Version 3.29 (September 2026)

Prev Next

Release information

Version numbering

Because OneSpan Authentication Server is a fundamental back-end part of the OneSpan cloud authentication services, i.e., OneSpan Cloud Authentication (OCA) and Intelligent Adaptive Authentication, the product versions of cloud and on-prem versions are aligned.

The cloud authentication services and the OneSpan Authentication Server on-prem product share parts of the same code base, but the cloud services naturally receive updates earlier and more frequently. Cloud releases use the third field of the product version (also called patch version) to indicate evolving product development. When a new on-prem version is released it usually consolidates and includes all enhancements and updates of the previous cloud releases. After an on-prem release, the second field of the product version (also called minor version) is increased and the patch version is reset to zero.

For you as on-prem customer this has no practical impact, except that the first release of a new product version may use a patch version higher than zero. For instance, the first on-prem release of 3.29 is 3.29.1 instead of 3.29.0.

Supported operating systems

OneSpan Authentication Server 3.29 supports the following operating systems:

Microsoft Windows

  • Windows Server 2025

  • Windows Server 2022

  • Windows Server 2019

Linux

  • Red Hat Enterprise Linux (RHEL) 9, 64-bit (version 9.8 or later if you want to use MariaDB 11.8)

  • Red Hat Enterprise Linux (RHEL) 8.10, 64-bit

  • Rocky Linux 9, 64-bit (version 9.8 or later if you want to use MariaDB 11.8)

  • Rocky Linux 8.10, 64-bit

  • Ubuntu Server 24.04 LTS, 64-bit  NEW 

  • Ubuntu Server 22.04 LTS, 64-bit

Supported ODBC databases

  • MariaDB 11.8.6 LTS (included as embedded database)  NEW 

    If you install the embedded MariaDB database, the DBeaver 26.0 database tool is also installed.

    OneSpan Authentication Server is fully compatible with data-at-rest encryption as provided by MariaDB.

  • Oracle Database 19c

    OneSpan Authentication Server is fully compatible with Transparent Data Encryption (TDE) as provided by Oracle Database to protect data at rest (tablespace encryption).

  • PostgreSQL 17.9  NEW 

    OneSpan Authentication Server has been tested with Transparent Data Encryption (TDE) as provided by the Percona TDE extension to protect data at rest (tablespace encryption).

  • Microsoft SQL Server

    • Microsoft SQL Server 2025  NEW 

    • Microsoft SQL Server 2022

    • Microsoft SQL Server 2019

    • Microsoft SQL Server 2017

    OneSpan Authentication Server supports the SQLServer AlwaysOn Availability Groups feature for Microsoft SQL Server.

    OneSpan Authentication Server is fully compatible with Transparent Data Encryption (TDE) as provided by Microsoft SQL Server to protect data at rest.

    OneSpan Authentication Server was tested with the following ODBC drivers:

    • Microsoft ODBC Driver 18.6 for SQL Server

    • Microsoft ODBC Driver 18.3 for SQL Server

    • Microsoft ODBC Driver 17.7 for SQL Server

    The required and supported ODBC driver version for each SQL Server version depends on your specific environment. For more information, refer to the following (last access May 8, 2026):

On Linux, OneSpan Authentication Server requires unixODBC to be installed and properly configured. It is your responsibility to install unixODBC and keep it up to date.

Supported browsers (Administration Web Interface)

The Administration Web Interface supports the following browsers:

  • Google Chrome

  • Mozilla Firefox

  • Microsoft Edge

The Administration Web Interface supports all browser versions currently supported by the respective vendors.

Supported web servers (Administration Web Interface)

The Administration Web Interface can be run on these web application servers (based on the respective JRE):

The OneSpan Authentication Server product CD contains a version of Web Administration Service adapted for Open Liberty and WebSphere Liberty for manual deployment.

Supported authenticators

OneSpan Authentication Server supports a wide range of software and hardware Digipass authenticators provided by OneSpan. For a list of available authenticators, see List of authenticators.

Other new third-party products

Software libraries

The software library lists are not exhaustive and include the most significant and security-relevant updates only. CVE references are provided for informational purposes only and do not imply that the corresponding vulnerabilities were exploitable in the product. For a complete overview, refer to the third-party dependency files included with the installed product.

OneSpan Authentication Server now includes the following (updated) third-party libraries:

Administration Web Interface now includes the following (updated) third-party libraries:

Utilities

This version now requires the following products to be installed:

  • For system monitoring with SNMP:

    • On Windows: Net-SNMP 5.9.5.2 (included)  NEW 

      Fixes: CVE-2025-68615

    • On supported Linux environments, install the Net-SNMP version that comes with your Linux distribution.

