduled certificate discovery from Linux-based load balancers such as BIG-IP F5, Nginx, and Citrix.
  • Certificates and CSR generation pages have been enhanced with the Random Password generation feature.
  • Users can now select up to five certificate templates while performing template-based SSL certificate discovery.
  • Users can now bypass proxy server settings while performing SSL certificate discovery. If this option is selected, Password Manager Pro will bypass the proxy server and directly perform online certificate discovery. This option is available during scheduled certificate discovery also.
  • Earlier, after certificate renewal, users will have to deploy MSCA/-self-signed certificates manually. Now, it is possible to deploy these certificates automatically if the user credentials are available.
  • Users will now be able to choose the 'Certificate type' [CER/DER/P7B/CRT] and 'Keystore type' [JKS/PKCS/PEM/KEY] while deploying certificates to Windows and Linux machines and while exporting certificates.
  • Now, it is possible to renew MSCA type Certificates with a new private key if a private key not available already.
  • From now on, Password Manager Pro supports ClouDNS to complete domain control validation while acquiring certificates from public Certificate Authorities.
  • Support for AES256-encrypted PKCS12 Keystores while adding certificate Keystores.
  • MSCA Discovery with KMP Agent using Multiple Templates
  • Users can now select up to five certificate templates while performing agent-based certificate discovery of local CA certificates. Before using this enhancement, please ensure the KMP Agent is upgraded to version 11300.
  • Search-Enabled Custom Columns
  • From build 11300 onwards, Password Manager Pro allows you to search within custom columns for SSL Certificates and SSH keys.
  • Multiple Servers List
  • Now you can include multiple servers for certificates in SSL certificate expiry notifications.
  • GoDaddy Certificates Import
  • From now on, users can directly import the existing certificates from their GoDaddy account into the Password Manager Pro repository.
  • Local Disassociation of Keys
  • It is now possible to dissociate keys locally if remote dissociation fails for users whose access has been discontinued.
  • APIs - Serial Number as the Mandatory Field
  • Earlier, the Serial Number field, which was optional in the below APIs, has now been made mandatory; To get a certificate, To get certificate keystore, and To delete a certificate.
  • Serial Number in the getCertificateDetails Rest API
  • In the getCertificateDetails Rest API, Serial Number has been added as an optional field; filling it fetches the details of that particular certificate alone.
  • Henceforth, the SSL certificates can be manually mapped with deployed servers list to any server directly from Certificates >> Certificates >> More >> Add Deployed Server'.
  • From now on, certificates/CSRs/certificate groups will have an email field to which the SSL expiry email notifications can be sent, where the expiry notification email address can be provided while creating the Certificate and CSR.
  • A new option - Deploy to Microsoft certificate store user account, has been added, which facilitates the deployment of the Microsoft Store deployed certificates to the respective user accounts, besides deploying to the computer accounts.
  • The SSL Certificate Expiry notification, set up under 'Admin >> SSH/SSL Config >> Notifications Settings >> Expiry', will now include Issuer, FingerPrint, and Serial Number fields in the Certificate Expiry email.
  • From build 11300, the 'Certificates Audits' tab will be available under the 'Audits' tab, where, all the certificates audit related to all the users will be displayed.
  • New REST APIs 'Get Password Policies' and 'Get Resource Types' have been added.
  • Bug Fixes:
  • The KMP agent got duplicated when re-installed from a different IP address. This has been fixed.
  • The 'Common name' column sorting issue in the 'Certificate Sign Report' wizard has been fixed.
  • The issue in MSCA auto-renewal with the EC key has been fixed.
  • Get Templates issues that existed with the non - English languages have been fixed.
  • Under 'Admin >> SSL Certificates >> IIS Binding', binding list retrieval failed for bindings with a protocol other than HTTP/HTTPs. This issue has been fixed.
  • Earlier during Digicert import, Password Manager Pro failed to import client/personal certificates into Password Manager Pro. This issue is now fixed.
  • Earlier, the date format had the month as a part of the value, due to which sorting did not work. Now, this issue has been resolved by modifying the date format in the CSV file to be the standard date format.
  • Earlier, while discovering certificates using a load balancer, there were problems with commands other than the standard Linux commands. This issue has been fixed.
  • Get templates issue has been fixed for CA name-based fetch.
  • Previously, the proxy configuration was not supported in GlobalSign integration, due to which users with proxy were unable to use the integration. This issue has been fixed now.
  • Earlier, it was possible to add or modify IISBinding only by giving the 'hostname'. This issue has been fixed, and now 'hostname' is not mandatory to create or update IISBinding.
  • Earlier, MSCA templates showed the OID instead of the template name. This issue is fixed.
  • During SSL discovery, discovery from servers with mutual authentication failed. This issue has been fixed now.
  • MSCA discovery, when carried out using an agent without any filter, failed. This issue is fixed now.
  • There was an issue in exporting the certificates as password-protected zips when password protection for exports was enabled under 'Privacy Settings'. This issue has been fixed now.
  • There was a failure in Linux deployment from the ServiceDesk Plus request. This issue has been fixed now.
  • Earlier, when the custom settings option 'View Support Information' was enabled for a custom user role, the users with that role were unable to access the 'Support' option from the profile drop-down. This issue is fixed now.
  • Earlier, when a new category was created with the same name as an existing one from the 'Personal' tab, the product did not display an error message. This issue is fixed now.
  • Earlier, if the name of a category seen from the 'Personal' tab contained the special character '&', the contents of the category were not visible in the display area. This issue is fixed now.
  • Earlier, when a new resource was created using the 'Create Resource' API, and the 'Resource URL' field was left blank, users could not edit the resource attributes in the Password Manager Pro UI. This issue is fixed.
  • Behavior Change:
  • From now on, all certificates with unique serial numbers will be listed under the 'Certificates' tab. However, the existing users can manage their already added certificates from the History section, which has now been moved under the 'Column Chooser'.
  • Security Fixes:
  • An XSS vulnerability (ZVE-2021-0956) that occurred during Load Balancer discovery has been fixed.
  • A SQL injection vulnerability identified in the PostgreSQL password reset functionality is fixed.
  • A path traversal vulnerability identified in the role report section is fixed by adding proper validation steps for the download file path of the report.
  • Earlier, users could reopen a closed remote SSH session window from the browser history page and reinitiate the remote connection without requesting for the password of the resource again. This issue is fixed.

New in ManageEngine Password Manager Pro 11.2 Build 11201 (Jul 16, 2021)

  • Bug Fix:
  • In 11200, users could not make connections using Windows domain accounts, configured with Access Control, even if the users had the access approval. This issue has been fixed.

New in ManageEngine Password Manager Pro 11.2 Build 11200 (Jul 7, 2021)

  • Enhancements:
  • New Query Reports
  • Two new default query reports for users having access to the browser extension and users who don't have access to the browser extension have been added.
  • New Resource Type
  • We have introduced a resource type, Cisco Nexus OS.
  • New Rest APIs
  • This release comes with a bunch of new RESTAPIs: Fetch UserGroupID, Configure Remote Password Reset for Linux resources, Share Resource and Share account to User Group.
  • Behavior Changes:
  • The API handling code which earlier responded to the V1 API format of ServiceDesk Plus On- Premises and ServiceDesk Plus Cloud will henceforth respond to their V3 API format.
  • The Authentication mechanism of ServiceDesk Plus Cloud has been updated from the older Authtoken based method to OAuth 2.0. In addition, from now on, it is possible to validate entries in the ticketing system columns against the entries in Password Manager Pro to check for any mismatches. Earlier, it was possible to check the entries in Password Manager Pro alone.
  • Note: If your current Ticketing System is ServiceDesk Plus On-Premises or ServiceDesk Plus Cloud, this upgrade pack will disable the integration and delete the complete integration data. You will have to reconfigure the ticketing system again. So, make sure you have a backup of the advanced configurations in the form of screenshots for reference purposes.
  • Bug Fixes:
  • When the PMP and KMP agents were installed in the same machine, the data used for the agents' authentication was stored in the same place in the registry, causing the overwriting of the agents' data, thereby making the agents non-functional. This issue has been fixed.
  • The automated scheduled task introduced for dashboard optimization caused the database connections to become unavailable, for some time, for a few users. This issue has been fixed now.
  • When Two-Factor Authentication was enabled, the legal banner and the privacy policy banner links in the Login page (enabled from the 'Rebrand' wizard) did not show up/work. We have resolved this issue.
  • Earlier, for some users, after configuring Duo TFA, the requests that were supposed to be sent to the PMP access URL were directly sent to the Password Manager Pro server. This issue has been fixed now.
  • Earlier, the 'Edit User' action did not work for certain users. We have resolved this issue.
  • Previously, the password entered in 'Importing users from AD wizard >> specify the user name and password manually' did not get saved due to a password encoding issue. This issue has been fixed.
  • Earlier, users were able to export offline passwords even when the export password was disabled using the export URL. This issue has been fixed now. A user enumeration issue has been fixed.

New in ManageEngine Password Manager Pro 11.1 Build 11104 (May 4, 2021)

  • Security Fix:
  • A vulnerability from version 9.7.0 that permitted the retrieval of masked non-website resource type passwords as clear-text, by capturing the API call of the Password Manager Pro browser extension and replacing the password ID of website account passwords. This vulnerability occurred under any or all the following circumstances; with the user type roles only, with the password masking option enabled by the Admin under 'General Settings', and only to the shared passwords.
  • Enhancement:
  • As an extension to the above fix, a new option has been introduced under 'General Settings >> Password Retrieval', which allows Autologon for URL-configured non-website resources via the browser extension, even if the plain text view of passwords is disabled. With this, users will have the flexibility to enable or disable the Autologon functionality carried on via the browser extension for which the URL is configured.

New in ManageEngine Password Manager Pro 11.1 Build 11103 (Apr 2, 2021)

  • Enhancement:
  • Duo-TFA SDK Update The third-party Two-Factor Authentication software Duo Security is now upgraded from v2 to v4. Once the PMP application is upgraded to build 11103, the Duo Security update will be applied automatically to the existing integration.
  • Bug Fixes:
  • Earlier, users faced an issue with the mouse scroll during RDP and VNC remote sessions initiated through Google Chrome version 89. This issue has been fixed.
  • Earlier, when password synchronization was enabled for any organization (MSP or a Client ORG), Password Manager Pro executed the task only for the organizations under MSP. This issue has been fixed now.
  • Earlier, users were unable to use the operators >= and <= in the LDAP search filter queries during user import from an LDAP domain. This issue has been fixed.
  • Security Fixes:
  • Earlier, a security vulnerability allowed unauthorized personnel to pull the Super Admin's email address by accessing the URL - /SuperAdminAlertList.ec, through API. This vulnerability has been fixed.
  • A Cross-Site Scripting (XSS) issue found in the Query report description has been fixed.
  • A Cross-Site Scripting (XSS) issue found in the User Password Change page has been fixed by ensuring proper output encoding for the password policy.
  • A Cross-Site Scripting (XSS) issue found in the edit LDAP server details page has been fixed.

New in ManageEngine Password Manager Pro 11.1 Build 11102 (Mar 12, 2021)

  • Security Fix:
  • A Cross-Site Scripting (XSS) issue that occurred in the web app connection page has been fixed.

New in ManageEngine Password Manager Pro 11.1 Build 11101 (Mar 12, 2021)

  • Enhancements:
  • Password Manager Pro is now available in the Portuguese language.
  • Bug Fixes:
  • Earlier, in schedules, created for AD groups during resource or user discovery, groups with an ampersand (&) in their names could not be edited. This issue has been fixed.
  • In earlier builds, the Password Manager Pro dashboard froze and the server ran out of memory due to the overload of audit data. This issue has been fixed.
  • In build 11002, in the 'Account Addition' password field, the character & was displayed as &. This issue has been fixed.
  • From build 11000, users could not create the Password reset Listener. This issue has been fixed now.

New in ManageEngine Password Manager Pro 11.1 Build 11100 (Feb 18, 2021)

  • Enhancements:
  • Enhanced Password Policy Enhancements have been made to the existing password policy by introducing new constraints and additional features which include; improved default attributes for Strong and Medium password policies, the introduction of password limit, the addition of new attributes, such as password similarity and sequences, ability for Admins to add and manage up to 5 dictionaries, Dictionary word check, Obvious Substitution (LEET) word check, Password Strength Meter, Sample Password Generator, New Password Generator, etc. These would be of great help to administrators in setting highly secure password policies.
  • Access Control & Domain Account Restrictions Earlier, a user with access to a domain account can log into any resource shared with them using the domain account. Henceforth, it is possible to implement Domain account restrictions for target resources, i.e., Windows domain account users can be granted access to specific resources alone, which they actually want to access, instead of all resources shared with them. Please note that from this release, the Password Request API for domain accounts alone has been blocked.
  • Bug Fixes:
  • In build 11002, when the Admin users from the MSP org scheduled reports in the Client org, they received Zero bytes reports. This issue has been fixed now.
  • From build 11002, Additional fields were missing from the Bulk edit page of resources. This issue has been fixed now.
  • From build 10500, users with the Password Administrator role were unable to perform 'change role' or 'delete user' operation - to change to a Password user or a Password Auditor, even when no resources or accounts were present under 'Transfer Approver privileges. This issue has been fixed now.
  • In build 11004, while generating a custom report, say, a report containing all the resources present under a Dynamic resource Group, no results or a blank page was displayed. This issue has been fixed.
  • Security Fix:
  • When users configured X-Forward-For in Password Manager Pro, there was a possibility to bypass web access restriction by setting the X-Forward-For header manually. This issue has been fixed now.

New in ManageEngine Password Manager Pro 11.0 Build 11004 (Dec 17, 2020)

  • Enhancement:
  • It is now possible to reset passwords under the following categories, either individually or in bulk, from 'Resources >> Password Explorer >> Admin Actions'; Expired Passwords, Conflicting Passwords, and Policy Violations.
  • The SAML SSO configuration, already available for MSP organizations, is now made available to Client organizations as-well, thereby allowing client organizations to build their own SAML setups.
  • During the 'User Access Token' method of Azure AD user import, it was not possible to get the 'Oauth' token when TFA is enabled. To overcome this, a new Authentication mode of Azure AD user import - 'App-Only Access Token' has been introduced in this release.
  • Bug Fix:
  • In build 10501, during AD sync, the resource or user removed from an AD resource/user group still showed up in the Password Manager Pro resource/user group. This issue has been fixed now.

New in ManageEngine Password Manager Pro 11.0 Build 11003 (Nov 10, 2020)

  • Enhancement:
  • It is now possible to 'retry' the periodic password reset of Resource groups by configuring password reset retry settings, which include the number of retries and retry interval. If this setting is enabled, the password reset will be re-attempted after every failure at the specified retry interval within the specified number of attempts.
  • Bug Fixes:
  • Earlier, there was an issue in the User Group Report. The resources part of the dynamic resource groups did not display their resource names properly in the Resource access details section of the report. This has been fixed now.
  • The RDP connection issue related to ServiceDesk Plus has been fixed.
  • The issue in enabling and disabling the Bulk two-factor authentication has been fixed.
  • Security Fix:
  • Cross-Site Scripting (XSS) issues in the following places have been fixed: VNC connection page, recorded session playback, RDP Shadow feature, Auto logon helper list, and Resource Types Filter.

New in ManageEngine Password Manager Pro 11.0 Build 11002 (Sep 28, 2020)

  • Security Fix:
  • A Reflected Cross-Site Scripting (XSS) vulnerability, found in the Query Report feature, has been fixed.
  • Bug Fix:
  • Post 11001 upgrade, when a username having a special character such as, '@' was copied, the character was replaced with '%40'. This issue has been fixed now.

New in ManageEngine Password Manager Pro 11.0 Build 11001 (Sep 20, 2020)

  • Security Fixes & Enhancements:
  • A Cross-Site Scripting (XSS) issue that occurred in the following places has been fixed: Login screen, AD import page, User group name, Perform password reset page, LDAP and SMART CARD and Configure Remote Password Reset add resource type page, edit account page, configure access control view, Resource types Filter, Change Password Window, Password History, Organization name, Resource Types, Custom Role, Associate resources, Create/Edit schedule view, Copy Resource Attribute, all Discovery Profiles, all Copy Personal Account attributes, Username, Password Policy Name, Copy account name, Trash password, Chat history, SQL connection page, TFA page, and while exporting offline passwords.
  • Missing Function Level Access Control (MFLAC) issue in the Import SSH key function and user Delete action has been fixed.
  • A SQL injection vulnerability identified in the recorded sessions Dashboard, Reports, and Audit has been fixed.
  • Any user having the audit ID of any chat was able to see the chat history. This issue has been fixed.
  • Password Manager Pro now comes with a comprehensive Cross-Site Request Forgery (CSRF) protection that restricts attackers from executing any or all of the following operations: Deleting and restoring trashed resource, Deleting and restoring trashed user, Changing the victim's default landing screen, Creating SSH keys, Editing authorize key, and Enabling/Disabling TFA.
  • Bug Fix:
  • There was an API related issue which prevented the browser plug-in of the Ticketing system from accepting ticket IDs with white spaces. This issue has been fixed now.
  • Renaming of the Comodo products as Sectigo by 'The SSL Store' was causing issues while renewing or reissuing Comodo orders, which has been fixed now.

