Issues Resolved
- Last Updated: November 8, 2023
- 1 minute read
- LoadMaster
- LoadMaster LTSF
- Documentation
The following issues have been resolved in this release.
| PD-13828 | IPv6: Under certain circumstances, specifying a Real Server using an FQDN (rather than a hostname or IP address) can result in the FQDN resolving to an invalid IPv6 address. This issue has been fixed. |
| PD-13816 | GEO: In previous releases, the DNS server returns NXDOMAIN or NODATA when there are disabled IPv4 or IPv6 records (i.e., sites) present in the configuration. The DNS server behavior has been modified so that it returns NOERROR in these cases. |
| PD-13808 | Licensing API: For consistency, the aslactivate() and alsilicense() routines will now accept either licensetypeid or lic_type_id as the parameter specifying the license type. |
| PD-13802 | SPLA Licensing: Fixed an issue that could cause several spurious virtual services to appear after a fresh install. |
| PD-13794 | Memory Consumption on Upgrade to 7.2.47: Upgrading a LoadMaster with over 4GB of memory to version 7.2.47 (only), could result in a significant increase in system memory usage on large configurations (many unique Real Server IP/port combinations). This issue has been fixed. |
| PD-13785 | User Interface: Fixed an issue that caused spurious text to appear at the bottom of the Certificates & Security > Remote Access UI when the Admin Login Method was modified. |
| PD-13780 | HTTP/2: An issue that caused embedded videos to fail to load properly via HTTP/2 virtual services has been fixed. |
| PD-13776 | User Interface LDAP Login: Fixed an issue where access is denied by some LDAP servers when specifying permitted groups. |
| PD-13752 | User Interface: Modified the UI so that the date/time format on the Home page and the Update License page are the same. |
| PD-13750 | WAF API: Fixed an issue with the maninstallwafrules() API returning ‘Unknown Command’ when the API was executed successfully. |
| PD-13749 | Security / SSH: Support for the weak MAC algorithm hmac-sha1 has been removed with this release. This may result is some older versions of SSH no longer working with LoadMaster. |
| PD-13739 | User Interface Security: Fixed an issue where LoadMaster was re-generating the default UI certificates after a reboot. |
| PD-13727 | WAF Rules / User Interface Resiliency: In LMOS version 7.2.47, if the download and installation of WAF rules fails on LoadMaster due to corruption, this failure could contribute to the exhaustion of available temporary storage, which would cause the UI to become unavailable. This issue has been fixed. |
| PD-13720 | HTTP/2: Fixed an issue that, when HTTP/2 is enabled on a SubVS, caused only the HTTP/2 response code and not the associated error message text to be returned to the client. |
| PD-13712 | UI Cipher Sets: Modified the UI so that Cipher Set can be named using both plus (+) and minus (-) characters. |
| PD-13672 | Application Template Import: Fixed an issue where you could not import a template containing SubVSs with Basic Authentication enabled on the Client side. |
| PD-13669 | License Expiration: Fixed an issue where LoadMaster services were not being disabled after the system license and applicable grace period had expired. |
| PD-13668 | UI Client Certificate Authentication: Changes were made in 7.2.46 that caused client certificate authentication for the UI to fail. This issue has been fixed. |
| PD-13664 | VMware Tools & VM Workstation: Fixed an issue with the VMWare Tools Add-on that caused an error to be displayed when deploying a LoadMaster in VM Workstation. |
| PD-13632 | Secure Flag in Cookies: In previous releases, the Secure flag in HTTP cookies is only set if the user adds a specific content rule to set it. With this release, the Secure flag is always set when Active Cookie persistence is selected for an HTTPS virtual service. |
| PD-13583 | FIPS Ciphers: Fixed the list of FIPS ciphers in the UI so that it is correct. |
| PD-13561 | Health Checking: When using a POST HTTP health check, the POST data is being sent as URL-encoded text instead of being sent as raw data. This issue has been fixed. |
| PD-13551 | Single Sign On (SSO): On LMOS 7.2.47.1 only, when a virtual service configuration uses NTLM + KCD for user authentication, the connection will close and force the user to re-authenticate. The LoadMaster will also log segfault errors. This issue has been fixed. |
| PD-13540 | VLANs on Bonded Interfaces: In previous releases, when adding or deleting VLANs on a bonded interface, connectivity on that VLAN will be lost during the operation. With this release, you can add and delete VLANs to a bonded interface without losing connectivity on the VLAN. |