OneSpan authentication platform

OneSpan Authentication Server 3.29 integrates and uses Authentication Suite Server SDK 4.0.2 (formerly OneSpan Authentication Server Framework).

This version is a major upgrade and introduces breaking changes. Once BLOB data is processed by this version, it cannot be processed by any version earlier than 3.27 anymore.

Upgrade path

OneSpan Authentication Server supports direct upgrades from 3.24 or 3.28 to version 3.29 on the supported operating systems.

This version introduces database schema updates to the user and authenticator tables (see New authenticator status flag and Bulk Cleanup DIGIPASS wizard improvements). In environments with large amounts of user and authenticator data, these changes can significantly increase the overall time required to complete data migration.

For instance, for a database that contains approximately 2,000,000 user records and 8,000,000 authenticator records, it is not uncommon for the data migration process to take up to two days (the actual migration time depends on available server resources and the configuration settings of the data migration task).

OneSpan Authentication Server – Supported upgrade paths

Figure: OneSpan Authentication Server – Supported upgrade paths

Table: Supported systems
OneSpan Authentication Server
3.293.283.273.263.253.24
Operating systems
Windows 2025✓✓
Windows 2022✓✓✓✓✓✓
Windows 2019✓✓✓✓✓✓
Windows 2016✓✓✓✓✓
Windows 2012 R2✓
Windows 2012✓
CentOS 7✓✓
RHEL 9✓✓✓✓
RHEL 8✓✓✓✓✓✓
RHEL 7✓✓✓✓
Rocky Linux 9✓✓✓✓
Rocky Linux 8✓✓✓✓
Ubuntu 24.04✓
Ubuntu 22.04✓✓✓✓
Ubuntu 20.04✓✓✓✓✓
Ubuntu 18.04✓✓✓✓
Database management systems
MariaDB 11✓[1]
MariaDB 10✓✓✓✓[2]✓[3]
Oracle DB 19c✓✓✓✓✓✓
Oracle DB 18c✓
Oracle DB 12c✓
PostgreSQL 17.9✓
SQL Server 2025✓
SQL Server 2022✓✓✓✓
SQL Server 2019✓✓✓✓✓✓
SQL Server 2017✓✓✓✓✓✓
SQL Server 2016[4]✓✓✓✓✓
SQL Server 2014[4]✓✓
SQL Server 2012[4]✓
  1. 11.8 LTS

  2. 10.11 LTS

  3. 10.6 LTS

  4. Windows only

New features and enhancements

Role-based administration

You can now define administrator roles to group related administrative privileges into clearly defined responsibilities outlining the tasks an administrative user can perform within the system. Instead of managing the administrative privileges for each administrator account individually, you can configure a set of administrator roles according to your organizational requirements and assign them to the administrator accounts where applicable, ensuring that administrators have only the level of access required to perform their duties.

This allows administrative access to be delegated safely, even in complex or multi‑domain environments. Administrator roles can be assigned, modified, or revoked at any time to reflect organizational changes or security requirements.

New authenticator status flag to enable or disable authenticators

You can now set the authenticator status, that means explicitly enable or disable an authenticator. If an authenticator is disabled, it cannot be used for regular user operations, such as authentication, administrative logon, transaction data signature validation, or provisioning requests. If you disable an authenticator license, users cannot create new authenticator instances with that license.

When authenticator records are imported, they are enabled by default. The authenticator status can be set in the authenticator properties by administrative users with the Update DIGIPASS privilege.

Bulk Cleanup DIGIPASS wizard improvements

The Bulk Cleanup DIGIPASS wizard received a couple of enhancements to improve the functionality, usability, and data safety:

  • New cleanup strategy. The new Digipass disabled for a specified period strategy identifies and processes all authenticators and authenticator instances that have been disabled for a specified number of days.

  • Configurable cleanup action. The Test run option has been removed. Instead, you can now select a cleanup action that should be applied to the authenticators and authenticator instances that were determined by the cleanup strategy. You can either get a list of the matching items (similar to test run), delete them, or disable them (set the authenticator status).

  • Safe default value. The minimum retention period for the Digipass not used for a specified period strategy was increased to 30 days to prevent the unintentional deletion of authenticators or authenticator instances that were merely not used for a couple of days. Furthermore, the Administration Web Interface sets a default value of 90.

  • Confirmation prompt. If you select delete or disable as the cleanup action, you now need to explicitly confirm that you want to continue to modify any data. A CSV report with the affected authenticators and authenticator instances is now always generated (previously, a report was only created for test runs).