New in ManageEngine Password Manager Pro 11.0 Build 11000 (Aug 11, 2020)

  • New Features:
  • Expiry Notifications for SSL Certificates
  • Now, use Password Manager Pro to discover, import, and configure expiry notifications for SSL certificates hosted in the following Amazon Web Services: AWS Certificate Manager (ACM) and AWS Identity and Access Management (IAM).
  • Self-signed Certificates Auto Renewal
  • Password Manager Pro now supports automated renewal of self-signed certificates along with Microsoft CA certificate renewal.
  • SSL Certificate Deployment and Binding - IIS Server
  • From now on, you can both deploy a certificate to the IIS server and also bind it to the desired website in the IIS, all from the Password Manager Pro interface itself, without the need to access the IIS server separately. Also, an option has been provided to automatically restart the IIS server for the deployment and binding to take effect, thereby eliminating the need for the manual restart from the IIS end.
  • Additional Fields
  • Password Manager Pro now brings you the 'Additional Fields' feature, configured from 'Admin >> SSH/SSL Config', and used to include any additional information about SSH keys and SSL certificates stored in the repository. There are four different categories of Additional Fields: character, numeric, date, and email. Users can choose to add or remove the Additional fields from SSH and SSL views. While creating an Additional field, users can choose whether it is applicable for SSH/SSL/both, and also customize the emails mentioned in it.
  • Column Chooser
  • This version of Password Manager Pro comes with the 'Column Chooser' feature that allows users to show or hide columns at runtime, and also rearrange the columns from the current view via drag-and-drop.
  • Pretty Good Privacy (PGP) Keys
  • PGP encryption is used to enhance cryptographic privacy and authentication for online communication by encrypting and decrypting texts, emails, files, etc. It uses a combination of data compression, hashing, and public-key cryptography to boost confidentiality. Now, Password Manager Pro brings you this PGP functionality in the form of PGP key generation, where the keys are used to encrypt the data like emails, texts, etc. Create, store and manage PGP keys under 'Admin >> SSH/SSL'. Modify the key description anytime, export private/public keys, export keys to multiple email ids, and generate, view, and schedule reports. You can also send expiry notification emails to admins. This feature allows you to share and collaborate information securely among your trusted groups of users and businesses.
  • GlobalSign
  • Password Manager Pro now supports integration with GlobalSign SSL—a trusted Certificate Authority and a leading cloud-based PKI solutions provider. This integration enables users to request, acquire, import, deploy, renew and automate the end-to-end lifecycle management of SSL/TLS certificates issued by GlobalSign, directly from the Password Manager Pro web interface.
  • Certificate Deployment using Agent
  • Password Manager Pro can already deploy and bind certificates to IIS servers belonging to the domain, where Password Manager Pro also resides. Now, Password Manager Pro can also deploy certificates to IIS servers in demilitarized zones and also bind them to websites in IIS, all using an agent. This makes Password Manager Pro more scalable, as it can deploy and bind certificates in IIS servers, irrespective of whether they are in the same or different domain.
  • CSR Signing using Agent
  • In addition to the already available two sign types, namely, 'MS Certificate Authority' and 'Sign with Root', used to sign certificates from Password Manager Pro, a third sign type 'MS Certificate Authority with Agent' has been introduced. This new sign type is mainly used to sign certificates originating from a distinct domain, i.e., other than the domain to which Password Manager Pro belongs.
  • Integrating with Ticketing Systems
  • Password Manager Pro now integrates with enterprise ticketing systems namely ServiceDesk Plus (on-premise) and ServiceNow. This integration ensures that automatic service requests are created in the ticketing environment to notify administrators of SSL certificates that are at the risk of expiring and certificates that are deemed vulnerable after a vulnerability scan in Password Manager Pro. Users can set notification policies to govern the frequency of service request creation for expiring and vulnerable tickets.
  • New Certificate Format - PEM A new certificate format, Privacy Enhanced Mail (PEM), has been added, in addition to the already available certificate export formats, Keystore and PFX, where the PEM format is used for digital certificates and keys, deployed in web server platforms (e.g., Apache).
  • Support for GoDaddy DNS
  • Password Manager Pro now supports GoDaddy DNS to complete the domain control validation procedure while acquiring certificates from public Certificate Authorities, along with the already available DNS support types, Azure DNS, Cloudflare DNS, Amazon route 53, and RFC2136 Update. Using GoDaddy DNS, users can update the DNS record for GoDaddy domain validation from the Password Manager portal itself.
  • Enhancements:
  • Password Manager Pro now provides additional insights on agent activity such as heartbeat interval, latest response time and operation performed.
  • For scheduled SSL expiry tasks, users now have the option to choose whether or not, to receive email notifications when no certificates in that particular schedule are nearing expiration.
  • Password Manager Pro offers automatic bundling of individual private key (.key) files and certificate files (.cer/.pem) into 'JKS' and 'PKCS' keystore file formats and provides export option for the same.
  • Two extra categories have been added to the criteria-based certificate group creation: AWS service and Certificate template.
  • Now, it is possible to use the Password Manager Pro service account credentials for authentication while deploying certificates in Windows servers.
  • Henceforth, while creating a certificate, users can provide ephemeral access (validity in hours and minutes) to the certificates created, after which the certificate auto-expires. This eliminates the need for compulsory permanent access credentials to access target systems and also explicit access repeal.
  • It is now possible to perform SNI-based SSL discovery using the Common Name and IP Address combination.
  • The option to filter certificates based on the key length and signature algorithm within specific expiry days has been added to the 'getAllSSLCertificates' Rest API.
  • It is now possible to customize notifications and their intervals. Users can now choose not to receive notifications regarding the expired certificates, and send a separate email and customized subject per certificate, from 'Admin >> SSH/SSL >> Notification Settings'. The same actions can be done while creating new schedules under 'SSH/SSL >> Schedules >> Add Schedule', where you have to select the Schedule Type as 'SSL Expiry'.
  • Earlier, Password Manager Pro allowed signing and deployment of certificates only from Windows systems. Now, it is possible to perform certificate signing and deployment to Windows systems from Linux installations through agents.
  • It is now possible to provide customized subjects in 'Schedules'. Also, users can tailor schedules by adding custom email content and a unique signature.
  • In RestAPI, the fetch details format is modified is such a way that the "details" attribute holds all the data. The following is the modified API list; GetCertificateDetails, getallsslcertificates, getAllSSLCertsExpiryDate, sslCertSingleDiscovery, sslCertRangeDiscovery, getallsshkeys, GetSSHKey, GetSSHKeysForUser and GetAllAssociatedUsers.
  • This release comes with an exclusive page for 'Windows Agents', accessible from the 'Certifcates' tab, from where users will be able to perform all agent-specific operations such as SSL Discovery using agent, deployment of SSL certificates in certificate groups using agent and CSR Signing with MSCA agent.
  • Certificate deployment in multiple servers has now been made simpler by using an agent, provided the agent is running in the server to be deployed, and both the agent name and the server DNS name are the same.
  • Now, auto-renewal of certificates is possible for the 'MSCA using agent' sign type as well, from 'Admin >> SSL Certificates >> Certificate Renewal'.
  • The 'Certificate Sign Report' comes with the following MSCA/Third party CA signing details; Certificate Authority, Certificate Template, Sign Type column.
  • The 'Certificate Renewal report' comes with the 'Renewed By' column relevant to MSCA and 3rdPartyCA renewal details.
  • A new option 'Reissue Certificate' has been added under 'Certificates >> GlobalSign' that allows users to request GlobalSign to reissue an SSL certificate.
  • The new 'GlobalSign Orders Report' allows the GlobalSign orders to be added as individual reports, which provide a detailed view of certificate orders requested from the GlobalSign CA.
  • From now on, users can add a "Key Comment' while importing a new SSH key and editing an existing key from the repository. Also, users can avail the checkbox "Update comment in associated users" to update the Key comment to the associated end servers automatically.
  • Now, it is possible to add additional properties to a certificate while creating it, by using the 'Advanced Options' menu. It allows users to choose from a list of Key Usage and Advanced Key Usage properties, and add them to the new certificate. Examples for the Key Usage properties include; Digital Signature, Decipher Only, Encipher Only, and Certificate Sign.
  • The DigiCert CA page has been enhanced with a new menu 'Show' that has four options, Expired, Revoked, Rejected, and Others, used to filter the DigiCert CA list view.
  • Now, while adding or modifying the Certificate Groups, it is possible to set 'additional fields' also as one of the 'By Criteria' filters for certificates.
  • New REST APIs 'GET CSR list' and 'Sign CSR' have been added.
  • The 'Expiry Notification' has been enhanced with the custom mail content, 'Title' and 'Signature'.
  • The 'Certificate Renewal Report' page under 'Reports >> Certificate Reports' now comes with a column chooser.
  • Users can now view all the certificates associated with a particular agent by clicking the 'Host Name' of the agent listed under 'Certificates >> Windows Agents'.
  • It is now possible to discover certificates issued by a particular 'Microsoft Certificate Authority' just by entering the MSCA name in the text box provided, during discovery. Remember, this additional option will be available for Password Manager installations in Windows server machines only.
  • Now, it is possible to add the Wildcard name in the SAN field while creating a CSR or a self-signed certificate. With the Wildcard certificates, one can secure an unlimited number of subdomains for a registered base-domain.
  • Earlier, Certificate Expiry Notification emails sent to the email addresses specified in additional fields followed a fixed format. Now, the customization settings configured for notification emails in 'Notifications' and 'Schedules' will be applied to the emails sent via email addresses in the additional fields as well.
  • Bug Fixes:
  • Previously, certificate deployment failed if the field "Store Password" contained a space character while creating certificates from 'Certificates → Create'. This issue has now been fixed.
  • Previously, when there was a "space" character present in a certificate group name, attempting to fetch the SSL certificates report pertaining to that group from the Reports tab threw the following error: "Invalid field format". This has now been fixed.
  • Previously, even after the certificate private key was imported and attached to a certificate in the Password Manager Pro's certificate repository, the "Export Keystore/PFX" was still disabled. This has now been fixed.
  • During AD User certificate discovery and Root certificate signing performed from the Password Manager Pro interface, the 'Connection Mode' got saved as 'No SSL' only, even if the 'SSL' mode was chosen. This issue has been fixed now.
  • Earlier, MSCA signing supported 'java keytool' CSR only. Now, from this release, all CSRs will be supported by MSCA signing.
  • During certificate creation, all values entered in the SAN field were all together categorized as 'DNS' only. Now, the values are segregated as 'DNS' and 'IP Address' categories.
  • Earlier, during Digicert integration, import of code signing and client/personal certificates got failed. This issue has been fixed now.
  • Security Fix:
  • Earlier, for SSH and SSL related API calls, the Authentication token was passed as a request parameter. From 11000, all SSH and SSL related API calls require the Authentication token to be passed in the request header only.

New in ManageEngine Password Manager Pro 10.5 Build 10501 (Jun 19, 2020)

  • Enhancement:
  • We have upgraded the PostgreSQL server to version 9.5.21.

New in ManageEngine Password Manager Pro 10.5 Build 10500 (Jun 4, 2020)

  • Enhancement:
  • Previously, it was possible to configure access control settings at the resource level only, and the same settings were applicable for all the accounts under the resource. Now, it is possible to set password access control independently for each account under a resource, without affecting the access control configurations of other accounts in the resource. This ability to set unique configurations for each account helps users maintain unparalleled security levels for each account, based on requirements. Remember, the account-level access control configuration takes higher precedence over the resource-level access control configuration.
  • Security Fix:
  • A Cross-Site Scripting (XSS) issue that occurred due to the absence of output encoding in the Resource name while masking password, theme type, skin color, Category name of the Personal tab, web app connections, and user sessions of the Audit tab, has been fixed.
  • A local File Intrusion issue during the MS store discovery that occurredhas been fixed.

New in ManageEngine Password Manager Pro 10.4 Build 10406 (May 16, 2020)

  • From the build 10103, an unauthenticated servlet vulnerability found in our internal framework that posed the risk of less-impactful entries getting inserted in the integration system configurations table, remotely, has been fixed.

New in ManageEngine Password Manager Pro 10.4 Build 10405 (Apr 29, 2020)

  • Security Fixes:
  • A SQL injection vulnerability identified in "Audit Reports" has been fixed.
  • A Cross-Site Scripting (XSS) issue that occurred due to the absence of output encoding in the user input has been fixed.
  • Earlier, the Keystore password of the certificate uploaded into the server was appended in the URL, which posed a security risk. From now on, the Keystore password will be sent as the 'RequestBody' to maintain optimal security.

New in ManageEngine Password Manager Pro 10.4 Build 10404 (Apr 13, 2020)

  • Security Enhancement:
  • The internal security framework has been upgraded to improvise the max-occurrence validation of parameters.
  • Bug Fixes:
  • From the build 10403, in certain customer environments, resolving the hostname from the request took more time than expected, which caused slowness in the Password Manager web console. This issue has been fixed now.
  • From the build 10400, Super Admins could not bulk transfer the ownership of resources and encountered an error "owner alone can transfer the resources". This issue has been fixed.
  • In the build 10400, during the remote password reset, an exception was thrown while discovering MS SQL accounts by supplying domain accounts. This issue has been fixed now.

New in ManageEngine Password Manager Pro 10.4 Build 10402 (Jan 7, 2020)

  • Bug Fix:
  • In certain scenarios, an exception was thrown during the backup process and the file 'pg_hba.conf' became empty. This caused trouble in viewing the Password Manager Pro web console. This issue has been fixed now.

New in ManageEngine Password Manager Pro 10.4 Build 10401 (Dec 5, 2019)

  • Enhancements:
  • Remote File Transfer - Linux
  • Earlier, it was possible to transfer files from remote Windows machines only during Remote Desktop Protocol (RDP) sessions launched via the Password Manager Pro interface. Now, from the build 10401, you will be able to transfer files to remote Linux machines as well, using Secure Copy Protocol (SCP) by launching SSH sessions directly from the console. However, unlike Windows, the remote file transfer is one way in Linux, i.e., to the target machine only.
  • APIs Added:
  • Two new APIs for "Sharing a resource to a user" and "Sharing a account to a user" have been introduced in this release.
  • Bug Fixes:
  • While adding a resource manually, when more than 100 characters were entered in the 'Location' field, which can originally hold up to 250 characters, the 'Edit Resource' page failed to show up. This issue has been fixed now.
  • In earlier versions of Password Manager Pro, the 'Account Addition API' did not work for MySQL, MS SQL and Postgre SQL database resources alone. This issue has been fixed now.
  • In earlier versions of Password Manager Pro, password reset did not work for the AWS IAM account alone. This issue has been fixed now.

New in ManageEngine Password Manager Pro 10.4 Build 10400 (Oct 18, 2019)

  • New Features:
  • Integration with DigiCert SSL
  • Password Manager Pro integrates with DigiCert—a leading TLS/SSL, IoT and various other PKI solutions provider. Users can request, acquire, create, deploy, renew and automate the end-to-end management of SSL/TLS certificates issued by DigiCert, all directly from the Password Manager Pro portal.
  • CSR Templates
  • It is now possible to create and use predefined templates for CSR (Certificate Signing Request) generation.
  • Option to Exclude Certificates
  • Users can now choose to ignore certain certificates during the SSL discovery or manual addition of certificates into the Password Manager Pro repository. A new option is added under 'Admin >> SSH/SSL >> Exclude Certificate', which you can utilize to add the certificates to be excluded, by specifying their Common Name and Serial Number.
  • Support for RFC2136 DNS Updates
  • Password Manager Pro now supports RFC2136 DNS updates to complete domain control validation while acquiring certificates from public certificate authorities (CAs). Option to modify the email id of the Let's Encrypt account, used by Let's Encrypt to send email alerts of expiring certificates.
  • Enhancements:
  • Earlier, it was possible to associate a SSH key with a user account only when the target system was reachable from the Password Manager Pro server. This was troublesome when the target system was inaccessible. Now, from the Password Manager Pro build 10400, an option is provided for Linux resource types that users can opt to force map SSH keys to user accounts, even if the target systems are not reachable.
  • Users can now use Password Manager Pro to sign CSRs (either using your internal Microsoft CA or a root certificate) as and when they are generated.
  • Password Manager Pro now supports file-based discovery for scheduled SSH and SSL discovery tasks.
  • A new dashboard widget to provide data about SSL configuration vulnerabilities has been added.
  • Support is enabled for the discovery of SSH keys with ECDSA and ED25519 signature algorithms.
  • A new REST API to view the private key passphrase of SSL certificates has been added.
  • Bug Fixes:
  • During OpenLDAP and Novell Directory import, new users' domain names were not updated properly, which caused login exception. This has been fixed now.
  • AzureAD did not work when the proxy server was configured in Password Manager Pro. This has been fixed now.

