Skip to main content

May 15, 2025

Omnissa Unified Access Gateway Release Notes

Unified Access Gateway 2111 | 30 NOV 2021
Check for additions and updates to these release notes.

What's New

The Unified Access Gateway 2111 release has been replaced by the 2111.1 release which contains a fix for the critical Log4j CVE-2021-44228 vulnerability. Details are listed in the 2111.1 Release Notes. Unified Access Gateway 2111.1 or later should be downloaded and deployed to benefit from the updates. UAG 2111 should no longer be used.

Omnissa Unified Access Gateway 2111 provides the following new features and enhancements:

  • TLS configuration for Horizon and Web Reverse Proxy and Identity Bridging has been extended to include specification of Named Groups (elliptic curves), Signature Schemes, and Client (outbound) Cipher Suites.

  • Added a new delay timer for OPSWAT endpoint compliance checks to improve user experience in cases where the OPSWAT On-demand agent is used with Horizon access.

  • Added support for Unified Access Gateway certificate authentication with client X.509 certificates that use the RSASSA-PSS signature algorithm.

  • SNMPv3 now includes support for additional Auth Alogrithms SHA-224, SHA-256, SHA-384, and SHA-512 in addition to MD5 and SHA.

The SNMPv3 Engine ID administratively assigned text value is now configurable. The SNMP MIB now includes disk monitoring in addition to CPU and memory.

  • Added support for Horizon Client and server data protection encryption when used with new versions of Horizon.

  • Java JDK 11 is used for all Unified Access Gateway components.

  • Java JDK 8 has been removed.

  • RSA SecurID support uses a new RSA SecurID Authentication API from RSA.
    The new API no longer supports the older sdconf.rec file for configuration. To configure RSA SecurID from the Admin UI or REST API, new values need to be specified. For more information about the new configuration settings for RSA SecurID, see the Deploying and Configuring Unified Access Gateway Guide or the details in the Admin UI for this version.
    Along with this API update, RSA Adaptive Authentication is no longer supported.

  • Host clock sync is now supported as an optional alternative to the default NTP protocol mechanism.
    This option is supported for Unified Access Gateway appliances running on VMWware ESXi where the VM can synchronize the clock with the ESXi hypervisor.

  • Configuration of log level modes such as DEBUG and TRACE can now be set for individual components instead of globally for all components.

  • Updates to Photon OS package versions and Java versions.

  • Added support for Blast Secure Gateway host header validation.

Internationalization

The Unified Access Gateway user interface, online help, and product documentation are available in Japanese, French, German, Spanish, Brazilian Portuguese, Simplified Chinese, Traditional Chinese, and Korean. For the complete documentation, go to (Omnissa Product Documentation).

Compatibility Notes

For more information about the compatiblity of Unified Access Gateway with other products, see Product Interoperability Matrix.

Lifecycle Support Policy

For information about the Unified Access Gateway Lifecycle Support policy, see this knowledge base article KB 2147313.

Installation and Upgrade

To download the Unified Access Gateway, see the Product Download page.

Technical Resources

There are several resources that help you learn and understand Unified Access Gateway. For more information, see Omnissa Product Documentation.

Known Issues

  • Deploying FIPS version of Unified Access Gateway 2111.x with Certificate Auth fails because Smart Card Authentication is not available on FIPS version 2111(.x) of Unified Access Gateway.

Resolution: Use the 2203 FIPS version.

  • Accessing the 2111(.x) FIPS Unified Access Gateway admin interface on https://uag1.example.com:9443/admin might fail if a hostname is used in the browser URL. The issue is related to SSL Server certificate handling.

Workaround: Use an IPv4 address in the browser URL instead of a hostname.

Resolution: Use the 2203 FIPS version.

  • Tunnel service on Unified Access Gateway 2111 causes error “AllowListManager Query returns Bad Response” impacting access for devices. For more information, see KB 88753.

Workaround : Use the 2203.1 or later version.

Resolved Issues

  • When setting a non-default Hostname for the OPSWAT Endpoint Compliance Check Provider Settings, the new value was not reflected in the dialog box when editing the settings.

  • Horizon URL launch of application and desktop sessions did not support the URL query parameters applicationId or desktopID so inprevious versions applicationName or desktopName had to be used instead. This is resolved so any of these names can now be used because the list of query parameters has been extended in this version.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…