Optimized authenticator application selection logic (CS0201848)

The Applicable DIGIPASS > Application Names policy setting to restrict the authenticator applications that are considered for authentication is now treated as an ordered list. Hence if multiple authenticator applications are eligible, they are evaluated in the order defined in the policy. Furthermore, if a serial number contains an application instance suffix, no additional wildcard is appended. This ensures more precise queries when an specific authenticator instance is explicitly specified.

The Administration Web Interface has been improved to change the list order of the applicable authenticator applications more easily.

Security notifications when new authenticator instances are registered

You can now configure automatic notifications to inform users whenever a new authenticator instance is registered to their account. The notifications can be sent via email or push notification using the Message Delivery Component (MDC). This feature helps to detect and prevent unauthorized attempts to register authenticator instances on behalf of other users.

The new Device Registration Security settings can be configured via the SERVERS > Global Configuration > DIGIPASS Activation tab and are disabled by default.

Client devices require a mobile app that was customized with Mobile Authenticator Studio 5.8.1 or later and configured to use device registration security.

Custom encryption key value configuration in Configuration Wizard

The Configuration Wizard now allows to set the initial key values for the sensitive data key and the storage data key during an advanced installation via the Cryptographic Keys page (replacing the previous Sensitive Data Encryption and Custom Data Encryption pages). It generates random key values of the possible maximum key length that you can either use right away or replace with custom key values.

If you perform a basic installation, the initial key values are always set to randomly generated values of the maximum key lengths (256 bit for storage data, 128 bit for sensitive data).

Support for stronger authentication and privacy protocols for SNMPv3

When you configure SNMPv3 targets for system monitoring, you can now choose from a wider set of stronger cryptographic authentication and privacy protocols to improve security for SNMP communication. The Configuration Wizard, Configuration Utility, and the Administration Web Interface have been enhanced to support the following options:

New authentication protocols

  • SHA-224

  • SHA-256 (new default value)

  • SHA-384

  • SHA-512

New privacy protocols

  • AES-192

  • AES-256 (new default value)

The new protocols can also be selected when you set up the initial SNMPv3 user during the initial configuration via the Configuration Wizard on Windows.

Invalidate administrative sessions on password change

You can now configure that administrative sessions expire automatically if the static password of the respective user account is changed. The new global Invalidate Sessions on Password Change option applies to interactive administrative sessions, e.g., Administration Web Interface and Tcl Command-Line Administration tool, it does not affect non-interactive service user sessions.

By default, the invalidating sessions on password change is enabled.

System dashboard re-enabled (Administration Web Interface)

The system dashboard has been re-enabled, after it was disabled in 3.28.2 due to a critical issue in the system dashboard data caching mechanism. The dashboard data storage has been redesigned. Instead of being directly stored with the audit data, it now uses a dedicated table in the main database for improved performance, efficiency, and scalability.

The system dashboard is an experimental feature and subject to be changed and vastly extended and enhanced in upcoming releases.

Deactivate authenticator instances using Cronto images (Administration Web Interface)

You can now deactivate an activated authenticator instance directly in the Administration Web Interface. Once you confirm the deactivation, the authenticator instance is expired, and all associated authenticator applications are deactivated.

The new INSTANCE DEACTIVATED page displays the deactivation message both as plain text and as a Cronto image, which you can copy and mail to the user. To complete the deactivation on the client, the user must either manually type the deactivation message or scan the Cronto image on the authenticator device.

Wildcard character configuration for user search (Administration Web Interface)

You can now globally configure how the Administration Web Interface should handle wildcard characters when searching for users, either by user name, user ID, or email (via FIND on the home page or the Find/Manage User page):

  • Auto (the default value) treats the search term as a partial match pattern and automatically adds wildcard characters before and after it (same behavior as in previous versions).

  • Manual allows you to add wildcard characters yourself.

  • Off means that wildcard characters cannot be used at all and the search returns only exact matches.

The Wildcards setting can be configured via the new SERVERS > Global Configuration > Administration tab (replacing the previous Session Management tab).

The View Global Configuration Options administrative privilege is now explicitly granted, henceforth the global configuration can be viewed by any administrative user.

Application index shown for each authenticator application (Administration Web Interface)

The Administration Web Interface now shows the application index of each authenticator application in the respective application tab. The application index is dynamically created during the DIGIPASS export file (DPX) import process based on the authenticator application order in the DPX.

The OneSpan Authentication Server authentication endpoints allow to explicitly specify an authenticator application via its application index to be used for the request. This option may also be exposed to end users, depending on the client application.

Configurable database connection retry interval and timeout

You can now globally configure the maximum time span the connection pool should wait while it attempts to acquire and establish a database connection before the operation is aborted as well as the delay between consecutive retry attempts.

The database Connection Management settings can be configured via the new SERVERS > Global Configuration > Data Store tab.