New in ManageEngine Password Manager Pro 10.3 Build 10302 (Sep 23, 2019)

  • Enhancement:
  • Redesigned Password Manager Pro Agent:
  • The Password Manager Pro (PMP) agent is used to connect with and manage remote resources that are not attached to the PMP server. Earlier, the agent was downloaded from the PMP console and straight away deployed in target systems. Now, from build 10302, each time while installing the agent on a remote server, you will have to provide a unique 'Agent Key', generated and copied from the PMP console while downloading the agent. The keys are for single use only and will be automatically revoked after that. If you wish to install a key in multiple servers, you can keep the key active for the number of hours specified.

New in ManageEngine Password Manager Pro 10.3 Build 10301 (Sep 10, 2019)

  • New Features:
  • Integration with ManageEngine Analytics Plus:
  • ManageEngine Password Manager Pro integrates with ManageEngine Analytics Plus, an on-premises reporting and business intelligence service. The PMP-Analytics Plus integration brings about out-of-the-box analytics on resources management. Analytics Plus sources data from PMP via its API using your login credentials. The reports are generated automatically with up-to-date data, and you can gain a complete overview of the reports from the module-specific dashboard of Analytics Plus. You can also set timeline filters.

New in ManageEngine Password Manager Pro 10.2 Build 10200 (Jul 30, 2019)

  • Enhancements:
  • SSL Discovery:
  • Agent-based Discovery:
  • Password Manager Pro now supports agent-based SSL discovery that allows administrators to discover and import certificates present across a network by installing one or more instances of agent software on target systems. The agent, which is available as a compressed package with all the necessary configurations in password Manager Pro interface, once installed in the required end servers, performs certificate discovery and updates the certificate database.
  • Load Balancer Certificate Discovery:
  • Password Manager Pro now allows administrator users to discover and consolidate SSL certificates deployed to Linux based load balancers such as Nginx and F5
  • through a process tunnelled via SSH.
  • Option to Login to Certificate Store and Microsoft CA using Service Accounts:
  • A dedicated option is provided for the Administrators to make use of the Password Manager Pro service account credentials to log in to target systems, while performing Certificate Store and Microsoft CA discovery, without having to manually enter them.
  • SSH and SSL Discovery:
  • Subnet Discovery:
  • Password Manager Pro now provides the subnet discovery option for both SSH and SSL discovery, allowing administrators to discover keys and certificates from specific subnetworks within an IP range.
  • Option to Exclude IP addresses:
  • Users can now choose to exclude specific IP addresses when performing bulk discovery from an IP address range.
  • Key-based Authentication for Certificate Deployment:
  • Password Manager Pro now provides an additional key-based authentication functionality (apart from the conventional password authentication), which users can leverage to deploy certificates to password-less Linux end servers.
  • Support for Amazon Route 53 DNS:
  • In addition to Azure and Cloudflare DNS, Password Manager Pro now supports Amazon Route 53 DNS to complete the domain control validation process when acquiring certificates from public CAs.
  • New SSH Key Types Added:
  • From now on, two additional SSH key types - ECDSA and ED25519 will be available for selection while creating new SSH keys, out of which, rotation is possible for the key type ED25519.
  • Option to Use Existing Password Manager Pro Account during Certificate Deployment:
  • While deploying certificates to target web servers, a dedicated option is provided for the users to use an existing Password Manager Pro account, instead of entering the credentials.
  • New Rest APIs Added:
  • Two new REST APIs are newly added; REST API to add certificates to Password Manager Pro certificate repository and REST API to delete ssh keys.
  • Bug Fixes:
  • Earlier, when a certificate was deployed to two servers, and if one of the deployed servers was deleted, the "Multiple Servers" icon was still shown. This has now been fixed.
  • Formerly, when multiple certificates were discovered from a single resource, and when the DNS name of one of the certificates was changed, the DNS names of all the other certificates also got changed. This has now been fixed.
  • Earlier, when the scheduled discovery operations for SSH and SSL failed, there were a few instances, where the audit records were not updated properly. This has now been fixed.
  • Previously, during the following processes—Microsoft Certificate Store discovery, server certificate upload, and Radius server configuration (server secret field), if a password, containing special characters, was entered, a "harmful content" error was thrown. This has been fixed.
  • Earlier, certificates without an original common name (with the SAN name as the common name, by default) failed to update, after running a scheduled discovery. This issue has now been fixed.
  • Previously, the 'Days' filter in the SSL Expiry Report failed to render correct results. This has now been fixed.

New in ManageEngine Password Manager Pro 10.1 Build 10104 (Jul 15, 2019)

  • Bug Fix:
  • When PMP configured with MS SQL database was upgraded to the latest version 10103, and an attempt was made using ConfigureReplication.bat/.sh to reconfigure High Availability, replication failed to initialize between the primary and secondary databases, due to failure in publisher creation in the primary server.

New in ManageEngine Password Manager Pro 10.1 Build 10103 (Jun 26, 2019)

  • New Features:
  • Integration with ManageEngine ADSelfService Plus (ADSSP)
  • Earlier, when the ADSSP's privileged domain account password was reset in PMP, the new password had to be manually updated in ADSSP. If not, ADSSP still retains the old password, thereby restricting the AD users from performing tasks such as password reset, account unlock, etc. With PMP-ADSSP integration, the privileged domain account details of ADSSP will be mapped with the domain account details in PMP. So, whenever the password reset of ADSSP's privileged domain account is performed in PMP, the new password will be automatically updated in ADSSP as well.
  • Integration with ManageEngine ServiceDesk Plus (SDP)
  • Technicians using SDP often need to access target machines (or resources) manually to resolve issues, which involves security-related challenges, such as sharing sensitive passwords for authentication, etc., especially while using the privileged accounts. They also had the pain of jumping between machines to perform different tasks. With this integration, accessing the remote systems from the ServiceDesk Plus portal is just a click away for the Technicians. Administrators can now provide the advantage of secure remote access to the target machines (or resources) only to the authorized Technicians, without sharing the credentials. The Technicians can remotely access the target endpoints (or resources) from the ServiceDesk Plus portal without having to log in to PMP each time to fetch the credentials.
  • Enhancement:
  • Option to add the recorded RDP session link to the "Change" description in ServiceDesk Plus
  • From now on, while integrating Password Manager Pro with the ServiceDesk Plus ticketing system, in addition to the option "Use ChangeID for Validation", a new option to allow PMP to add the link to the recorded RDP session to the "Change" Description of ServiceDesk Plus will be available.
  • Bug Fixes:
  • In PMP build 10102, the Periodic Password Export could not be scheduled, when either of the options 'Once', or, 'Day(s)' or 'Monthly' was chosen. This issue is fixed now.
  • In PMP build 10101, when a custom resource type was created (under Admin >> Resources >> Resource Types >> Add) using the "Existing Resource Type" category and applied to the resources, the password reset failed for the Domain accounts in the resource. This issue is fixed now.
  • While handling a security fix in build 10102, the URL of PMP Agent was mistakenly blocked along with a few other URLs. This interrupted the communication between the Agent and the PMP server, which in turn suspended the Agent-related activities in PMP. This issue is fixed now.
  • Password Manager Pro provides the option to configure remote password reset through a landing server for Cisco devices such as Cisco Catalyst, Cisco IOS, and Cisco CAT OS. From PMP build 10001 onwards, when an existing landing server was selected to perform the remote password reset for a resource, the settings though appeared to be saved did not get saved actually. This issue is fixed.
  • In addition to using account credentials to launch a remote SSH connection, Password Manager Pro also allows the remote connections to be tunnelled through private keys. From PMP build 10001 onwards, when the private key option is enabled or disabled for a Linux-based resource type (Linux, Cisco IOS, Cisco CatOS, Cisco PIX, Juniper NetScreen OS, HP Procurve and VMware ESXi), the auto-logon helper option for that resource got disabled, thereby entirely removing the option to launch a remote connection. This issue is fixed.

New in ManageEngine Password Manager Pro 10.1 Build 10102 (Jun 5, 2019)

  • Enhancements:
  • Support for ECDSA key in the new OpenSSH private key file format
  • In Password Manager Pro, SSH connections can be initiated using both passwords and keys. And the product already supports key-based authentication using RSA and DSA keys. Now that OpenSSH has introduced the new ECDSA key format, Password Manager Pro will also support the ECDSA key format for SSH connections with this upgrade.
  • Support for the latest versions of Sybase ASE for Remote Password Reset
  • Earlier, we had support only for the older version of Sybase ASE database, version 12.5, to carry out the Remote Password Reset. Now, we have enhanced our support to the newer versions of Sybase ASE database, from version 15 & above.
  • Security Fixes:
  • Earlier, the common unique Authentication token (generated during installation) was used for all the mobile and extension logins. Hereafter, each login to the mobile and extension will have a unique Authentication token.
  • The Captcha authentication is introduced as a security check in the Login page and Personal Passphrase page of Extension, to limit the number of failed login attempts.
  • Earlier, during API calls, the Authentication token was passed as a request parameter. Hereafter, each API call made to the application requires the Authentication token to be passed in the request header.
  • Bug Fix:
  • PMP - MSP Edition is designed to create a Resource group named "Default Group" when an MSP Admin is assigned to manage any client ORG. In our earlier versions, if an MSP Admin is removed from managing a client ORG and then re-added, another "Default Group" was created under their ownership, causing duplication. This issue has now been addressed. When an MSP admin is removed and readded to manage a Client ORG, PMP will match the existing "Default Group" of this admin and continue to retain the same without creating a duplicate group.

New in ManageEngine Password Manager Pro 10.1 Build 10101 (May 10, 2019)

  • New Feature:
  • Integration with public Certificate Authorities (CAs):
  • Password Manager Pro facilitates end-to-end life cycle management of certificates obtained from trusted certificate authorities (CAs), enabling users to request, consolidate, deploy, renew and track certificates issued by multiple commercial CAs, all from a single interface. This functionality, powered through a seamless API integration with The SSL Store™—one of the largest platinum partners of world's leading CAs, provides the users with the option to acquire the certificates from the following third-party CAs and manage them directly from Password Manager Pro's web interface: Sectigo (formerly Comodo), Symantec, Thawte, Geotrust, and RapidSSL.
  • Enhancement:
  • Unlike the earlier versions of Password Manager Pro, the "Search" field under the "Users" tab has now been enhanced to search for usernames using both the First and the Last Names.
  • Bug Fixes:
  • Earlier, when accounts were added through API, the "Password" field did not support the special characters; < > [ ]. Henceforth, the users will be able to create passwords using the above mentioned special characters, while adding accounts through API.
  • Previously, the DNS-based domain control validation procedure was unsuccessful for Let's Encrypt sub-domain certificate requests. This issue is fixed now.
  • Earlier, CSR/Certificate creation was failing, if comma separated values were provided for the Organization or the Organization Unit. This issue is fixed now.

New in ManageEngine Password Manager Pro 10.0 Build 10100 (May 7, 2019)

  • New Feature:
  • Integration with public Certificate Authorities (CAs)
  • Password Manager Pro facilitates end-to-end life cycle management of certificates obtained from trusted certificate authorities (CAs), enabling users to request, consolidate, deploy, renew and track certificates issued by multiple commercial CAs, all from a single interface. This functionality, powered through a seamless API integration with The SSL Store™—one of the largest platinum partners of world's leading CAs, provides the users with the option to acquire the certificates from the following third-party CAs and manage them directly from Password Manager Pro's web interface: Sectigo (formerly Comodo), Symantec, Thawte, Geotrust, and RapidSSL.
  • Enhancement:
  • Unlike the earlier versions of Password Manager Pro, the "Search" field under the "Users" tab has now been enhanced to search for usernames using both the First and the Last Names.
  • Bug Fixes:
  • Earlier, when accounts were added through API, the "Password" field did not support the special characters; < > [ ]. Henceforth, the users will be able to create passwords using the above mentioned special characters, while adding accounts through API.
  • Previously, the DNS-based domain control validation procedure was unsuccessful for Let's Encrypt sub-domain certificate requests. This issue is fixed now.
  • Earlier, CSR/Certificate creation was failing, if comma separated values were provided for the Organization or the Organization Unit. This issue is fixed now.

New in ManageEngine Password Manager Pro 10.0 Build 10001 (Apr 11, 2019)

  • Enhancements:
  • High Availability Monitoring for PostgreSQL Database Server
  • Password Manager Pro now comes with more advanced HA management and monitoring capabilities for PostgreSQL database server with various notification options under "Admin >> High Availability". The all-in-one, dashboard-style GUI enables monitoring the availability of your Primary and Seconday servers and the associated databases. You can switch the view from the Primary to Secondary server, and vice-versa, anytime, which allows an effective tracking of your servers and their performance. You will be able to view the following in the HA GUI; the HA summary, the status of the servers and the associated databases, the replication pending count, and the connection lost and connection resumed times. You can also modify the Secondary server details.
  • Support for SAML-based SSO Configuration for Azure AD Users with Multi-Factor Authentication (MFA)
  • In earlier versions, though it was possible to use SAML-based Single-Sign-On (SSO) from the Microsoft Azure portal for Azure AD users, the authentication did not happen when Multi-Factor Authentication (MFA) was enabled in Azure AD. Now, it is possible to use the SAML-based authentication with Azure AD as the Identity provider coupled with Azure MFA.
  • Bug Fixes:
  • Password Manager Pro supports Active Directory-based Single-Sign-On that works via NTLMv2. While this was working fine in older versions, the NLTMv2 authentication against the Computer Object was failing in version 10.0. This issue is now addressed and the AD SSO feature works fine now.
  • In Password Manager Pro version 10.0, the "Advanced Search" field did not return the intended results for the keyword entered using the AND/OR-based search criteria. This issue is fixed and the "Advanced Search" is fully functional now.
  • From Password Manager Pro version 9.7, when a user was deleted from AD / LDAP / Azure, instead of a single notification email, there was a continuous triggering of emails from Password Manager Pro, during every sync. This issue is fixed.
  • From Password Manager Pro version 9.8, in specific cases, while viewing the resources under a Dynamic Group, other resources out of the group (belonging to the logged-in user) were also displayed along with the resources belonging to the selected group. This issue is fixed.
  • From Password Manager Pro version 9.9, when the local authentication for AD users was disabled (under "Admin >> Settings >> General Settings >> User Management"), the local authentication got disabled for "all users". This restricted the users from accessing Password Manager Pro using their local admin credentials and an 'Incorrect Username/Password' error was thrown. This issue is fixed.
  • In Password Manager Pro version 10.0, the "Download" button did not work while transferring a file from a remote machine to a local machine via RDP connection. This issue is fixed.