| PD-13515 | Sorry Server: Adding a ‘sorry server’ to an HTTPS straight through virtual service does not work. This issue has been fixed. |
| PD-13511 | GEO: Modified how the view configuration file is generated to prevent intermittent response issues seen while using GEO with a Zone Name specified. |
| PD-13507 | SAML: Fixed an issue where the Subject Name Identifier in the SAML response was not being handled properly, resulting in errors. |
| PD-13500 | SSO: A colon character (:) can now be included in the Allowed Virtual Hosts value via the API and in the UI under a virtual service’s ESP Options. |
| PD-13498 | HTTP/2: In previous releases, an SSL accelerated virtual service would not work properly after changing the service type from HTTP-HTTP/2-HTTPS to HTTP/2 Pass-through. This issue has been fixed. |
| PD-13496 | Powershell API: A new cmdlet, Get-SSODomainQuerySession, is provided to fetch SSO domain sessions. |
| PD-13432 | MELA Licensing: In previous releases, when a MELA license obtained from Kemp 360 Central expires, you cannot re-license the Loadmaster with the same license type. With this release, this restriction has been removed. |
| PD-13431 | Licensing: In previous releases, it was possible to license a Free LoadMaster via offline licensing and disable call home. This has been changed so that a Free LoadMaster can only be licensed online. In addition, call home is enabled by default and cannot be disabled. |
| PD-13401 | Memory Exhaustion: In previous releases, in a LoadMaster with a RAM size of 8GB or less it was possible that the system would run out of memory if there were a large number of long lived SSL connections. With this release measures have been implemented to prevent the system from running out of memory. |
| PD-13400 | SSO: In previous releases, when Failed Login Attempts is set to ‘1’, a user will not get blocked until after 2 failed login attempts. This issue has been fixed. |
| PD-13376 | MELA Licensing: In previous releases, a LoadMaster deployed in Azure did not send its public IP to Kemp 360 Central during licensing, and so Kemp 360 Central could not communicate with it. This issue has been fixed. |
| PD-13276 | Statistics: Fixed issues observed on some platforms where the UI and/or API were reporting differing, incorrect, or invalid values. |
| PD-13126 | GEO: In previous releases, the DNS server returns NXDOMAIN for a query on the second level of a child domain. With this release, the NOERROR status is returned for a DNS query sent on any level of a child domain. |
| PD-13065 | Interface Bonding: (LoadMaster X15 only) Issues seen when bonding interfaces between certain Cisco switches have been fixed. |
| PD-13053 | SSO: In previous releases, clicking the ‘Kill All’ button when viewing the open sessions for one SSO domain also kills all open sessions in all other SSO domains. With this release, only the open sessions associated with the domain being displayed are killed. |
| PD-13045 | SAML: In previous releases, if there are many SAML based sessions open when trying to view open sessions, the WUI does not display the sessions and instead a segmentation fault appears in the logs. This issue has been fixed. |
| PD-12962 | Virtual Service Names: In previous releases, it was possible to begin the name of a virtual service with a number or a special character. This is no longer permitted. |
| PD-12767 | SSO: API (and UI) response times for retrieving/displaying a large number of SSO open sessions has been improved so that most queries complete in under 1 second. |
| PD-12668 | ActiveSync Virtual Services: Connectivity Issues with ActiveSync Virtual Services may be observed at high traffic volumes. Previously, under high load and thousands of SSO sessions, the LM memory utilization would grow until it ran out of memory.Now, there may be thousands of SSO sessions and the LM memory will remain steady. |
| PD-12384 | KCD Server Authentication: Modified ticket handling to improve response times. |
| PD-12068 | Clustering & Memory Management: Addressed issues causing shared memory corruption when the cluster type is Remote LM and the configuration contains a large number of virtual services. |
| PD-11737 | SAML & KCD: In previous releases, SAML + KCD configurations were reported to experience high CPU usage and slow response times, causing interruptions in client traffic. Improvements to KCD authentication have been made to lower CPU utilization and provide faster response times. |