Server data migration task now scheduled to run on any server

The server data migration task will now be run with server mode set to Any, to allow the task to be picked up by any server in environments with multiple server instances with a shared database.

SMS HTTP gateway improvements (Message Delivery Component) (CS0218326, CS0177415)

The Message Delivery Component (MDC) introduces the following enhancements for SMS HTTP gateway support:

  • SOAP content type support. MDC now supports SOAP as a content type to communicate with SMS HTTP gateways via SOAP messages.

  • Mutual TLS (mTLS) support. MDC now supports mTLS to provide bidirectional server and client authentication between MDC and SMS HTTP gateways.

Storage key rotation during upgrade now skipped in replicated environments (CS0209411)

As of version 3.28.1, the Configuration Wizard allows you to create a new storage key and schedule a key rotation task to re-encrypt all BLOB data in the OneSpan Authentication Server database if it detects that the current storage key is too weak.

Because performing key rotation during an upgrade causes data corruption in replicated environments, the Storage Key page is now automatically skipped if replication is enabled.

Deprecated column data type conversion (Microsoft SQL Server)

In earlier versions, some database columns in Microsoft SQL Server were defined using the NTEXT data type. This data type has since been deprecated by Microsoft. If you now install a new deployment or upgrade an existing one with Microsoft SQL Server, the respective database columns are automatically created or converted to use the NVARCHAR data type instead.

Entrust nShield 5 HSM support

This version provides support of Entrust nShield 5c and nShield 5s HSMs for Linux 64-bit platforms. It also includes a new version of the Key Management Tool (5.0).

FIDO2 device binding support

OneSpan Authentication Server now supports multi-device activation provisioning scenarios that require binding a FIDO2  instance of a FIDO2–capable authenticator with an authenticator instance (based on the Vision FX provisioning protocol). Such scenarios are used for authenticators that combine Cronto visual cryptography with FIDO2 hardware-bound credentials, such as DIGIPASS FX2.

Fixes and other updates

Issue OAS-36394: CSV report deleted after download

Description: Reports generated by a bulk DIGIPASS cleanup are being deleted upon download, resulting in a server crash upon a subsequent download attempt.

Affects: OneSpan Authentication Server 3.28

Status: This issue has been fixed.

Issue OAS-36144 (Support case CS0230046): Message-Authenticator RADIUS attribute cannot be configured via Tcl Command-Line Administration tool

Description: After implementing the Message-Authenticator RADIUS attribute handling in version 3.27, the configuration was not possible via the Tcl Command-Line Administration tool (dpadmincmd).

Affects: OneSpan Authentication Server 3.27–3.28

Status: This issue has been fixed. The create, update, and query subcommands of the component and backend_svr TCL commands now support the optional boolean msg_attr_validation parameter.

Issue OAS-35422 (Support case CS0223257): Email address validation does not allow underscore characters

Description: When setting a user's email address, the validation is overly strict and rejects underscore characters ("_") in the domain part.

Affects: OneSpan Authentication Server 3.27–3.28

Status: This issue has been fixed.

Issue OAS-35178: Back-end authentication without static password succeeds (RADIUS)

Description: A vulnerability was identified where RADIUS authentication using the CHAP protocol can incorrectly succeed if no static back-end password is provided although back-end authentication is required. This issue can occur with certain configuration settings, for example, if local authentication does not allow static passwords (e.g., Digipass Only) and back-end authentication is always required and uses Active Directory or LDAP.

While the authentication using PAP correctly rejects such attempts with an "empty static password" error, the CHAP protocol implementation incorrectly allows the authentication to proceed with a blank static password.

Status: This issue has been fixed.

Issue OAS-34246: Audit partitioning configuration gets corrupted when re-running Configuration Wizard

Description: When running the Configuration Wizard again using the Re-run Installation Wizard option, the Audit Partitioning and Secure Auditing pages are incorrectly skipped. This causes the wizard to incorrectly disable audit table partitioning without prompting the administrator.

In some environments, this issue can cause the Configuration Wizard to become unresponsive and significantly increase the time to complete the database operations. In the worst case, the configuration settings get corrupted and the server may not operate correctly.

Affects: OneSpan Authentication Server 3.28.1

Status: This issue has been fixed. Running the Configuration Wizard again after an installation or upgrade does now correctly display the Audit Partitioning and Secure Audit pages and preserve the existing configuration.