New in ManageEngine Password Manager Pro 10.0 Build 10000 (Mar 27, 2019)

  • New Features:
  • Linux Resource Discovery using SSH:
  • Earlier, Password Manager Pro supported Telnet-based discovery alone for Linux endpoints. Now it supports SSH protocol as well for resource discovery. By providing SSH login credentials, the Admins will be able to discover the Linux endpoints using an IP Address / IP Range.
  • Note: Telnet-based discovery will eventually be deprecated as it is not a secured protocol.
  • "Let's Encrypt" Wildcard SSL Certificate Management Support:
  • Password Manager Pro already supports SSL certificates signing by "Let's Encrypt" Certificate Authority. Recently, they have upgraded their protocols to enable support for wild card certificate signing as well. Hence, from now on, the PMP users will be able to get their wildcard SSL certificates signed by "Let's Encrypt" CA and manage the same.
  • SSL Certificate Discovery from SMTP servers:
  • Password Manager Pro already allows discovery of SSL certificates from Certificate Stores, Microsoft CA and Active Directory. In addition to this, the SSL certificates can now be discovered from SMTP servers as well.
  • SSL Certificate Discovery as a Scheduled Operation:
  • Earlier, importing of SSL certificates from the Microsoft Certificate Store was an on-demand operation. Now, it is possible for Admins to create scheduled tasks (under Admin >> SSH/SSL >> Schedule >> Add Schedule) to automatically discover and import the certificates from Microsoft Certificate Store and certificates issued by Microsoft Certificate Authority.
  • Import Certificate Signing Requests (CSRs):
  • Though it was earlier possible to import a key or a certificate inside Password Manager Pro, the Certificate Signing Requests (CSRs) had to be generated inside the application only. Now, PMP allows importing (under "Certificates >> Create CSR >> Import") and managing of CSR files, generated externally, by forwarding them to trusted certificate authorities and tracking their status.
  • Enhancements
  • Crumbling of SSH Session Recordings:
  • Formerly, the SSH session recordings were stored as encoded, individual files. This might cause performance issues when the SSH session time is stretched, as the file gets constantly updated in real-time. From now on, the recordings out of extended SSH sessions will be stored as multiple files and rolled over. This should provide a smooth SSH session experience and also a zero buffer time during the session playback.
  • Remote Password Reset for Weblogic Server:
  • Apart from the endpoints listed here, Password Manager Pro can now reset, verify and manage the passwords of Weblogic application servers as well. It is possible to manage the passwords of all the Weblogic server versions, as the password reset is performed with the help of JMX service.
  • RDP Gateway Enhancements:
  • Password Manager Pro employs "SparkGateway" from Remote Spark for establishing RDP Gateway sessions. The bundled version of SparkGateway, updated in this version, comes with enhanced file transfer functionalities. This allows users to leverage file transfer improvements while opening RDP connections using PMP.
  • Option to Retain SSH Keys in Target End-points while Deleting the same from Password Manager Pro vault:
  • Heretofore, when an SSH key was deleted from the Password Manager Pro vault, the same was removed from the associated Unix/Linux endpoints as well. From this version, Admins have the option (in the SSH key delete confirmation window) to choose whether to remove a key from the endpoint, while deleting it from inside the vault.
  • Bug Fixes:
  • While using Internet Explorer, the RDP sessions had intermittent freezing issues and lag, especially when the sessions were idle for 10-15 mins.
  • Due to an encoding issue, the SSH sessions did not work, when the users whose AD username begins with the character 'u' logged into the Password Manager Pro.
  • When the option "Generate unique password for every account(Recommended)" was selected under "Groups >> Actions >> Periodic Password Reset", new passwords generated were based on the resource group password policy, instead of account password policy. This has been fixed now.
  • From version 9000, the "User Authentication Failed" report under "Dashboard >> User Dashboard >> User Activity" displayed 'No audits found' message due to a filter issue. This has been fixed now to show the valid data.
  • Earlier, a new web app connection always replaces an existing connection (when launched through the "Connections" tab). This is fixed now, and each connection launches in new tabs.
  • Password Manager Pro uses SCP protocol for deploying SSH keys in target end-points. Previously, only the "To" file information was sent along the SCP request which worked fine. But in the recent SCP versions, the "From" file information has also been made mandatory. So now, Password Manager Pro sends both "To" and "From" information of the SSH key files, thus ensuring proper completion of file deployment.
  • In earlier versions of Password Manager Pro, while deploying SSL certificates in Microsoft Internet Information Services (IIS) server, the private keys exported along with the certificates were corrupted. This is fixed now.
  • Previously, while signing a certificate using custom Root CA, a security error was thrown when the "SAN" field was blank. This is now fixed, and the certificates can be signed, even when the SAN field is left empty.
  • Security Fix:
  • We have renovated the security framework of Password Manager Pro. The following are some of the major changes and enhancements:
  • In earlier versions, Password Manager Pro primarily relied on "Blacklisting" for securing the product URLs from Injection and other script attacks. With this release, the security framework has been updated to use "Whitelisting" of the necessary URLs, which maximizes product security.
  • The validation of JSON array parameters has been intensified for optimal security.
  • A few checks with respect to file uploads (e.g., limit and size) are included to keep load attacks at bay.

New in ManageEngine Password Manager Pro 9.9 Build 9901 (Feb 13, 2019)

  • Bug Fixes:
  • In v9900, PDF generation did not work for reports that contained graphs based on resource details. This has been fixed.
  • From v9700 till v9900, application login did not work for users if their username or password contained non-ASCII characters. This encoding issue has been fixed.

New in ManageEngine Password Manager Pro 9.9 Build 9900 (Jan 23, 2019)

  • New Features & Enhancements:
  • Plugins for DevOps Containers - Jenkins and Ansible
  • The Password Manager Pro plugins developed for credential management in Jenkins and Ansible help improve security in organizations' DevOps pipeline. The plugins ensure that required credentials are retrieved securely from Password Manager Pro's vault every time when an automation schedule is run through the tools, instead of being embedded in plain text within script files. Moreover, with the credentials stored in Password Manager Pro, you can also enforce regular rotation and automatic update of the new password in the respective remote device.
  • Build Password Reset Workflows with SSH Commands:
  • Now extend Password Manager Pro's reset provisions to support remote password changes for SSH-based resources in your environment without the need for a CLI terminal. Quickly build command workflows using built-in or customized SSH sets and map them to respective SSH device accounts to execute password resets in a simple and effective manner. This new addition to Password Manager Pro's reset capabilities enables you to enforce automatic password updates for resource types that are not supported out-of-the-box by the application.
  • Two-factor Authentication Support:
  • From v9900 onwards, Password Manager Pro readily integrates with the following services to provide two-factor authentication support for application login.
  • Microsoft Authenticator
  • Okta Verify
  • RESTful API Updates
  • New API to get audit details.
  • Resource and account creation APIs enhanced to include password policy association.
  • Resource and account edit APIs enhanced to include password policy association.
  • Bug Fixes:
  • From v9200 till v9803, passwords checked out under a time-sensitive access request did not get checked back in automatically upon access expiration if a Password Manager Pro server restart took place in between. This has been fixed.
  • From v9802 till v9803, users could not raise password access requests when they and the environment in which Password Manager Pro server was installed were in different time zones. This has been fixed.
  • [MSP Edition] From v9802 till v9803, while configuring access control for a resource in a particular client organization, the user groups list in the configuration window also displayed the user groups that belonged to other client organizations. This has been fixed.

New in ManageEngine Password Manager Pro 9.9 Build 9803 (Dec 14, 2018)

  • Bug Fixes:
  • Earlier, while configuring remote password reset and auto logon helper for Windows, Windows Domain, and Linux resources, administrators could view the usernames of unshared accounts at a certain step during the configuration. This was while specifying the domain account to be used for launching remote connections to the selected resource(s). If the administrators chose a shared resource’s domain account, the unshared accounts were also displayed in the drop down list along with the shared ones available for choosing. This was applicable when the configuration was carried out for both an individual resource and in bulk. While the settings could be saved by the administrator even after specifying an unshared account, remote password reset and auto logon actions did not work when executed in real time. This has been fixed.
  • From v9700, scheduled PDF copies of User Activity, User Access, and Password Inventory reports could not be opened by the mail recipients and instead showed a file corruption error. This has been fixed.
  • From v9700, the keystore password of the certificate file used for HTTPS connections from the web server was printed in plain text in Password Manager Pro's log files. This has been fixed.
  • Security Fix:
  • From v9700, Password Manager Pro customers who had enabled SSL certificate management add-on faced credential exposure in application server log files while running a certain certificate discovery command internal Microsoft CA servers. The credential exposure was specifically when the local CA certificate discovery action was configured to discover certificates that matched a specified template. The action resulted in the account's credentials (provided by the administrator for remote login to the CA server) getting printed in clear text in Password Manager Pro application server's log files. This has been fixed.

New in ManageEngine Password Manager Pro 9.9 Build 9802 (Dec 5, 2018)

  • New Features & Enhancements:
  • GoDaddy integration for SSL certificate lifecycle management: Password Manager Pro now supports management of SSL certificates issued by GoDaddy certificate authority. This enhancement, powered through a seamless integration with GoDaddy's API, allows administrators request, consolidate, deploy, renew, revoke and manage life cycles of certificates issued by GoDaddy certificate authority from a single interface.
  • SSL certificate sharing among users: Password Manager Pro now allows sharing of SSL certificates or certificate groups with users and user groups. This will enable administrators to share required SSL certificates with technicians and allow them to track the validity and expiration dates for their server certificates. The feature further allows the technicians to also raise a request with the administrator to provision access to the private key of the shared certificate whenever required.
  • Localization Support for Traditional Chinese: Introducing localization support for Traditional Chinese in Password Manager Pro's multi-language editions, besides Chinese, Japanese, Spanish, German, French, Turkish, and Polish languages.
  • RESTful API:
  • New REST API to add dynamic resource groups.
  • REST API to create resources enhanced with the option to enable key-based authentication for Linux resources.
  • From v9802 onwards, Password Manager Pro's auto logon feature will list the Windows domain accounts that the user has access to, besides the local user accounts in Cisco resources. If the Cisco resource is already set up to accept Windows domain account credentials for authentication, users can launch SSH sessions to that resource using the domain accounts as well.
  • From v9802 onwards, XLS exports of password inventory reports (both canned and custom) will include a new column that displays resource owner information.
  • A new option has been added under Admin >> General Settings >> User Management to restrict users from adding privileged accounts to Password Manager Pro via browser extensions.
  • Earlier, when two-factor authentication (TFA) was enabled, the login screen of Password Manager Pro's mobile applications and browser extensions asked for the username first and the primary password and TFA credential were then requested together in a fresh second screen. Henceforth, the user has to input the username and password (first-factor) in the login screen and then the TFA credentials in a new screen upon successful primary authentication.
  • Bug fixes:
  • From v8604, when an administrator edited resources in bulk from the Resources or Groups tab and saved the changes, the action also reset the password reset configurations to default for the selected resources. This has been fixed.
  • From v9702, while copy-pasting values stored as custom text fields (non-password) in the Personal tab, special characters were converted to their hexadecimal values during the action due to decoding issues. This has been fixed.
  • From v9600, API user accounts with 'Full Access' permission over a resource were unable to add a new account under that resource using 'Create Resource' REST API. This has been fixed.
  • [IE browser only] From v9400, users were unable to view an account's password in clear text from that account's 'Passcard' link as well as in the 'Account Details' window. This has been fixed.
  • Earlier, the symbol 'exclamation mark' ( ! ) was not included in the set of special characters available for password policies. Due to this, associating resources/accounts with a password policy that enforced the usage of only the symbol 'exclamation mark' ( ! ) under special characters resulted in passwords being set as 'unknown' during auto-generation. This has been fixed.
  • Earlier, if the Password Manager Pro administrator had disabled the local authentication option for all users, users could still bypass the restriction provided that they used a valid local account username and password. This has been fixed.

New in ManageEngine Password Manager Pro 9.9 Build 9801 (Nov 2, 2018)

  • From v9700, Password Manager Pro moved to Apache Tomcat v8.5.27 and with this, the Tomcat server was expecting the URLs to be encoded in all the incoming requests. The Password Manager Pro agent was still sending plain URLs and in cases where the URLs had special characters like backslash (''), this resulted in the requests being dropped abruptly, causing the agent to keep trying endlessly. In scenarios where there were thousands of agents, this even resulted in a DOS attack on the Password Manager Pro server, causing busy CPU. This issue is now fixed by encoding the URLs used by the agent in all its requests.
  • From v9700, when the Password Manager Pro server starts and is not able to access the encryption key, it resulted in the passwords of the built-in 'admin' and 'guest' accounts being reset to their default values. This condition existed only for installations running with PostgreSQL as the back-end database and is now fixed. It is always recommended to remove both these built-in accounts in production installations of Password Manager Pro.

New in ManageEngine Password Manager Pro 9.9 Build 9800 (Sep 10, 2018)

  • New Features & Enhancements:
  • Data encryption and protection with SafeNet HSM
  • Password Manager Pro (PMP) now provides out-of-the-box support for SafeNet Luna PCIe HSM which gives administrators the option to enable hardware-based data encryption for the application. This update helps administrators ensure increased data security levels by leveraging the integration to securely store PMP's encryption key in the SafeNet HSM appliance available in their environment.
  • Password Reset Plugin: Provision to add custom plugins to remotely reset passwords for unsupported resource types
  • Password Manager Pro (PMP) now allows manual addition of custom reset plugins (created in the form of an implementation class) that can be invoked from PMP server to carry out remote password resets for platforms that are not supported out-of-the-box, such as legacy resource types, in-house applications, etc. Administrators can leverage this update to also configure access control for unsupported resources and enforce automatic reset of their passwords instantly upon usage.
  • Integration support for YubiKey two-factor authentication
  • From v9800 onwards, Password Manager Pro readily integrates with YubiKey—a physical key made by Yubico, which ensures secure and strong user authentication, to provide two-factor authentication support for application login.
  • Root-based certificate signing
  • Password Manager Pro now enables administrators to sign and issue SSL certificates to end-servers within the network environment, based on a root certificate that is trusted within the network.
  • Website domain expiry notification:
  • Administrators can now track upcoming public domain expirations in Password Manager Pro, facilitated via 'Whois Lookup'. They can also opt to receive periodic email notifications regarding the same.
  • New RESTful APIS
  • To delete users with their usernames
  • To add users to user groups
  • To lock/unlock users
  • To import SSH keys
  • To associate/dissociate SSH keys
  • The REST API to create a new resource now additionally supports inclusion of "Domain Name" for the resource being created. Also, the REST API to get a user's ID now supports special characters in the passed username.
  • Henceforth, REST API calls to PMP server will have a threshold policy. When any specific API call reaches the threshold number of 150 calls within a span of one minute, that API will be locked for a minute.
  • Users imported from Active Directory (AD) to Password Manager Pro will hereafter be provided the option to launch an RDP connection to Windows resources using the AD credentials with which they are currently logged into PMP.
  • Password Manager Pro now expedites domain validation for Let's Encrypt certificate renewal through automated verification of DNS-01 challenges (for Azure and Cloudflare DNS).
  • Password Manager Pro now includes provisions to import certificate files to keystore by automatically pinning its corresponding private key with the acquired certificate.
  • Audit logs for bulk password resets triggered at resource group level and modification of dynamic resource groups have been revised to include more information. The bulk password reset log now also captures the name of the resource group for which the reset action has been triggered, either on-demand or scheduled. The second log now thoroughly captures the criteria value changes carried out for the selected dynamic resource group.
  • The "Transfer Ownership" option under the Users tab now lists the available PMP users in an alphabetical order to help expedite the operation.
  • Bug Fixes:
  • From v9600 till v9702, both on-demand and scheduled remote password resets for Oracle resources failed due to server-side issues. This has been fixed.
  • From v9700 till v9701, when the MSP administrator imported an organization from a CSV file that also included information for Account Manager, the detail was not added to PMP during the import. As a result, operations like manage organization, edit, and delete organizations could not be performed for the imported organization. This has been fixed.
  • From v9500 till v9702, if the user conducted a custom search in the Resource Audit section, cleared the results, and then tried to carry out a PDF export of all the audit logs in that section, the action did not work and instead a new tab with a blank white screen opened. This has been fixed.
  • From v9600 till v9702, the search options in both User and Resource trash did not work. This has been fixed.
  • Earlier, if a user had checked out the password of an access controlled resource for a specified duration and the PMP server is restarted within that duration, the condition was automatically revoked and the user was able to continue using the password beyond the given time. This has been fixed.
  • Earlier, when an administrator created a new API user and saved the details in Password Manager Pro, the saved host name was automatically changed to that user's IP address which led to connection issues during API calls. This has been fixed.
  • Earlier, Linux resources added to PMP via REST API were not displayed in the list of available resources for "Public Key Association" in the SSH Keys tab. This has been fixed.
  • Earlier, while trying to fetch the IDs of a resource and its account via REST API by providing the resource and account names, resource names containing special characters were not allowed. This has been fixed.
  • Security Fix:
  • Earlier, a Remote File Inclusion (RFI) vulnerability in Password Manager Pro's landing server configuration tab allowed the administrator to upload any file to any location in PMP server via the image file upload field. This has now been restricted to only image files, which can be saved only in the predestined location.

New in ManageEngine Password Manager Pro 9.7 Build 9702 (Jul 27, 2018)

  • Bug Fixes:
  • From v9500 till v9701, while trying to export to PDF only the results obtained from a custom search in the Recorded Connections audit, the action did not work and instead all audit records in that section were exported. This has been fixed.
  • In v9700 and v9701, while performing password reset for selected resource group(s), the "Generate Password" option did not work when the user tried to specify a password to be used for all accounts. This has been fixed.
  • [IE browser only] From v9400 till v9701, the option to enable/disable a schedule under Admin >> Scheduled Tasks >> Schedule Actions did not work if the global language choice for Password Manager Pro was not English. This has been fixed.
  • Earlier, periodic password export could not be scheduled for a resource group when the username of the logged in user contained one or more special characters. This has been fixed.
  • Earlier, the "Forgot Password" option available in the Password Manager Pro login screen did not work for users accessing the site via Firefox and IE browsers. This has been fixed.
  • Earlier, when an auto logon helper was edited and the approval request was sent to a chosen administrator, the corresponding notification email was not triggered to the administrator's inbox. This has been fixed.
  • Security Fix:
  • From v9702 onwards, Password Manager Pro master encryption key's cryptographic strength has been enhanced by increasing the randomness of the character strings used.

