LM-7526 Application Programming Interface (API): Fixed an issue where the command for "local cert" returned extra tags.
LM-7525 ACME Certificate Renewal: Fixed an issue that caused certificate renewal to fail.
LM-7711 DNSSEC: Fixed an issue with dnssed key generation.
LM-7640 GEO: Fixed an issue with the log message "unable to open '/etc/bind.keys'; using built-in keys instead".
LM-7600 Kernel Panic: Fixed an issue with Null pointer dereference.
LM-6942 Security/Stability: Fixed a possible buffer overflow and segmentation fault that could occur if a carefully-crafted command is executed when logged into the system through SSH.
LM-6576 Networking: Fixed an issue that caused NG Hardware VLANs to not work on 10Gb interfaces.
LM-6180 GEO: Fixed an issue with unauthorized Remote Machine connections after setting the shared secret.
LM-6176 Networking: Fixed an issue with the Prolabs SFP-1000Base-T-C connector not being seen when the LoadMaster started.
LM-6151 Web User Interface (WUI): Added a warning to emphasize that a shared secret is required for GEO partners, High Availability (HA), and clustering.
LM-6147 Clustering: Fixed an issue with cluster node deletion.
LM-6007 GEO: Fixed an issue with GEO partnering on Azure and AWS environments when using a shared secret.
LM-6004 HA: Fixed an issue with HA in Azure and AWS environments when using a shared secret.
LM-6000 Clustering: Fixed an issue with clustering when using a shared secret.
LM-5861 SSO: Fixed an issue where the LoadMaster was not blocking a user after "n" failed attempts, where "n" is the number set by the user in the Failed Login Attempts field.
LM-5635 SAML Authentication: Fixed an issue where SAML authentication succeeds, but the user is then redirected to an incorrect URL.
LM-5339 NTLM/KCD: Fixed an issue where a user is getting blocked incorrectly (When Failed Login Attempts is set to 0).
LM-5058 Web Application Firewall (WAF) and Remote Logging: When both WAF and Remote Logging are enabled, WAF processing and Layer 7 processing can hang, leading to a service outage. WAF has been modified to continue processing even when log entries are not being processed and a watchdog process will now monitor the logging pipeline to recover remote logging processing if it stops.
LM-5058 WAF: Fixed an issue where a configuration change under heavy load could cause the WAF engine to restart.
LM-5054 Kubernetes Ingress Controller (KIC): Fixed an issue where ingress annotations were not working properly because of un-escaped spaces in lists.
LM-5050 Backup/Restore: Fixed an issue where a backup cannot be restored when the file name contains specific strings.
LM-5048 User Interface (UI) Certificate Login: Fixed an issue where enabling UI Remote Access with client certificates using the API (not the WUI) resulted in login failures.
LM-5044 WAF: Fixed an issue where an error in custom rules could cause the WAF engine to restart.
LM-5038 Backup/Restore: Fixed an issue that causes a backup import to fail when the backup archive contains specific strings.
LM-5036 Logging: “set LOG_LEVEL for 'kernel: L7: Got a bad wkday” messages were changed to a debug-level log.
LM-5034 Debug Logging: Fixed an issue where log lines were being inappropriately split into two lines, violating the related standard.
LM-5026 ACME Certificates: The UI and API limit for the TLD (Top-Level Domain) part of an email address was limited to 4 characters. An email address such as “user@domain.cloud” would be rejected as invalid. This limit has been increased to 24.
LM-5020 GEO Clustering: Fixed an issue that caused GEO cluster checks to fail with the log message "logger: error receiving the file from the remote LoadMaster".
LM-3095 OSCP: Fixed an issue where the user is authenticated from the LDAPS server even if the certificate chain is not completed for the LDAPS server.
LM-2770 SSO: Fixed an issue where the user was blocked even if the Failed Login Attempts parameter was set to 0 (NTLM Proxy).
LM-2740 Persistence: Fixed an issue with the Server Cookie persistence option when HTTP/2 is enabled.
LM-1006 GEO: Fixed an issue relating to missing remote Virtual Services showing the protocol and port when using GEO cluster health checks.
LM-4912 FIPS: The Add Received Cipher Name and Require SNI hostname fields are now available in the FIPS WUI.
LM-7708 Security/Stability: Closed possible command injection vulnerabilities in the aclcontrol and modvs API commands.