Issue OAS-34018: Exception when re-running reports (Administration Web Interface)

Description: An issue has been identified when running reports that use run-time queries (for example, Administration Activity Summary). If, after generating the report, you remain on the Summary page and then navigate back to a previous page instead of closing the wizard, attempting to run the report again, the Administration Web Interface will show a null pointer exception.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-33654 (Support case CS0211633): Security-related HTTP response headers updated (Administration Web Interface)

Description: By default, the Administration Web Interface web application returns HTTP response headers that can help to prevent malicious attacks. The used security-related HTTP response headers and their handling were updated:

  • In earlier versions, security-related HTTP response headers were added to dynamic web application pages only. Now they are also applied to static content, for example, JavaScript and CSS files.

  • The frame option header is now set to deny any website from framing the Administration Web Interface by default (X-Frame-Options: DENY).

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-33268: Potential uncontrolled format string security vulnerability

Description: A potential security vulnerability has been identified that is caused by an uncontrolled format string weakness that can occur if the trace file path and UTF-8 file audit path are the same. This issue affects only deployments that use the text file audit method and have tracing enabled. In severe cases, this issue may cause the OneSpan Authentication Server service or daemon to terminate unexpectedly.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-33022: Domain list is not refreshed when creating a new domain (Administration Web Interface)

Description: An optical UX issue was discovered that occurs when a new domain is added via Add Domain while viewing the Domain list. After you enter the domain details on the Add New Domain page and submit, you remain on that page to add additional domains if required. If you then click the Click here to return to the previous page link, you are taken back to the Domain list, but any newly created domain does not appear until the Domain list is refreshed.

Affects: OneSpan Authentication Server 3.26–3.28

Status: This issue has been fixed.

Issue OAS-32893: Incomplete data migration not detected after upgrade

Description: After upgrading OneSpan Authentication Server, even though data migration has not finished and another upgrade attempt is started, the database schema check performed by the command line utility (dpdbadmin) incorrectly reports the database as up to date and returns a success status code. Instead, the upgrade should be blocked until the data migration has successfully completed.

Affects: OneSpan Authentication Server 3.27–3.28

Status: This issue has been fixed. And if executed in standalone mode, dpdbadmin now provides a return code, RETURN_SCHEMA_VERSION_MISMATCH_MIGRATION_NEEDED.

Issue OAS-32807: Included Net-SNMP command-line tools cannot resolve obsolete dependency

Description: If you install the Net-SNMP package included with the OneSpan Authentication Server setup and attempt to use its command-line tools to configure SNMP, the tools will terminate because of an unresolvable, obsolete Perl dependency (Win32::Registry). This issue affects the mib2c, snmpconf, and traptoemail command/script.

If you are using the Configuration Utility to configure SNMP, you are not affected by this issue.

Affects: OneSpan Authentication Server 3.24–3.28 (on Windows using included Net-SNMP)

Status: This issue has been fixed. The Perl dependency were updated to use the correct module.

Issues OAS-32375, OAS-32374 (Support case CS0208142): Advanced DPX upload does not accept 64 character key components (Administration Web Interface)

Description: In version 3.28, the Import DIGIPASS from DPX wizard was enhanced to accept basic transport keys of up to 64 characters (allowing the use of 256-bit keys). However, advanced transport keys – that consists of multiple key components – were still limited to 32 characters per key component. The documentation did not mention the increased maximum  transport key length.

Affects: OneSpan Authentication Server 3.28

Status: This issue has been fixed. The Import DIGIPASS from DPX wizard now also accepts up to 64 characters for each key component of an advanced transport key. In addition, key components are now automatically formatted into groups of four characters to simplify data entry, consistent with the handling of basic transport keys.

The documentation was updated and now shows the correct maximum key length for transport keys.

Issue OAS-32300 (Support case CS0207587): Misaligned checkboxes and labels on Admin Privilege tab (Administration Web Interface)

Description: When you edit the administrative privileges of a user account on the USER > Admin Privileges tab, a layout issue causes the checkboxes and their labels to appear on separate lines.

Affects: OneSpan Authentication Server 3.26–3.28

Status: This issue has been fixed.

Issue OAS-31809: Effective lock duration for user auto-unlock attempts calculated incorrectly (Authentication)

Description: When you enable user auto-unlock, the effective lock duration is calculated incorrectly. For example, with the lock duration multiplier set to 200, the lock duration should double after each unsuccessful authentication. Instead, it increases only by the minimum lock duration each time.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-31377: Duplicate recurring tasks created after server crash or task failure (Task Management)

Description: When the OneSpan Authentication Server service/daemon crashes or a scheduled task fails during its execution, the task scheduler does not properly verify whether a future occurrence of a recurring task already exists before creating a new one. This can result in multiple duplicate entries for the same recurring task (e.g., Delete Audit Data), leading to unnecessary server load and potential conflicts when the duplicated tasks are run simultaneously.