New in ManageEngine Password Manager Pro 9.7 Build 9701 (Jun 29, 2018)

  • Features & Enhancements:
  • New system role with privacy administration privileges:
  • From 9701 onwards, a new system role named "Privileged Administrators" will be available in Password Manager Pro. A privileged administrator will have the same capabilities as an administrator. Besides, they'll also have the privilege to configure privacy and security controls available under Privacy Settings, IP Restrictions, and Emergency Measures in the Admin tab.
  • Major Bug Fixes:
  • In versions 9601 and 9700, SSH connections to remote systems (includes remote password reset operations) failed if Password Manager Pro was running on an Ubuntu server. This has been fixed.
  • In v9700, if RSA SecurID and Duo Security were configured as the second authentication factor in Password Manager Pro, users were unable to log into the application due to authentication error. This has been fixed.
  • In v9700, when the administrator changed the default "Server Port" under Admin >> Password Manager Pro (PMP) Server and saved the settings without providing a certificate, the PMP service did not run after server restart. This has been fixed.
  • In v9700, if AD user import was configured via LDAP integration with synchronization enabled, the Password Manager Pro accounts of a specific set of users in that AD domain were accidentally locked by the application when the sync schedule was run. This has been fixed.
  • In v9700, while trying to transfer ownership of resources from one user to another under the "Users" tab, the action was unresponsive if the username of the current owner contained the slash symbol ( / ). This has been fixed.
  • Minor Bug Fixes:
  • In v9700, when ownership of a resource group was transferred from one administrator to another, the subsequent notification email sent to configured recipients did not display the name of the new owner. This has been fixed.
  • In v9700, while configuring notifications for a specific resource group, administrators were unable to select one or more user groups as notification recipients for the following password actions—Password Expired, Password Policy Violated, Password Out Of Sync. This has been fixed.
  • In v9700, users were unable to view a retrieved password if they had earlier included a percent sign ( % ) in the "Reason for Retrieval" field while raising an access request for that password. This has been fixed.
  • From v9200 till v9700, when a user specified that they wanted to access the password "later" while raising an access request for a resource for which auto-approval of requests was configured, the corresponding email notification was not sent to the specified recipients. This has been fixed.
  • From v9200 till v9700, if a user requested access to a resource more than once with different timeframes specified for each request's password checkout period, only the timeframe of the first logged request was recognized for that user. As a result, all subsequent access requests raised by the user for the same resource were approved only with the already logged timeframe for password checkout. This has been fixed.

New in ManageEngine Password Manager Pro 9.7 Build 9700 (May 29, 2018)

  • New Features & Enhancements:
  • Additional protection in web GUI while displaying personal data
  • Form fields that contain personal data such as Username, DNS Name, Email ID, Server Name and more will henceforth be masked at all times to enhance protection. Additionally, when a specific user unmasks and views any of the masked data fields, the action captured in the audit trails with a timestamp and the IP address of the machine from which the user viewed the data.
  • Canned report to demonstrate GDPR compliance stature
  • Password Manager Pro now comes with a canned report that tells you the stature of your compliance with specific requirements listed in Chapter 3 of the General Data Protection Regulation (GDPR), in terms of how users' personal data is handled within the product. This report, apart from providing a holistic view of how personal data is handled, will also prove useful while preparing for privacy audits.
  • Provision to authorize selective administrators with privacy administration privileges
  • From v9700 onwards, a new "Authorized Administrators" option will appear under Admin >> Settings. This option can be used to authorize only the desired administrators with the privilege to view, access, and modify the following Password Manager Pro settings
  • Privacy Settings
  • IP Restrictions
  • Emergency Measures
  • Note
  • When you upgrade to v9700 from earlier versions, users with the following roles will be automatically assigned as authorized administrators:
  • Default "Administrator" role
  • Custom role with permission to access and modify "PMP Server Settings" under PMP Settings category.
  • Password protected exports
  • Administrators can now include an additional layer of password protection for export operations across Password Manager Pro. This applies to,
  • Resource and resource group exports (XLS file)
  • Audit exports (PDF and CSV files)
  • Report exports (XLS and PDF files)
  • The authorized administrator can either set a global passphrase which will be uniformly used for the aforementioned export operations or allow the users to define their own passphrase for their exported files.
  • Mandating administrator acknowledgement of data transfer while setting up integration with third party applications
  • Henceforth, when the Password Manager Pro administrator sets up integration with the services mentioned below, the administrator will be required to acknowledge the data transfer from Password Manager Pro server for each respective integration.
  • Cloud Storage - Dropbox, Box, and Amazon S3
  • Two-factor Authentication - PhoneFactor, RSA SecurID, RADIUS Authenticator, and Duo Security.
  • Support for Encryption at Rest (EAR) while using MS SQL server as the backend database
  • For Password Manager Pro installations that function with a MS SQL server as the backend database, Transparent Data Encryption (TDE) is supported henceforth to achieve EAR. TDE encrypts all the data and log files stored in the SQL server and the key used to encrypt the database is also secured further with a certificate to enhance protection.
  • Backup file encryption:
  • Database backup (.zip) files in Password Manager Pro-both on-demand and scheduled, will hereafter be encrypted with the Password Manager Pro master encryption key and stored in the destination directory securely. In case of Password Manager Pro installation running a remote MS SQL server database, the backup file will be encrypted only if the specified backup destination is within the server in which Password Manager Pro is installed and not the remote machine.
  • Privacy controls for canned reports:
  • Password Manager Pro now allows authorized administrators to configure privacy settings for canned reports. Administrators can choose from an exhaustive list of personal data, deciding whether each input in the list should be completely omitted from the reports or included as masked information.
  • IP restrictions:
  • IP-based restrictions are now supported to limit inbound connections and minimize unwanted traffic to Password Manager Pro server. Restrictions can be configured for web access, API calls, communication from native mobile applications, browser extensions, and Password Manager Pro agents deployed on target machines. The IP restrictions can be set at various levels and combinations, such as defined IP ranges or individual IP addresses. The authorized administrator can either whitelist or blacklist the set of desired IP addresses.
  • Trash can for delete operations:
  • Users and resources in Password Manager Pro can now also be moved to trash alternatively instead of permanent deletion, along with the option to restore from trash when needed. The trashed users and resources will be retained by Password Manager Pro only until the next rotation schedule is carried out for the master encryption key.
  • Purging selective session recordings:
  • Earlier, session recordings and chat logs could only be purged in bulk by configuring to delete recordings that are older than a specified number of days. From v9700 onwards, session recordings can also be individually selected under Audit >> Recorded Sessions and purged. Additionally, chat logs for a specific session recording can also be deleted while retaining the recording itself and vice versa.
  • Managing unidentified email addresses in Password Manager Pro:
  • A new provision has been added to enable administrators to track and remove unidentified email addresses in Password Manager Pro which do not belong to any of the users in the application. This provision currently allows management of unidentified email addresses which are captured in "User Sessions" audit as well as those that are configured as notification email recipients for scheduled tasks' completion statuses and license expiry alerts.
  • Emergency Measures:
  • In the rare scenario that a suspicious activity is sensed within Password Manager Pro but has not yet been identified, a set of recommended best practices that can be carried out have been added under Admin >> Manage >> Emergency Measures. The illustrative list of incident response actions give the administrator a head start on stopping all inward and outward communication to and from Password Manager Pro server respectively, such as stopping API calls, blocking agent communication, and stopping the SSHD server.
  • Under rebranding, Password Manager Pro now provides an additional option to configure and display a customizable privacy policy banner in the login page.
  • Earlier, the "Total Passwords" count displayed in the dashboard did not include resources of the type File Store, Key Store, and License Store. From v9700 onwards, the count will include the aforementioned resources as well.
  • While setting up user import from LDAP directories, Password Manager Pro administrators now have the choice to also define the corresponding attribute labels for department and location as used in the LDAP directories.
  • A new option has been added to Password Manager Pro MSP version under Admin >> General Settings >> User Management, which can be used to display the organization names of the client orgs in the organization drop down list (at the top right corner) instead of the orgs' display names.
  • The option to delete client organizations has been added to Password Manager Pro MSP version. When a client organization is deleted, all the resources and users added under it will also be deleted.
  • Bug Fixes:
  • In v9601, SSH connections to remote systems failed if Password Manager Pro was running on an Ubuntu server. This has been fixed.
  • In v9600 and v9601, due to an issue in Windows resource discovery, when the administrator tried to import OU A, OU B was wrongly imported. This has been fixed.
  • From v9000 till v9601, the password expiry date for accounts in the Passwords section was wrongly displayed in the quick info beside each account. For instance, if the expiry date for account's password was May 25, it was shown as June 25 even though it did not affect the password from expiring on May 25. This has been fixed.
  • From v9000 till v9601, the owner of a criteria resource group was sometimes unable to view the password of an account associated with a member resource in that resource group. This happened when the specific resource is owned by another user who's a member of a user group with which the criteria resource group has been shared and the former owner is not a member of that user group. This has been fixed.
  • From v8700 till v9601, if the administrator had disabled the default roles, Password Administrator and Password User using Role Filter in their instance, the disabled roles were automatically enabled when their Password Manager Pro server was restarted.
  • Earlier, user import from Active Directory groups did not work if Password Manager Pro secondary server was up instead of primary server. This has been fixed.
  • Earlier, when an additional password field was added and used as an account attribute, the option to copy the password to clipboard for that additional field was not available in the resource and account details windows as well as in the Passcard screen. This has been fixed.
  • Earlier, "Change Password" option was shown in the My Profile drop down menu for AD, Azure AD, and LDAP users even though it was not applicable to them. The option has now been removed.
  • Security Fix:
  • Earlier, PostgreSQL database password as well as the keystore password for HTTPS connections from the web server were stored in the configuration files as plain text. They have now been encrypted with AES-256 algorithm for enhanced security.

New in ManageEngine Password Manager Pro 9.6 Build 9601 (May 8, 2018)

  • Bug Fixes:
  • Earlier, while creating a custom password policy, even if the administrator had set 'No' for the requirement 'Enforce Numerals', numerals were still used in the newly generated passwords for resources. This has been fixed.
  • In v9600, when SSL was configured on the Password Manager Pro web server, the server did not start up due to an issue with the auto redirect from HTTP to HTTPS. This has been fixed.
  • Security Fix:
  • SparkGateway, which comes bundled with Password Manager Pro to enable RDP connections to target systems, has been upgraded from v5.0 to v5.6 to support CredSSP protocol v6. This latest version released by Microsoft contains security updates to address a remote code execution vulnerability (CVE-2018-0886) that existed in the protocol.

New in ManageEngine Password Manager Pro 9.6 Build 9600 (Apr 4, 2018)

  • New Features & Enhancements:
  • SQL and SSH Remote Terminal Sessions with Windows Domain accounts:
  • From v9600 onwards, users can launch SSH connections to Linux resources using Windows Domain accounts stored in Password Manager Pro's database. Remote password reset actions for Linux resources can also be configured by using a Windows Domain account for remote login to the Linux resources.
  • Provision to remotely connect to a MS SQL server using a Windows Domain account has also been added.
  • Secure Cloud Storage Options for Anytime, Anywhere Access to Passwords:
  • Provision to export and automatically synchronize the password-protected, encrypted HTML files to authorized users' Amazon S3 and Box accounts.
  • Administrators can configure automatic deletion of the exported files in the users' Amazon S3 or Box accounts after a set time period and also trigger password resets for all the resources contained in the file.
  • Active Directory - Synchronization Enhancements:
  • Version 9600 introduces a revamp to the 'Synchronization Schedules' screen under Active Directory (AD) configuration. The screen now includes a sidebar navigation tab that lists the AD domains that have synchronization schedules configured and also offers a separate view of synchronization schedules configured for users and resources respectively. The enhancements include:
  • Provision to schedule separate synchronization intervals for import of users and resources respectively, for any given domain.
  • Provision to schedule separate synchronization intervals for multiple groups in a domain, for import of users and resources.
  • Provision to schedule separate synchronization intervals for multiple organizational units (OUs) in a domain, for import of users and resources.
  • Provision to set a custom display name for groups/OUs imported from AD domains. The original AD names of the groups/OUs will also be retained.
  • Microsoft CA Certificate Signing:
  • Password Manager Pro now allows users to get certificate requests signed from Microsoft Certificate Authority, thereby facilitating complete life cycle management for certificates issued by Microsoft Certificate Authority.
  • CMDB Integration for SSL Certificates Synchronization:
  • Administrators can now sync SSL certificates stored in Password Manager Pro's repository with ManageEngine ServiceDesk Plus CMDB and map certificates to specific servers / applications in the CMDB. This allows them to monitor their usage and expiration from ServiceDesk Plus' CMDB.
  • SSL Certificate Groups:
  • This enhancement allows users to organize SSL certificates into logical groups based on various criteria and execute actions in bulk for the groups.
  • Localization Support for Turkish:
  • Introducing localization support for Turkish in Password Manager Pro's multi-language editions, in addition to Chinese, Japanese, Spanish, German, French, and Polish languages.
  • Disable Password Resets for Privileged Accounts:
  • This enhancement to account creation and edit actions under Resources tab allows administrators to disable both local and remote password resets for all or a specific set of accounts associated with a resource.
  • Administrators can now set a non-administrative role—either system-owned or custom made, as the default user role in their Password Manager Pro installation. The default role will also be assigned automatically to users imported from CSV files/AD/Azure AD/LDAP, unless manually specified otherwise by the administrator.
  • Earlier, when the Password Manager Pro server (PMP) had a firewall or load balancing configuration, the PMP audit trails showed the IP address of the firewall/load balancer instead of the IP address of the user's machine. From v9600 onwards, PMP will log the IP address of the machine, from which it was accessed, in the audit trails instead of the firewall/load balancer IP address.
  • For Password Manager Pro's MSP editions, the audit trails under Resource, User, and Task Audit tabs now also display the name of the respective MSP or client organization associated with the related operation.
  • Date based discovery filter for Microsoft Certificate Authority certificate discovery introduced.
  • Option to separately track and manage various versions of the same SSL certificate (with the same common name).
  • Option to import and map a private key to certificate.
  • Bug Fixes:
  • From v9200 till v9502, when a resource had access controls enabled and multiple users later requested access to that resource with different timeframes for password checkout, the timeframe of the last logged request alone was recognized and every user could get access to that resource only during that timeframe. This has been fixed.
  • From v9200 till v9502, when a resource has access controls enabled for a particular user group, the access controls did not apply to any new user(s) added to that user group later. Similarly, the access controls still applied to a user even after they had been removed from that user group. This has been fixed.
  • From v9000 till v9502, when users who were either Password Users or Password Auditors launched an SSH or a SQL session, the option to initiate a chat with the administrator monitoring the session was not displayed in the session terminal window for the aforementioned users. This has been fixed.
  • From v8700 till v9502, under custom roles, the permission to add resources to a resource group in Password Manager Pro was attached to the operation 'Add Resource Group'. This has been changed; the permission is now attached to the operation 'Edit Resource Group.'
  • From v9000 till v9502, under any sections of the Audit tab such as Resource Audit, User Audit etc., when the user runs a filter or keyword search for a specific set of audit trails and later tries to export the obtained results alone, the exported PDF or CSV file instead contained all the audit trails. This has been fixed.
  • From v9000 till v9502, if the users were enforced to provide a reason for password retrieval under General Settings, the users could submit a blank space in the reason field and still retrieve the password. This has been fixed.
  • Earlier, remote password reset did not work for Oracle user accounts if the respective accounts' names began with a number or a special character. This has been fixed.
  • Earlier, if a resource's DNS name contained more than a hundred characters, the corresponding Resource Actions icon did not work under the Resources tab. This has been fixed.
  • Earlier, when users tried to manually change the password for an existing account of any resource, they were able to set a password that did not comply with the password policy defined for that resource if password visibility is set to 'Show' under 'Show/hide Password'. This has been fixed.
  • Earlier, when generating certificate signing requests with SAN names, the SAN names were not updated. This has been fixed.
  • Earlier, there were issues with fetching the system locale on Microsoft CA discovery. This has been fixed.
  • Security Fix:
  • Password Manager Pro's master encryption key generation process, which was identified as being weak and vulnerable due to relatively less entropy, has now been made stronger with the inclusion of a higher entropy rate. This addresses and fixes the said vulnerability—the ability to roughly identify the character pattern used to generate the master encryption key (provided that one has direct physical access to the server in which PMP is installed).

New in ManageEngine Password Manager Pro 9.5 Build 9502 (Feb 20, 2018)

  • In v9500 and v9501, execution of password reset operations for Windows machines—via both agent-based and agent-less methods, occasionally resulted in an application server crash due to restrictions in filtering null values for 'Domain Name' fields. This has been fixed.
  • In v9500 and v9501, user import from LDAP did not work for the following LDAP server types, except MS Active Directory—Novell eDirectory, OpenLDAP, and Others. This has been fixed.
  • Henceforth, the following functions in Password Manager Pro can be carried out with PowerShell scripts instead of Task Scheduler service. The support to use PowerShell scripts has been provided as an alternative, in order to overcome the limitations of using Schtasks commands.
  • Fetching of Scheduled Tasks for Windows and Windows Domain resources.
  • Scheduled Tasks password resets for Windows and Windows Domain resources.