Affects: OneSpan Authentication Server 3.25–3.28

Status: This issue has been fixed. The following improvements were implemented:

  • Recurring task scheduling. The task scheduler now properly verifies if a matching task already exists before creating new future task entries, ensuring that a recurring task is scheduled only once.

  • Trace logging fixed. Task details in trace output were truncated after the Start Time field, omitting the remaining task properties. The full task information is now logged correctly.

  • Parallel execution limit. The Delete Audit Data task is now limited to one concurrent execution per node, consistent with other task types.

Issue OAS-30543 (Support case CS0206171): Moving a user account in replicated environments can lead to excessive memory consumption

Description: In environments with replication enabled, Onespan Authentication Server verifies that a user account has been correctly moved when it is moved from one domain to another. This verification is not optimally implemented, and, in the worst case, can lead to excessive memory consumption and degraded performance.

Affects: OneSpan Authentication Server 3.24–3.28.1

Status: This issue has been fixed. The memory consumption is now within regular limits, and the operation’s performance has been improved.

Issue OAS-30058: Avoid initial time synchronization settings can lead to rejected OTPs

Description: The Avoid Initial Time Synchronization policy setting allows to skip the initial time shift initialization on the server side when an authenticator is used for the first time (by effectively using either Identification Time Window or Signature Time Window instead of the Initial Time Window value for the initial synchronization). This can be useful for software authenticators, because the time shift is usually handled by the mobile app. Depending on the values of the DIGIPASS synchronization window settings, this can occasionally cause issues with validating OTPs and lead to rejected authentications.

Affects: OneSpan Authentication Server 3.26–3.28

Status: This issue has been fixed. If Avoid Initial Time Synchronization is set to Software DIGIPASS only, the initial synchronization time window is now set to 1 minute (see DP Control Parameters).

Issue OAS-28118 (Support case CS0184822): Custom keystore configuration lost after upgrade (Web Administration Service)

Description: When you upgrade an existing Web Administration Service deployment, which has been configured to use a custom keystore file, the keystore configuration setting attributes (in particular certificateKeystoreFile and certificateKeyAlias) of the Connector/SSLHostConfig/Certificate element in the Apache Tomcat configuration file (server.xml) are reset to their default values. Furthermore, the keystore attributes are not migrated if the default keystore file is not present in the installation directory.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed.

Issue OAS-26081 (Support case CS0175315): DBeaver tool unsuccessfully attempts to download MariaDB driver files when offline

Description: After installing or upgrading an existing OneSpan Authentication Server deployment that uses the embedded MariaDB database, the default local client configuration of the included DBeaver database tool is empty. When you attempt to connect to the OneSpan Authentication Server database with the DBeaver database tool, it attempts to download MariaDB driver files, which does not work without further configuration steps if the server is not connected to the internet.

Affects: OneSpan Authentication Server 3.24–3.28 (with embedded MariaDB database)

Status: This issue has been fixed.

Issue OAS-25131: Misleading ODBC connection error logged in trace by dpdbadmin

Description: When running the ODBC database command-line utility (dpdbadmin) with verbose logging (for example, dpdbadmin checkschema -v -v), certain informational ODBC diagnostic messages are incorrectly logged as ODBCError entries with severity type MAJOR. This can be misleading because the database connection is established successfully and the operation completes without errors.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed. Informational ODBC diagnostic messages are now correctly logged with severity type INFO. Actual errors, such as failed logon attempts, continue to be reported at the MAJOR severity type.

Issue OAS-24606: Import from unsorted Digipass import file can cause issue

Description: Importing authenticator records from a Digipass import file (CSV) can cause issues if the file contains authenticator instances that are linked to authenticator licenses which are defined later in the file.

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed. The CSV import logic was enhanced to first process all authenticator licenses before importing any authenticator instances.

Issue OAS-21699: Misleading audit message when authenticator type limit is reached (Provisioning)

Description: When an authenticator cannot be assigned during provisioning because the policy's assignment limit for this authenticator type has already been reached, the request fails. However, the corresponding audit message indicates a misleading reason (“Multiple DIGIPASS found where a single DIGIPASS was required”).

Affects: OneSpan Authentication Server 3.24–3.28

Status: This issue has been fixed. If provisioning fails because of the authenticator type limit, the audit message now provides a more meaningful reason (“The DIGIPASS type limit has been reached“).

Issue OAS‑7855 (Support cases CS0115168, CS0108075): Leftover registry subtree when uninstalling the embedded database (Setup)

Description: When you uninstall the embedded MariaDB database on Microsoft Windows 2016, the MariaDB setup leaves a registry subtree behind. Since the OneSpan Authentication Server Setup Utility uses that registry subtree to detect an existing MariaDB deployment, it will incorrectly indicate an external installation of MariaDB if you attempt to reinstall OneSpan Authentication Server afterward.

Affects: OneSpan Authentication Server 3.19 and later on Windows Server 2016

Status: This issue does no longer apply! The respective functionality was changed/removed in this version. Windows Server 2016 is no longer supported, and the issue does not occur on any currently supported versions of Windows.

Deprecated/removed components and features

Supported platforms, data management systems, and other third-party products

This version no longer supports the following products:

Operating systems

  • Ubuntu Server 20.04 LTS, 64-bit

  • Windows Server 2016

Database management systems

  • Microsoft SQL Server 2016

LDAP servers

  • IBM Security Directory Server (Deprecated)

    IBM Security Directory Server is considered deprecated and no longer officially supported, but its functionality has not been removed yet. Any remaining references and features in the code base, UI, and documentation will be removed in a future release.

  • NetIQ eDirectory

    The support for NetIQ eDirectory has been completely removed. You can no longer use it for any previously supported purposes, including back-end authentication or data synchronization. If you upgrade an existing deployment, any pre-defined eDirectory-related policies remain in the data store and must be removed manually.

Hardware security modules

  • Thales ProtectServer 2

  • Thales ProtectServer

Other deprecated features

The following features and components are considered as being deprecated and will be removed in a future release. There are no plans to further enhance them or fix any related issues. If you are using any of the listed features, you are highly encouraged to evaluate the recommended alternatives.

Deprecated feature

Recommended alternative

Announced in

Removal in

IBM Security Directory Server

Microsoft Active Directory, OpenLDAP

3.29

Not scheduled yet

NetIQ eDirectory

Microsoft Active Directory, OpenLDAP

3.27

3.29

Alternative ODBC table names

n/a

3.20

Not scheduled yet

Known issues

Issue OAS‑26628: Cannot switch from one hardware security module (HSM) to another

Description: It is not possible to switch from one hardware security module (HSM) to another, for instance, from Thales ProtectServer 2 to Thales ProtectServer 3.

The Configuration Wizard does not provide an option to switch the hardware security module (HSM) and cannot configure the new HSM properly.

Status: No fix or workaround available.

Issue OAS-25314: Incorrect error message reported for OTP validation failure when an expired authenticator is assigned

Description: When a user has multiple authenticators assigned and at least one of them is expired, an authentication attempt using an incorrect OTP may incorrectly report that the authentication failed because of an expired authenticator, even if the OTP was validated against a non-expired authenticator. This issue occurs only if (at least) the authenticator with the lowest serial number is expired. The error stack entry incorrectly displays a "The DIGIPASS has expired" error message instead of "Validation Failed".

Affects: OneSpan Authentication Server 3.25 and later

Status: No fix or workaround available. Review the full error stack to identify which authenticator is actually expired (error code 1025) and which caused the OTP validation to fail (error code 1012).

Issue OAS-24342: Web Administration Service daemon does not restart after upgrade (Setup)

Description: In some environments, Web Administration Service does not restart correctly when an existing deployment is upgraded. Any connection attempt immediately after an upgrade will fail with an HTTP 500 server error. If you restart the daemon, Web Administration Service works as expected.

Affects: OneSpan Authentication Server 3.27 and later on Linux

Status: No fix available. If you experience this issue, restart the Web Administration Service daemon manually.

Issue OAS-9159 (Support case CS0057804): Usability issues when two reports are started at the same time (Reporting)

Description: When two reports are started at the same time, e.g. with two different browsers, a (nonfunctional) download link for the second report will be available before the report task has even started. The corresponding report results cannot be accessed.

Affects: OneSpan Authentication Server 3.19 and later

Status: No fix available. To avoid this issue, do not run multiple reports at the same time.

Issue OAS-5605 (Support cases CS0039109, CS0046614): Issues with Chinese characters in XML and PDF reports (Web Administration Service)

Description: Chinese characters are not correctly displayed in XML and PDF reports.

Affects: OneSpan Authentication Server 3.12 and later

Status: This issue has been fixed for XML reports in OneSpan Authentication Server 3.21. The issue can still occur in PDF reports in case they contain characters that are not defined in the used PDF font. Workaround for PDF reports: Generate an HTML report and print it to PDF.

Issue OAS-4163 (Support case CS0030058): Cannot assign multiple authenticators to a single user in one step (Web Administration Service)

Description: The Assign DIGIPASS wizard allows you to assign authenticators to users. Although you can select multiple authenticators and multiple users, you can only assign exactly one authenticator to one user at a time. For instance, if you select two authenticators in the wizard, you need to specify two different user accounts, one user to assign each one authenticator.