New in ManageEngine Password Manager Pro 9.5 Build 9501 (Jan 31, 2018)

  • In v9500, users with administrator privileges encountered a blank white screen for a few minutes when they logged into Password Manager Pro, due to product banner loading issues. This has been fixed.
  • In v9500, A remote password resets for Windows workgroup machines failed as a result of A the recent replacement of VBScript scripts with .Net API calls. This has been fixed.

New in ManageEngine Password Manager Pro 9.5 Build 9500 (Jan 12, 2018)

  • Feature Enhancements:
  • User Sessions:
  • This enhancement allows administrators and auditors to view the list of user sessions for a specified time period. A user session includes all actions performed by a user, between a specific login and logout. The view also indicates currently active sessions with the option for administrators to forcefully terminate. This feature is an addition under the Audit tab and helps administrators with fine grained monitoring and control of user activity.
  • Key Manager Plus Integration - Now available for all editions
  • From v9500 onward, all Password Manager Pro editions (Standard, Premium, and Enterprise) support Key Manager Plus integration to help enterprises take complete control of their SSH and SSL environments in addition to passwords.
  • Replication of Password Policies Across Client Organizations (MSP Edition)
  • This latest enhancement to the replication feature allows MSP administrators to quickly replicate MSP organization's custom password policies across the client organizations.
  • Bug & Security Fixes:
  • From v8700 till v9402, during Windows resource import from Active Directory (AD) via discovery function, password administrators were unable to view and set up AD Synchronization in the Windows Discovery Tasks page, although they had the permission. This has been fixed.
  • From v9000 till v9402, while moving accounts between resources, the search box provided within the destination drop down menu did not work. This has been fixed.
  • Earlier, during user import from an LDAP domain, the user groups in the domain were also wrongly identified as individual user objects and listed under Password Manager Pro's 'Users' tab. This has been fixed.
  • Earlier, with regard to LDAP authentication, users who were moved from one OU to another in their Active Directory (AD) domain could later not log into Password Manager Pro using their AD credentials. This has been fixed.
  • The VBScript scripts used for the following functions in Password Manager Pro (PMP) have been made obsolete and replaced by equivalent .NET API calls made from within the PMP application. This is to ensure the passwords never leave the PMP application space, even to Windows Task Manager or Process Explorer.
  • Local and service accounts enumeration during Windows discovery.
  • Fetching of service accounts and scheduled tasks for Windows and Windows Domain resources.
  • Password change and verification as well as associated service restarts for Windows resources.
  • Service accounts and scheduled tasks password resets for Windows Domain resources.

New in ManageEngine Password Manager Pro 9.4 Build 9402 (Dec 15, 2017)

  • Bug fixes:
  • Earlier, while editing a resource via RESTful API, changing the type of the resource was not supported. The API has now been enhanced to allow the modification of this attribute.
  • Earlier, while trying to add a new value or edit the existing value of a resource-level additional field via RESTful API, the action also reset the values of other additional fields of that resource and the fields became empty. This has been fixed now.
  • Earlier, in the MSP edition, while revoking a client org's 'Manage Permission' for a set of admins, the action could not be completed if the number of selected admins exceeded 25. This has been fixed.
  • From v9400 till v9401, shared resource groups did not show under 'Password Explorer' for administrators and users alike. This has been fixed.

New in ManageEngine Password Manager Pro 9.4 Build 9401 (Dec 11, 2017)

  • In v9400, 'Change Private key' was not working for users without Key Manager Plus license. This has been fixed now.
  • In v9400, users without Key Manager Plus license continuously received Let's encrypt renewal schedule notification mails. This has been fixed now.
  • In v9400, schedule execution failed in other organizations when running in MSP client org. This has been fixed now.
  • From v9200 till v9400, RDP remote session was not working for users having user name starting with the letter 'U'. This has been fixed now.
  • From v9000 till v9400, clicking upon 'Agent Alerts' notification, popped up 404 error. This has been fixed now.

New in ManageEngine Password Manager Pro 9.4 Build 9400 (Nov 30, 2017)

  • New Feature:
  • Key Manager Plus Integration:
  • The tight integration brings all features of Key Manager Plus right inside Password Manager Pro to provide a complete Privileged Identity Management solution.This help enterprises centrally manage, monitor, control and audit the entire life cycle of privileged passwords, SSH keys and certificates from a single user interface.
  • Security fix:
  • From v9000 till v9300, there were reflected XSS issues in the URLs 'SearchResult.ec and BulkAccessControlView.ec'. This reflected XSS issue has been fixed now.
  • Bug fixes:
  • From v9000 till v9300, 'Export Passwords' option was listed under 'Resource Actions' even when "Export/Offline Access - Allow admins and users to export password information to plain-text spread-sheet (.xlsx)" was disabled. This has been fixed now.
  • From v8700 till v9300, Users, assigned with custom roles created with the privileges of a password user, were not able to invoke the 'Join Active Sessions' action under Audit -> Remote Sessions.This has been fixed now.

New in ManageEngine Password Manager Pro 9.3 Build 9300 (Nov 18, 2017)

  • New Feature:
  • File Transfers Over Remote Desktop Sessions
  • Henceforth, in real-time Windows RDP sessions launched via Password Manager Pro's session gateway, users can securely transfer files from local machine to remote target machine, and vice versa.
  • Enhancements & Bug Fixes:
  • Password Manager Pro now uses captcha services during application login to enhance security. The users will be required to resolve a captcha when they enter an invalid username/password for five continuous login attempts.
  • Earlier, out of the remote sessions (RDP, SSH, and SQL) launched via Password Manager Pro's session gateway, one or more of the sessions at random still continued to show under the 'Active Privileged Sessions' tab even when those sessions had already been terminated by respective users. This has been fixed.
  • Earlier, the results for 'Find Out of Sync Passwords' action executed for a resource group showed that all passwords were in sync even when passwords for one or all of the Windows resources in that group were not in sync. The wrong results were captured in the audit records as well. This has been fixed.
  • Earlier, when a user clicked on the 'Forgot Password?' link in the Password Manager Pro (PMP) login screen to set a new password via email, the email could not be validated if the recipient's email address contained an apostrophe. This has been fixed.
  • From v8600 till v9200, in Azure AD user/user groups import, only a maximum of 100 users/user groups could be imported. This has been fixed to allow users/user groups import without any count limitation.
  • From v8700 till v9200, users faced blank page issues when the custom role assigned to them did not allow specific actions in that page. For instance, under dashboard provisions, if a user is allowed to access only the user dashboard and not the password dashboard, clicking on the 'Dashboard' button in the left navigation pane displayed a blank white screen upon loading. This has been fixed.
  • From v9000 till v9200, under 'Resources' tab, the users faced specific search and page navigation issues after they had accessed a resource group displayed in the 'Password Explorer' tree view. The following bugs have been fixed:
  • In case of search, when a user used the in-line search option available for 'All My Passwords' (or any other tab under 'Resources'), then navigated to a resource group via the tree view and returned back to 'All My Passwords' page, the typed-in search term and the respective results were still retained and displayed.
  • When a user navigated between pages under tabs such as 'Passwords' or 'Favorites', then clicked on a resource group via the tree view and returned back to the tab accessed earlier, the page number (2 or above) that had been selected previously was launched instead of the first page.
  • From v9000 till v9200, the global search option in the top pane did not work properly when the search term contained the ampersand sign ( '&' ). For instance, if the search term was 'AT&T', search results were returned only for 'AT', i.e. only for the characters before the sign. This has been fixed.
  • From v9000 till v9200, when the account name of a resource contained more than 140 characters, the corresponding Account Actions and Resource Actions icons did not work for that account. This has been fixed.
  • From v9000 till v9200, when the URL length of a resource was more than 700 characters, the corresponding Resource Actions icon did not work. This has been fixed.

New in ManageEngine Password Manager Pro 9.2 Build 9200 (Oct 13, 2017)

  • New feature:
  • IIS Web.config discovery:
  • Password Manager Pro can now identify the domain accounts which are used in the connection string of IIS web.config files that are stored in PMP. While changing the password of the domain accounts stored in Password Manager Pro, it can automatically update the password in the IIS web.config files.
  • Enhancements and fixes:
  • Password Access Control Workflow has been upgraded. With this update:
  • One or more user groups can be designated to approve password access requests.
  • Earlier, some users can be excluded from access control. Now, you have an option to exclude both users and user groups from access control.
  • Users can specify when they want to access the password - now or later, while making a request and can also send a reminder mail before the access time.
  • Similarly, administrator can specify when the user can access the password - now or later, while processing the request.
  • In addition, users can be enforced to provide reason for password retrieval.
  • Reminder e-mail can be sent to the administrator to approve the password request before the stipulated time.
  • A grace time of upto 60 minutes can be provided to the user when the access time ends.
  • Auto check-in time can be specified when the request is approved by the administrator.
  • Maximum time period can be specified after which the pending access request becomes void.
  • Password Manager Pro now integrates with ManageEngine ServiceDesk Plus by validating change request in addition to the ticket ID entered by the user in the ticketing system. And validated occurs only when the change ID provided is approved in ManageEngine ServiceDesk Plus.
  • Password Manager Pro enables recording of RDP remote session launched from the product and you can trace the recorded RDP remote session through the resource name, user who launched the session, time at which the session was launched. In addition, start and stop audit for RDP remote session has been enhanced now.
  • In v9000 and above, the mail notification sent to the users about the access permission shared or revoked contained blank values. This has been fixed now.
  • In v9000 and above, 'resource actions' icon was not listed for user with custom role 'edit resource'. This has been fixed now.
  • From v9200 and above, a resource can also be searched in the search column by providing the resource URL. Earlier, a resource can be searched only by providing the resource name, description or resource type.
  • In v9000 and above, configure access control deactivation for resources in bulk was not working. This has been fixed now.
  • In v9100 and above, when enabling two factor authentication - Duo security, the screen hangs at 'Initializing web client'. This has been fixed now.
  • In v8704 and above, Secondary DNS field in WindowsDomain resource type was removed. This has been fixed now.
  • Earlier, already existing resource type can be added again with change in alphabet case (lower case or upper case). This has been fixed now.
  • Earlier, addon failed to auto-fill passwords to the websites in client org. This has been fixed now.
  • Earlier, Access Snapshot was not working upon clicking 'View per page' to 50 / 75 / 100 resources. This has been fixed now.
  • Earlier, Windows discovery fails when the username / password contained angular brackets and the harmful content audit has the actual password in clear text. This has been fixed now.

New in ManageEngine Password Manager Pro 9.1 Build 9101 (Sep 27, 2017)

  • Enhancements & Fixes:
  • SparkGateway that comes bundled with Password Manager Pro has been upgraded from v4.6 to v5.0. With this update, RDP sessions can now be launched over TLS 1.2 to machines in which previous TLS versions have been disabled.
  • Earlier, while integrating Amazon Simple Email Service (SES) with Password Manager Pro under 'Mail Server Setting', secure connections over SSL or TLS could not be configured. This has been fixed.
  • From v8500 till v9100, Active Directory Single Sign-on could not be enabled if the 'Secondary Domain Controllers' field held more than 100 characters. This is now changed to accept up to 250 characters.
  • From v9000 till v9100, any resource/account/resource group access permission changes for user groups were not notified via email despite the alert configuration under General Settings. This has been fixed.
  • From v9000 till v9100, the 'Edit User' screen did not load the Duo Username for Duo TFA-enabled users. This has been fixed.
  • From v9000 till v9100, duplicate names could be assigned for two user groups by changing the name of one group in 'Edit Group Attributes' to match the other group's name. This has been fixed.
  • From v9000 till v9100, users were unable to download files stored under the 'File Store' resource type. This has been fixed.
  • When Password Manager Pro (from v9000 till v9100) was launched on Firefox 54, checkboxes weren't displayed across multiple tabs such as Resources, Users, and Groups. This has been fixed.

New in ManageEngine Password Manager Pro 9.0.0 Build 9000 (May 2, 2017)

  • New User Interface:
  • From build 9000 onwards, Password Manager Pro will switch to a new user interface (UI) in order to improve user experience. The rich, modern look of the new UI embraces the flat design, and includes enhancements to the speed and usability of the application. Users will be able to navigate between tabs quicker than before and access data without multiple page reloads, thereby equipping admins to get their jobs done faster. This simple and responsive design is optimized across both mobile and web platforms to provide a wholesome experience to the user.
  • Important Change in the Design of Criteria-based Dynamic Resource Groups:
  • From build 9000 onwards, for criteria-based dynamic resource groups, criteria will be applied only on the resources owned by the group owner and on the resources owned by the administrators who have manage permission to the group. Criteria will not be applied on the shared resources. This represents a significant change from the existing design. At present, criteria gets applied on all resources that are owned by the user who is creating the group and on the ones shared with "Manage" permission. Shared resources are being excluded in the new version. Once you move to the latest version, some resources that were part of a criteria-based dynamic group created by you would have been removed from the group due to this change.
  • In the new design too, administrators who have access to a dynamic group with "Manage" permission (henceforth known as "Full Access" permission) shall be able to add the resources owned by them to that group. That means, the resources owned by them shall become part of the dynamic group upon satisfying the criteria.
  • Note: This change was introduced in PMP 8.0 for those who installed the full version afresh. That means, for customers who have directly installed builds 8000 and above, this behavior remains the same. The above change will be felt only by customers who have been using Password Manager Pro before the 8000 build was released.
  • MIB Update for SNMP Trap Settings:
  • This version includes an update to the MIB (MANAGEENGINE-PMP-MIB), which is integral to SNMP trap configuration in Password Manager Pro. As part of the update, the OIDs used to identify the VarBinds have been revised.
  • In v7000 and above, while retrieving passwords, if the user was enforced to provide a reason as configured by the admin, the user was able to retrieve passwords from "Pass Cards" and "All My Passwords" UI by adding just a space in the reason field. This has been fixed.
  • In v8600 and above, when Azure Active Directory (AAD) authentication was configured and enabled for users, users from only one specific AAD tenant were able to log in to Password Manager Pro using their AAD credentials while users in other tenants faced login errors. This has been fixed now, by updating the value of the endpoint to which the sign-in requests are sent from Password Manager Pro.
  • In v8700 and above, role summary report could not be generated for a role if the respective role name comprised Japanese characters. This has been fixed.
  • In v8700 and above, admins using Password Manager Pro's Premium edition were unable to create API users even though XML-RPC API/SSH CLI access and related operations were allowed in the premium edition. This has been fixed.
  • In v8700 and above, if an admin disables the "Personal" tab for users by unchecking the respective option under General Settings, the option itself disappeared from view the next time when the admin accessed General Settings. This has been fixed.
  • Earlier, in MSP editions, client organizations that had been marked as favorite by respective users were not displayed at the top of the list as they should be. Instead, the client org that one user had most recently marked as their favorite was globally displayed at the top for all users. This has been fixed.
  • Earlier, while importing users from AD/Azure AD, when the admin specifies the users to be imported as comma separated values, the action resulted in error if there was spacing after the commas. This has been fixed.
  • Earlier, when users share their resource group with other users, the former faced resource group duplication issues in their UI dashboard whenever the latter added a new resource to that shared resource group. This has been fixed.
  • Earlier, while adding an account under a resource, the account could not be saved if the user had earlier enabled a custom password field under "Account Additional Fields" and entered a password containing specific special characters including Greater Than/Less Than ( "<", ">" ) symbols in that field. This has been fixed.
  • Earlier, during manual resource addition operation, the user was able to add two different accounts under the same name but different casing. However, while saving the added accounts, the second account's user-provided password was automatically replaced with the first account's password. This has been fixed.
  • Customers who upgraded to 8700 from any of the older versions faced an issue with the "Personal" tab, i.e. if they had earlier disabled the Personal tab for users, the provision was automatically enabled for users after the upgrade. This has been fixed.

New in ManageEngine Password Manager Pro 8.7 Build 8704 (May 2, 2017)

  • Security Fix:
  • In v8600 and above, after launching an RDP session, the users were able to view the shared RDP password in plain text by opening the page source of the respective session tab, even when they were not authorized to view the password. This has been fixed.

New in ManageEngine Password Manager Pro 8.7 Build 8703 (May 2, 2017)

  • Issues & Fixes:
  • Earlier, when details such as role name, description etc. were provided in Japanese while creating new user roles, the Japanese characters were not displayed in any of the corresponding role reports that were exported as PDF. This has been fixed.
  • Earlier, when a scheduled password reset was carried out for a Windows domain account after password expiry, the reset action results were at times audited as failed even though the password was successfully reset in the resource. This happened if the domain account had services and IIS app pools associated with it. This has been fixed.
  • Security Fix:
  • Earlier, when scheduled password reset was triggered for a Windows domain account, the new password of the account was printed in plain text in the logs if the Log Level setting was configured as 'DEBUG'. This has been fixed.

New in ManageEngine Password Manager Pro 8.7 Build 8702 (May 2, 2017)

  • Issues & Fixes:
  • Earlier, when users who use Password Manager Pro's Standard or Premium edition upgraded their installation to v8700 and above, features that were unrelated to the edition they use were displayed in the product GUI. This has been fixed now.
  • In v8700 and above, remote sessions launched by users with user-type roles (that is, non-administrators) were not recorded even though session recording was configured globally for all users. This has been fixed now.

New in ManageEngine Password Manager Pro 8.7 Build 8701 (May 2, 2017)

  • Enhancements & Fixes:
  • In v8700, under custom roles feature, when a group of users were moved in bulk from their current roles to an administrator-type role using "Change Roles", the operation failed during certain circumstances owing to insufficient number of administrator licenses even though adequate licenses were in fact available. This has been fixed now.
  • Earlier, when super administrators carried out edits to their own profile such as password policy or email ID changes, they lost their super administrator privilege automatically when they saved the edits; and they were reverted to their old role. This has been fixed now.
  • In v8700, when an administrator viewed the list of users who were members of a user group, the database values of the users' "Role" column were displayed in the web UI table view. This has been fixed now.
  • Security Fixes:
  • Earlier, while importing resources from a CSV file, when "Overwriting of existing resources" is enabled by a user along with a configuration setting to overwrite a resource only when it is owned by that user resources owned by other users were overwritten in certain circumstances despite the owner check. This has been fixed now.
  • A function level access control vulnerability resulted in unauthorized permission which allowed an user to lock their own Password Manager Pro account, This has been fixed now.
  • A function level access control vulnerability resulted in unauthorized permission which allowed a user to change their current role to another administrator-type role. When a user was assigned a custom role with operational scope only to "Change user roles" and no other administrator privilege, that user could change their own role to another administrator-type role that contained higher operational scope. This has been fixed now.
  • An XSS vulnerability which resulted in unauthorized permission to execute arbitrary commands was found in Password Policies feature. This has been fixed now.
  • The internal security framework used for Password Manager Pro has been upgraded to the latest version.

New in ManageEngine Password Manager Pro 8.7 Build 8700 (May 2, 2017)

  • New Features, Enhancements & Fixes:
  • Custom Roles : Option to create custom roles for users, with provision to define operational scope for each role in a fine-grained manner. You can allow or restrict operations for the custom role (from a list of 100+ options like adding resources, allowing remote access to resources, creating policies etc.) and assign the role to desired number of users. To learn more custom roles, click here.
  • In v8000 and above, while exporting password inventory report in .xls format for two or more resource groups, the report was generated for only one random group instead of all selected groups. This has been fixed.
  • In v8603 and above, when a user selected a group of resources and attempted to bulk edit one/many of the resources' attributes, there was an issue while saving the edits. Specifically, the values present in the Notes field of all accounts associated to the selected resources were automatically overwritten with a blank value, even when no edits were carried out by the user to that effect. This has been fixed.
  • In v6300 and above, while integrating Password Manager Pro with a PhoneFactor system for two-factor authentication, the option to 'Test Agent Connection' returned an error if the user had manually specified account credentials and agent service URL (this issue did not occur when the credentials had been stored in Password Manager Pro). This has been fixed.
  • In v8500 and above, when a password user tries to export in plain-text the resources in a resource group shared with him/her, the exported spreadsheet (.xlsx) was blank. This has been fixed.
  • In v8505 and above, the 'Copy to Clipboard' option across the GUI did not work in Chrome browser. This has been fixed.
  • In v8601 and above, when a user tried to update password for scheduled tasks from Password Manager Pro, the reset failed due to a double quote missing in the reset command. This has been fixed.
  • Earlier, users were unable to launch RDP connections from Password Manager Pro's web-interface when the respective username contained a space or the password contained a percent sign ( % ). This has been fixed.
  • Earlier, when details such as name, description etc. were provided in Japanese for resources, the Japanese characters were not displayed in the PDF version of Canned and Query reports generated for the respective resources. This has been fixed.
  • Earlier, in the MSP edition, there was a configuration issue with the Replicate Settings option available under Organization actions. The issue caused the User Group Settings to replicate time and over in the client org, with respect to the number of times the user clicks on Replicate Settings. This in turn interfered with the workflow of various options under User Group Settings. This has been fixed.

New in ManageEngine Password Manager Pro 8.6 Build 8604 (May 2, 2017)

  • Security Fixes:
  • In v8601 and above, users making use of LDAP authentication with two-factor authentication enabled, were able to access their Password Manager Pro account by supplying only the username for LDAP authentication and thereafter the valid second factor credentials. This was possible because when anonymous binding is enabled, LDAP server allows connection without credentials, if one knows the LDAP username. This issue has been fixed.

New in ManageEngine Password Manager Pro 8.6 Build 8603 (May 2, 2017)

  • Enhancements & Fixes:
  • Bulk edit option is now available for resources, which allows the administrator to select several resources and edit them in bulk at the same time.
  • Username mapping is now available for two-factor authentication options such as Duo Security and PhoneFactor. This option allows you to map usernames between Password Manager Pro and two-factor authentication services listed above.
  • Earlier, integrity checks for password synchronization once enabled was carried out for all passwords on a daily basis by default. The administrator could only adjust the time at which the check should be carried. Henceforth, integrity checks can be scheduled to be run at desired time intervals.
  • Earlier, newly configured mail server settings could not be successfully saved if any of the given e-mail ids consisted of '-' (hyphen). This has been fixed now.
  • Earlier, in the Japanese version of Password Manager Pro, text inputs in the 'Reason' field syslog messages sent from the tool were either incomplete or comprised of garbled characters. This has been fixed now.
  • In v8500 and above, when resources with file attachments were shared with password users, the users were unable to download the attachment. This has been fixed.
  • Security Fixes:
  • A function level access control vulnerability resulted in unauthorized permission to edit Password Manager Pro's default resource types. This has been fixed now.
  • Earlier, if the option 'unique password generated through email' is configured for two-factor authentication in Password Manager Pro, the OTP generated and sent to a user's email id during a login attempt did not expire instantly upon one-time usage. The OTP could be reused multiple times for login from different systems as long as the primary login session remained active. This has been fixed now.
  • In order to negate the possibility of DOS attacks, threshold limits have been introduced for HTTP operations (using POST method) from the web console. The threshold limits restrict the number of times that a particular HTTP operation can be carried out per minute from a user ID.

New in ManageEngine Password Manager Pro 8.6 Build 8602 (May 2, 2017)

  • Bugs & Security Fixes:
  • In v8600 and above, when an administrator changed the web-server port number under
  • Admin-->Server Settings, the action caused a service failure after a restart. This issue has been fixed.
  • A function level access control vulnerability resulted in unauthorized permission to view other users' personal passwords stored under a specific category, when the option "Allow users to create their own passphrase" is disabled under General Settings. This has been fixed now.

New in ManageEngine Password Manager Pro 8.6 Build 8601 (May 2, 2017)

  • New Features:
  • Lock Password Manager Pro Users:
  • Option to temporarily prevent any user from accessing Password Manager Pro by locking down the respective account. The user accounts can be unlocked anytime, with all user settings intact including share permissions.
  • New REST APIs:
  • To edit resources.
  • To edit/delete accounts
  • Support for Duo Security Two-factor Authentication
  • Support for Duo Security two factor authentication for login to Password Manager Pro. Already, Password Manager Pro supports Google Authenticator, PhoneFactor, RSA SecurID, a one-time, randomly generated unique password, and any RADIUS-compliant two factor authentication mechanism as the second level of authentication for two factor authentication.
  • Enhancements:
  • Add Secondary Domain Controllers to a Windows Domain Resource
  • While creating a Windows Domain resource, users can add the DNS Name / IP Address details of secondary (or multiple) domain controllers associated with the resource. Once added, they can also auto log on to all associated domain controllers using the same Windows Domain account.
  • MSP Edition:
  • Earlier, the "Import Organization from CSV file" feature did not provide the option to attribute an "Account Manager" for the organization during the import itself. As a result, once organization details were imported from the CSV file, the MSP admin had to separately assign an administrator in Password Manager Pro as the Account Manager. Henceforth, an Account Manager column containing the administrator "username" can be added in the CSV file itself and directly attributed to the new organization during import.
  • Earlier, when the administrator configured "Replicate settings across client orgs," the saved settings were applicable only for new client orgs and not for existing orgs. As a result, resource/user groups, share settings, and additional fields were not replicated in the existing orgs. Now, a new option has been introduced to sync the newly configured replication settings (except additional fields) across existing client orgs as well, either all or desired.
  • While creating new users via RESTful API, they can now also be added to a new or existing user group.
  • Earlier, while adding a new resource with Password Manager Pro via RESTful APIs, API users had default permission to specify another existing user as the resource owner. The API user could also edit a resource owned by other users. Now, an option has been introduced to disable API users from adding/editing resources under other user's ownership.
  • Earlier, while adding a new Windows Domain resource, the "Configure password reset for associated service accounts and IIS AppPool accounts" section did not give further options for the user to enable/disable password resets separately for service accounts, scheduled tasks, and IIS AppPool accounts. Password resets could be configured either for all or none of them, regardless of whether services/IIS AppPools were run using the domain account. Now, new options have been introduced which allows the user to exclusively choose required password resets"among service accounts, scheduled tasks, and IIS AppPools as well as service restart options.
  • Earlier, when password resets for Windows Scheduled Tasks were carried out, users faced version compatibility issues for Task Scheduler if the target Windows server edition was different from that of server in which Password Manager Pro was running. To solve such platform issues, the Scheduled Tasks password reset mechanism has been enhanced to also support Task Scheduler 2.0.
  • Earlier, when two-factor authentication (TFA) was enabled, Password Manager Pro's login screen asked for the username first, and both primary password and TFA credential were requested together in a fresh second screen. Henceforth, the user has to input both username and password (first level of authentication) in the login screen. Only when the primary authentication succeeds, the user will prompted for the TFA credential in a new screen.
  • Bug Fixes:
  • In v8500 and above, while importing resources from Active Directory under "Resource Discovery" option, comma separated values entered in the "Resources to import" field were not imported properly. Only the first value was imported. This has been fixed now.
  • In v8600, when a user group was restricted from storing their personal passwords in Password Manager Pro, the users of that group were unable to retrieve their enterprise passwords. This happened only when the global option to manage personal passwords was enabled under General Settings, but disabled for that specific user group. This has been fixed now.
  • Security Fixes:
  • A function level access control vulnerability resulted in unauthorized permission to edit Password Manager Pro's pre-defined password policies (Strong/Medium/Low/Offline Password Fil). In addition, the vulnerability also allowed the deletion of the password policy that has been set as default. This has been fixed now.

New in ManageEngine Password Manager Pro 8.6 Build 8600 (May 2, 2017)

  • New Features & Enhancements:
  • Azure AD Integration: Introducing out-of-the-box integration with Azure Active Directory (AD), which allows users to login to Password Manager Pro with their Azure AD credentials, in both Windows and Linux platforms. The integration also allows import of users and user groups from Azure AD to Password Manager Pro, and keeps data synchronized through Azure AD sync schedules.
  • Query Reports: This new addition to the Reports section now allows administrators to construct reports by writing their own SQL statements. The statements can be used to directly query the Password Manager Pro database and fetch required information to address unique reporting requirements.
  • Store Recorded Sessions in an External Location: Video recordings of RDP, SSH, Telnet, and SQL sessions will hereafter be stored in an external location, instead of Password Manager Pro database. Users can configure two external locations, one primary and another backup, where recorded sessions will be stored automatically once the operation is audited in Password Manager Pro, provided there is connectivity between the configured locations and Password Manager Pro server. For earlier recorded sessions stored in Password Manager Pro database, export options are given to move them to the configured external location.
  • Purging of Recorded Sessions now available, as a separate operation: Earlier, video recordings of RDP, SSH, Telnet, and SQL sessions could not be purged separately. The sessions could be purged only as a part of user audit purge. But, purging user audit records just to remove sessions also removed the operations details such as user account used to launch session, date and time, and more. Now, there are alternate options to configure purging of recorded sessions alone and retain the audit details of the operation.
  • Earlier, when the SSL certificate for the server was changed, RDP sessions could not launched automatically and the user had to manually install the certificate again to initiate a session. Now, the issue is fixed and new certificates will be automatically verified when RDP sessions are launched.
  • Bug & Security Fixes:
  • Server JRE that comes bundled with Password Manager Pro is upgraded from v1.7.0_71 to v1.8.0_102 due to security vulnerabilities in the older version. PostgreSQL and Tomcat server have also been upgraded to the latest versions 9.5.3 and 8.0.20 respectively.
  • Maverick Legacy libraries used for SSH CLI in Password Manager Pro have been upgraded to the latest versions.
  • OpenSSL libraries used in Password Manager Pro have been upgraded from 0.9.8g to 1.0.2j, the latest version released with vulnerability fixes.
  • Reflected and stored XSS vulnerabilities which resulted in unauthorized permission to carry out critical operations were found in Landing Server configuration, Rebranding, and Reports features. This has been fixed now.
  • A vulnerability which resulted in unauthorized permission to delete Default Resource Types in Password Manager Pro has been fixed.
  • A CSRF vulnerability, which resulted in unauthorized permission to change the default resource type set for any resource, has been fixed.

New in ManageEngine Password Manager Pro 8.5 Build 8505 (May 2, 2017)

  • Enhancements & Bug Fixes:
  • Option to trigger a bulk password reset in one click for all the resources that a specific user has access to, i.e. resources owned by or shared with that user. This allows the administrator to reset all passwords related to a specific user in case they leave the organization and then transfer those resources to another user.
  • While evaluating Password Manager Pro with the 30-day trial edition, users can now switch instantly between the different product editions available (Standard / Premium / Enterprise) and test the desired edition.
  • In Windows account discovery feature, an additional check has been introduced which allows the user to choose not to import any disabled computer account in the Active Directory during the discovery process. The user also has an option now to identify existing resources in Password Manager Pro that have been marked as disabled in AD and delete them.
  • Resources and groups can now be imported directly from KeePass (1.x and 2.x) to Password Manager Pro.
  • Earlier, when cross-domain authentication is used for Windows discovery tasks, local accounts and service accounts were not enumerated from the selected domain. This issue is fixed now.
  • A new report named "Unshared Passwords" report has been added to the 'Canned Reports' section. The report lists all the passwords that have not been shared with any user in Password Manager Pro.
  • Bug & Security Fixes:
  • Earlier, password integrity checks failed for certain target systems in agent mode as Password Manager Pro server reported connection failure. This issue has been fixed now.
  • Earlier, 'Rebranding' settings could not be edited when Password Manager Pro web-interface is connected using Internet Explorer. This issue is fixed now.
  • In 'Personal Passwords' section, after a custom category is set as default, users could not add new accounts or delete existing accounts in that particular category. This issue is fixed now.
  • In v8500 and above, new resource addition operations could not be completed successfully if the DNS Name / IP Address field contained the character "_" (Underscore). This issue is fixed now.
  • Earlier, Windows account discovery tasks could not be completed if the admin password supplied to carry out the operation contained a double quote ("). This issue is fixed now.

New in ManageEngine Password Manager Pro 8.5 Build 8504 (May 2, 2017)

  • Enhancements & Bug Fixes:
  • Earlier, upgrade packs could be applied only to Password Manager Pro's primary installation, and high availability had to reconfigured every time after the upgrade. Henceforth, upgrade packs can be directly applied to the secondary installation as well, without any need to reconfigure high availability.
  • In v8500 and above, when Password Manager Pro server was restarted, personal password management option was getting enabled even in cases where it had been disabled by the administrator. This has been fixed.
  • Earlier, there were AD sync issues while importing users and resources from different domains. Resources/users from the wrong domain were imported for a few sync schedules when they were run again after the first import operation. This issue is fixed.
  • Earlier, in the MSP edition, while providing a user group with 'Manage Organization' permission for different orgs, only 100 organizations could be allotted to that user group. This limit has been removed now.
  • In v8500 and above, while adding a new account under a resource, the add operation could not be successfully completed if the 'Notes' field contained more than 230 characters. This issue is fixed.
  • In v8500 and above, whenever a password is checked in by a user, the audit log for the check in operation did not properly display the resource name (if the name contained characters like ' a m p & ' ). This issue is fixed.
  • Earlier, for any resource group, if the option 'Reset passwords upon expiry' was enabled, the option did not work for the resources within the group for which access control had been configured. This issue is fixed.
  • In v8500 and above, while adding a Linux resource, the add operation could not be completed if 'Private Key' field was left blank. This issue is fixed.
  • Bug & Security Fixes:
  • Earlier, clear/copy to clipboard actions in the GUI were carried out with Flash support. For security purposes, Flash elements have been removed for these actions and support is now provided through JavaScript.