Affects: OneSpan Authentication Server 3.21 and later

Status: No fix available. To assign additional authenticators to a user, you need to run the Assign DIGIPASS wizard again.

Issue OAS-3761 (Support case CS0024326): Inaccessible authenticators proposed for manual assignment (Web Administration Service)

Description: The Assign DIGIPASS wizard allows you to explicitly select the authenticators to assign to multiple users (by selecting Search now to select DIGIPASS to assign in the Search DIGIPASS page). However, the Select DIGIPASS page may also show authenticators that are actually inaccessible to assign to the respective users, because they are in another domain than the users. If you select such an authenticator and continue, you will receive a "Failed to find available token for assignment." error.

This issue does not occur if you only select one user to assign an authenticator. In this case, the Select DIGIPASS page correctly shows only authenticators in the same domain as the user account.

Affects: OneSpan Authentication Server 3.21 and later

Status: No fix available. Ensure to explicitly select only authenticators that are in the same domain as the users you selected to assign an authenticator.

Issue OAS-3455 (Support case CS0021350): Audit Viewer shows incorrect error message when loading a text audit file

Description: When you open a text audit file in Audit Viewer, the application loads and processes the complete text audit file in batches that are continuously added to the audit message list. Each batch takes a while to process, but there is no indication whether loading the complete audit file has been finished yet.

If you deselect and select the Auto Scroll Down box, while the file is still being processed, you may receive a "No more new messages to display" error message.

Affects: OneSpan Authentication Server 3.22 and later

Status: No fix or workaround available.

Issue 83511: HSM driver must be manually configured on Linux

Description: When integrating a hardware security module (HSM) with OneSpan Authentication Server, you will need to configure the HSM driver before you install OneSpan Authentication Server. On all Linux distributions using the UNIX System V operating system, the HSM driver must be configured for communication with OneSpan Authentication Server because the script created upon driver installation does not automatically start the system service.

Affects: OneSpan Authentication Server 3.6 and later

Status: No fix available. Workaround: replace the init.d file created during driver installation with the system.d file in the corresponding link. For more information, see OneSpan Authentication Server Installation Guide for Linux.

Issue 58722: Mobile Authenticator Studio timeshift no longer supported

Description: When the Timeshift feature of Mobile Authenticator Studio is used, it causes the offline data to become invalid. The option to set a timeshift for Mobile Authenticator Studio authenticators is no longer supported. This feature is outdated and has become obsolete because mobile devices are now correctly synchronized with OneSpan Authentication Server at shorter intervals.

Affects: OneSpan Authentication Server 3.6 and later

Status: Do not use the Mobile Authenticator Studio Timeshift feature to avoid the offline data to become invalid.

Issue 48452 (Support case PS-144964): Multiple authentication and accounting ports on OneSpan Authentication Server (RADIUS communicator)

Description: OneSpan Authentication Server allows for the configuration of two RADIUS authentication ports and two RADIUS accounting ports. By default, one authentication and one accounting port is specified, the second ports can only be edited in the configuration file of OneSpan Authentication Server , not directly in the Administration Web Interface.

Affects: OneSpan Authentication Server 3.5 and later

Status: If a second authentication and/or a second accounting port for the RADIUS Communicator will be used, the port specifications need to be edited in the identikeyconfig.xml file.

Issue 46294 (Support case PS-141029): SafeNet HSM mode setup causes installation failure (OneSpan Authentication Server Setup)

Description: Deployments of OneSpan Authentication Server with Thales ProtectServer HSM only support HSMs that run in Normal mode. If the HSM is run in High Availability or Workload Distribution mode, the installation of OneSpan Authentication Server fails.

Affects: OneSpan Authentication Server 3.6 and later

Status: The Thales ProtectServer HSM must be run in Normal mode, i.e., ET_PTKC_GENERAL_LIBRARY_MODE must be set to NORMAL.

Issue 41616: Self-signed certificates created by Microsoft Internet Information Services (IIS) cannot be used (Message Delivery Component (MDC))

Description: When trying to configure email delivery with SSL/TLS using a self-signed certificate created using Microsoft Internet Information Services (IIS) and converted to PEM format using OpenSSL, MDC cannot recognize a valid self-signed certificate and displays an error message. This is caused by the OpenSSL library. In some circumstances, the OpenSSL application itself may display an "Unable to get local issuer certificate (20)" error message.

Affects: All platforms.

Status: No fix available. This is a compatibility issue between OpenSSL and Microsoft IIS. Do not use self-signed certificates generated using Microsoft IIS.

Issue 25333: Undefined TEMP path not supported

Description: A Windows installation will fail if the TEMP environmental variable is undefined or empty.

Affects: All Windows platforms.

Status: No fix available.