New in ManageEngine Password Manager Pro 8.5.0 Build 8503 (Aug 31, 2016)

  • FEATURE ENHANCEMENTS / BUG FIXES:
  • Earlier, when a domain admin account was shared with users for RDP auto logon to related domain member machines, the users could use that domain account credentials to log in to the domain controller as well. Now, while sharing domain admin accounts with users for auto logon purposes, an optional check is given to prevent RDP connections to the domain controller resource.
  • A new check has been introduced, while adding a Windows resource, to restrict users from using the local account of that resource to launch RDP connection, and instead use only the domain account to connect to the resource.
  • Earlier, when the last remaining user in an organization unit (OU) was removed in AD, the same user did not get removed from the corresponding user group in Password Manager Pro. This issue is fixed.
  • Earlier, in the "Show Passwords" table under "All My Passwords," the selected column sort order did not persist for non-admin users once they navigated to other tabs. This issue is fixed.
  • In Password Manager Pro Japanese edition, audit log for the operation 'Discovery Task Deletion' was not captured properly in the audit records. This issue is fixed.
  • Earlier, under Passcard option, when the provided link is opened to access the concerned account, the password could not be viewed properly if the Resource Name or Account Name shown in the GetPasscard page contained a "space." This issue is fixed.
  • Earlier, for Add Resource operations, account addition step failed if the concerned account's password field contained specific characters (). This issue is fixed.
  • Earlier, when users tried to reset Google Authenticator settings from the Password Manager Pro login page, the option did not work due to case-sensitive issues or if the username contained '' (Backslash). This issue is fixed.
  • In v8500, users were unable to add new resources under the pre-defined type 'PostgreSQL,' if they had earlier created and saved 'PostgreSQL' as a custom resource type. This issue is fixed.
  • In v8303, while importing OUs from Active Directory, all the resources in the 'Default Group' in Password Manager Pro were automatically removed if the name of any of the OUs contained a comma (,). This issue is fixed.
  • Earlier, in the UI screen, Admin-->Add Resource-->Add Accounts, when an account was added, password of the added account was partially revealed along with the account name in the display box beneath. This happened if the password contained both double quotes (") and greater-than sign (>), in that order. This issue is fixed.
  • Earlier, under "Scheduled Password Reset," while setting Password to use, the option "Assign the same password to all user accounts, but change it during every schedule" did not work properly. Instead of a same password, unique passwords were set for each account. This issue is fixed.
  • Earlier, while using RESTful API to add or modify a resource, the users could not use the characters, '' in the account password. This limitation has been removed now.

New in ManageEngine Password Manager Pro 6.9.0 Build 6901 (Jul 1, 2013)

  • New Features / Enhancements:
  • Support for launching PMP web-interface in Internet Explorer 10
  • The implementation procedure for "Custom Listener", which enables providing your own implementation for Password Reset Listener, has now been simplified with the enhancements in the GUI. You need not have to edit the configuration files in PMP manually to enter the details about the implementation class. These details can now be provided through entries in GUI
  • Enhancements to bolster the overall security posture of the product
  • Bug Fixes:
  • Earlier, when the administrator had restricted the users from viewing the passwords in plain-text when auto logon had been configured, in certain specific scenarios, there were issues in retrieving passwords even when auto logon had not been configured. This has been fixed.
  • Restrictions on the usage of weak ciphers in the product

New in ManageEngine Password Manager Pro 6.5 Build 6503 (Apr 5, 2012)

  • New Features/Bug Fixes/Changes
  • Encryption Key Rotation: Provision to change the master encryption key either periodically as a best practice or at suspicion of key compromise. Fully automated steps to regenerate new key, decrypt all data with old key, encrypt them with new key and securely storing the new key.
  • User Preferences Setting: PMP users can now set individual preferences for what view should be loaded by default in the 'Home', 'Resources', 'Audit' and 'Reports' tabs in the web user interface.

New in ManageEngine Password Manager Pro 6.5 (Apr 5, 2012)

  • New Features & Enhancements:
  • No-Frills Auto Logon for Launching Windows RDP and SSH Remote Terminal Sessions
  • Leveraging the power of HTML 5, PMP 6.5 brings the first-in-class auto logon mechanisms for launching Windows RDP, SSH and Telnet sessions. While current solutions require inconvenient and insecure methods like end-point agents, helper programs at user desktop and browser plug-ins, the only requirement for PMP's cutting-edge solution is a HTML 5 compatible web browser. Users can launch highly secure and completely emulated Windows RDP, SSH and Telnet sessions from within the browser with a single click, not requiring any access to passwords
  • Being HTML 5 compatible, users can launch Windows RDP and SSH sessions also from browsers in their tablet devices like iPad
  • Provision for authenticating both with the local accounts as well as domain accounts for the launched Windows RDP sessions
  • A new sub-tab named 'Auto Logon' has been introduced in Home Tab for easily locating the remote accounts and quickly launch one-click sessions
  • Secure, Offline Access to Passwords with Auto Sync:
  • Support for secure, offline access to passwords. Users will get an option to export the passwords in the form of an encrypted (AES-256 encryption) HTML file, which can be opened in browsers for offline access
  • Provision to automatically synchronize the exported HTML file to users' mobile devices through Dropbox. From a single action in PMP user interface, the offline file lands in the users' Dropbox app in their smart phones or tablet devices
  • Admins can configure PMP to automatically delete the exported files to users' Dropbox accounts after a set time period
  • Admins can configure all passwords that were exported to be automatically reset in the remote systems after a set time period
  • New Resource Types for Remote Password Synchronization:
  • Support for remote password reset and verification of VMWare ESXi and HP iLO resources
  • Custom Fields:
  • Provision for creating additional fields to store file type input. Upto 4 files of any type can be attached to every resource and every account within a resource
  • Bug Fixes & Changes:
  • The option to restrict the users from exporting passwords in plain-text has been moved from 'General Settings' to "Admin >> Customize >> Export Passwords - Offline Access" GUI. The option is also available in 'User' and 'User Group' tabs
  • Earlier, there were issues in displaying custom fields when creating/editing resources. This has been fixed.
  • In the GUI to create copies of resources/accounts and in the GUI to move accounts from one resource to another, the names of resources and accounts will henceforth be shown in alphabetical order
  • Earlier, in some specific scenarios (where authentication was required) there were issues in sending emails from PMP. This has been fixed.
  • Earlier, in the case of auto logon helper (browser plug-in deployment model) there was an issue in launching direct connection to target systems. This has been fixed.
  • Earlier, there were issues in launching PMP web-interface in Firefox 11. This has been fixed.

New in ManageEngine Password Manager Pro 6.4 Build 6404 (Apr 5, 2012)

  • New Features / Bug Fixes / Changes
  • Automatic Approval in Access Control Workflow
  • Provision for automatic approval of password access requests. Users need not have to wait for approval by authorized administrators while going through the access control process.
  • RADIUS Server Authentication
  • RADIUS server can now be integrated with PMP for leveraging RADIUS authentication.
  • List of Super Administrators
  • List of all super administrators will be displayed in the information bar to all administrators, password administrators and auditors

New in ManageEngine Password Manager Pro 6.4 Build 6403 (Apr 5, 2012)

  • Bug Fixes / Changes
  • Invoking auto logon helper in turn downloads a browser addon file. The SSL certificate that ensures trustworthiness of the addon has now been renewed.
  • Earlier, user group activity report was not displayed properly on the dash board. This has been fixed.

New in ManageEngine Password Manager Pro 6.4 Build 6402 (Apr 5, 2012)

  • New Features / Enhancements:
  • Password Manager Download
  • Dual encryption of passwords and files for extra security. Sensitive data are now encrypted once in the application (AES 256-bit) and once in database
  • PMP can now be set-up to run in FIPS 140-2 compliant mode where all encryption in PMP is done through FIPS 140-2 certified systems and libraries
  • Provision to prevent the execution of malicious code/script in the application to combat cross-site scripting
  • Password Activity Report enhanced with details on the list of resources for which access control workflow has been activated/deactivated and also the resources for which access control workflow has not been configured
  • New report depicting the resources / passwords that are not part of any resource group
  • Provision to check integrity of passwords of a resource group with support for integrity verification on-demand & scheduled
  • Bug Fixes / Changes:
  • Earlier, two options were provided for managing encryption key in PMP - you were allowed to either leave it to be managed by PMP or move it to a secure location / external drive and manage it yourself. Now, the option of leaving it to be managed by PMP has been removed. PMP does not allow the encryption key to be stored within its installation folder. This is done to ensure that the encryption key and the encrypted data, in both live and backed-up database, do not reside together. It is strongly recommend that you move and store this encryption key outside of the machine in which PMP is installed - in another machine or an external drive.
  • Earlier, when exporting the personal passwords, the custom fields were not shown in plain-text. This issue has been fixed.
  • Earlier, through 'Admin >> Server Settings', when the PMP server port alone was changed, it threw an error. This has been fixed
  • UTF-8 encoding support in MS SQL server

New in ManageEngine Password Manager Pro 6.4 Build 6401 (Apr 5, 2012)

  • New Features / Enhancements:
  • Password Manager Download
  • MS SQL Server as Backend Database
  • Support for MS SQL server as the backend database in PMP.
  • High Availability Support with MS SQL Server
  • Uninterrupted access to passwords by deploying redundant PMP servers and MS SQL database instances
  • AES 256 Encryption
  • Support for AES 256 encryption for sensitive data when using MS SQL server as backened
  • Remote Password Reset of LDAP Servers
  • Remote password reset support for LDAP servers belonging to the types Microsoft Active Directory, OpenLDAP, Oracle Internet Directory and Novell eDirectory
  • Password Reset Schedules
  • Option for assigning the same password to all the accounts of a group of resources and changing the password automatically during every schedule
  • PMP Agents
  • Prior to 6400, some of the communication between PMP server and agents was initiated by the server, which required the agents to keep a TCP port open. To eliminate this risk and the need to manipulate firewall rules to allow traffic to a non-standard port on the agent side, the communication model is changed where the agents always initiate communication with the server. The agents periodically check for tasks by opening a secure connection with the server and no longer need to have a port open in the system they are installed.
  • LDAP - PMP User Database Synchronization
  • Whenever new users get added to the LDAP, provision to create synchronization schedules and automatically add the users to PMP and keep the user database in sync.
  • Active Directory
  • Support for using the same user credential to import information from multiple domains, based on the privileges and trust setup in AD.
  • Copy Resources
  • Provision to create copies of one or more resources to facilitate easy addition of identical resources
  • Copy/Move Accounts
  • Provision to copy a single account or multiple accounts of a resource and adding the under one or more resources
  • Provision to move an account or multiple accounts of a resource to a different resource or resources
  • Configuring Server Settings, SSL Certificates through GUI
  • Support for changing the PMP server port and SSL certificates from PMP GUI. This eliminates the need for manually editing the configuration files
  • Custom SSH/Telnet ports
  • Support for using any custom port for SSH and Telnet for connecting to remote resources
  • Instant Backup
  • Support for taking one-time backup of PMP database anytime
  • Performance Enhancements
  • The client responsiveness in 'Home' tab and 'Resources' tab have been optimized
  • Changes / Bug Fixes
  • Earlier, there was an option to send notifications to users after importing them from Active Directory. This option has now been removed.
  • Earlier, in LDAP user import, the OU and other details entered were not persisted. Now, the details are saved and displayed
  • Earlier, while creating scheduled tasks for custom reports, the option to send the report to the users specified under 'other users' did not take effect. This has been fixed.
  • Earlier, the password reset of Ubuntu resources did not work when 'sudo' had been used. This is fixed
  • In Internet Explorer, there was an issue in auditing the reason entered by the users for retrieving a password using auto logon helper. This has been fixed
  • Earlier, there were issues in editing the properties of resource groups. This has been fixed.
  • The issue in generating AD user schedules report as a PDF has been fixed
  • The issue related to exporting personal passwords as XLS has been fixed
  • In PMP build 6400, the share permissions to the user groups imported from Active Directory did not take effect. This has been fixed.
  • In certain scenarios, generating the 'User Access Report' as a PDF did not work. This has been fixed
  • Earlier, when password access control had been enabled, in certain scenarios, when a user made a request to access a password, there were issues in sending email notifications for approval to the administrators. This has been fixed.
  • Earlier, in High Availability set up with MySQL, when the slave database was restarted, PMP raised an alert stating High Availability was not alive. Now, in scenarios like this, PMP will double-check the status before raising the alert
  • In personal password management, the issue related to deleting the personal categories has been fixed

New in ManageEngine Password Manager Pro 6.2 Build 6200 (Mar 8, 2010)

  • New Features / Enhancements
  • SIEM Integration:
  • Provision for generating SNMP traps and Syslog messages upon the occurrence of any activity/event - be it password access or modification or any other activity performed in the PMP application. The traps/syslog messages can be sent to the SIEM tools, which can thoroughly analyze these events, correlate them with other network events and provide informative, holistic insights on the overall network activity.
  • Two Flavours of APIs for A-to-A Password Management:
  • Completely revamped provisions for Application-to-Application Password Management, which help eliminate hard-coded passwords in enterprise environments. PMP provides two flavors of the API - a comprehensive application API based on XML-RPC over HTTPS and a command line interface for scripts over secure shell (SSH), using which any enterprise application or command line script can programatically query PMP and retrieve passwords to connect with other applications or databases.
  • Local Service Account Password Reset:
  • Provision to find and reset all the local account passwords used for services and scheduled tasks in Windows resources
  • Enhancements in Bulk Password Reset:
  • Provision for bulk password reset by selecting multiple resources / resource groups
  • Provision for bulk update of passwords in PMP database alone without updating on the actual resources
  • Reports:
  • Enhanced dashboard reports providing details on currently logged in users
  • Provision to export all reports in '.xls' format
  • High Availability:
  • Enhancements in High Availability setup with provision for alerts on failure events
  • Bug Fixes / Changes:
  • Earlier, after carrying out a search operation, if one accessed the 'Enterprise Passwords' tab, while an empty page was shown in Firefox, a warning page came up in Internet Explorer. This issue has been fixed now
  • Earlier, in Password Request-Release workflow, when the time limit for administrator approval was set as '0' indicating indefinite time period, the approval time period ended after some time. This has been fixed now
  • Earlier, in certain cases, Windows remote password reset and password integrity verification failed. It has now been fixed
  • Earlier, while implementing concurrency control in Password Request-Release workflow, the maximum time period up to which the password was to be available exclusively for a particular user was specified in hours. This has been changed to minutes to enable granting of exclusive privilege less than one hour
  • Earlier, the view length of entries (passwords/resources) in PMP web-interface was not user-specific. It has been made user-specific now.
  • Entries in password explorer tree in the 'Home Tab' are now sorted alphabetically
  • Provision to control 'Manage Share' permissions for criteria-based resource groups
  • Earlier, Single SignOn worked only with NTLM-v1. Now, it works with NTLM-v2 through integration with a third party library named 'Java Enterprise Security Provider Authority' (Jespa), which provides advanced integration between Microsoft Active Directory and Java applications
  • Earlier, MD5 algorithm was used for hasing the PMP user passwords for local authentication. Now, SHA 512 is being used.

New in ManageEngine Password Manager Pro 6.1 (Jun 20, 2009)

  • Nested Resource Groups
  • Option to arrange and maintain resource groups in hierarchical structure (groups, sub-groups) for navigational convenience
  • Password Explorer
  • 'Home' tab re-arranged in an intuitive way to provide easy access to the passwords owned and/or shared. The explorer contains the following components:
  • All My Passwords
  • My Recent Passwords
  • My Favourite Passwords
  • Nested Resource Group Tree
  • Remote Password Synchronization for Juniper Netscreen Devices
  • Support for changing the privileged passwords of remote Juniper Netscreen devices from PMP GUI
  • Templates for Customizing Email Notification Content
  • By default, PMP has a specific content for the email notification for various password actions. If you want, you can customize the content and have your own content.
  • Export Passwords of Resource Groups
  • Option to export the passwords of specific resource groups alone
  • Bug Fixes & Changes
  • MySQL version upgraded from 5.0.36 to 5.079
  • Earlier, when there were large number of passwords, loading of the dashboard took some time. This has now been optimized
  • Earlier, there were issues in carrying out password synchronization / verification using a single account in Linux. This has been fixed.
  • Earlier, when Active Directory authentication was enabled, there were problems in logging in to PMP using the local authentication when a AD user was deleted. This has been fixed.