Skip to main content

September 4, 2026

Omnissa Unified Access Gateway Release Notes

Unified Access Gateway 2412 | 28 JAN 2025
Check for additions and updates to these release notes.

Unified Access Gateway appliance helps enable secure remote access for virtual desktops, internal sites, applications, and file repositories users. To learn more, see Unified Access Gateway Documentation.

Omnissa Unified Access Gateway Release Notes provides information about the new features and enhancements in each release. This page contains a summary of the new capabilities, issues resolved, and known issues that are reported in each version.

What's New

Unified Access Gateway 2412 provides the following new features and enhancements:

  • Transition Update

    • The transition from Broadcom to Omnissa is now complete. The Unified Access Gateway Admin user interface, configuration strings, and file paths have been updated to reflect the new Omnissa brand.
    • As HTML Access is renamed to Web Client, the related keys and Admin UI settings on Unified Access Gateway are also renamed.

  • Operating System Update
    • Following the transition from Broadcom to Omnissa, the Unified Access Gateway now uses the AlmaLinux operating system. AlmaLinux is an open-source, community-driven Linux operating system. Unified Access Gateway 2412 uses AlmaLinux 9.2.

    • Compatibility between ALMA 9.2 and ESXi (vSphere/vCenter)

  • Users can now configure Unified Access Gateway to perform OpenID Connect (OIDC) authentication. See OpenID Connect (OIDC).

  • Administrators can now configure Gateway Specification that will allow only the required services for that specification type to run on the appliance. See Gateway Specification in Deploying to vSphere using the OVF Template Wizard.

  • Security Improvements

    • Added protection against user impersonation attack to ensure a desktop launch session is sent from the same client endpoint where it was generated when Unified Access Gateway is used with SAML authentication in Service Provider initiated mode.

    • Added protection against SAML assertion replay attack to ensure that the SAML assertion issued by an Identity Provider can be used only once in its lifetime.

    • In case of Smart card, RADIUS and RSA SecurID authentication, Unified Access Gateway issues a SAML assertion (containing the end user attributes) to Horizon Connection Server. Added support for encrypting this assertion.

    • Change in the default value of SAML Authentication request signature algorithm from SHA-1 to SHA-256.

    • On FIPS version of Unified Access Gateway, Extended Master Secret extension is mandatory for TLS 1.2 connections.

    • Updates to TLS Ciphers. See System configuration.

  • Added compatibility with Horizon Connection Server's support for handling encrypted SAML assertion, issued by Identity Providers. See Encrypted assertion between Unified Access Gateway and auth methods.

  • On the Upload Identity Provider Metadata section of the Admin UI, you can now view all the uploaded certificates present in the Identity Provider metadata.

  • Logging improvements.

  • Updates to OS package versions and Java component versions.

Before You Begin

Resolved Issues

  • UAG-10980: NullPointerException while validating SAML assertion for which the RelayState is Unknown.

  • UAG-11413: Authentication failure after setting the RSA token PIN.

  • UAG-10906: Events sent to configured syslog server(s) do not contain hostname of Unified Access Gateway.

  • HW-213267: RADIUS authentication fails with Internal Server Error intermittently.

Known Issues

  • ESC-63850: X.509 certificate authentication might fail with Internal server error under high concurrent request load when revocation checking is enabled and CRL/OCSP endpoints exhibit slow response times.

    Workaround

    1. Backup the configuration file.

      cp /opt/omnissa/gateway/supervisor/conf/cas.ini /opt/omnissa/gateway/supervisor/conf/cas_backup

    2. Add the following property:

      sed -i "s|-jar|-Dcertauth.business.concurrency.factor=2000 -jar|g" /opt/omnissa/gateway/supervisor/conf/cas.ini

    3. Run the command:

      supervisorctl reread && supervisorctl update

  • UAG-11578: Modifying default gateway from the Admin UI does not take effect.
    Workaround
    To work around this issue, see the Knowledge Base article Default gateway cannot be changed from UAG v2412 Admin Console (6000779) .

  • PPAT-17219:

    • Android Tunnel is incompatible with Unified Access Gateway 2412 - FIPS mode only.
    • Windows Tunnel version 24.01 and lower is incompatible with Unified Access Gateway 2412 - FIPS mode only.

      To ensure compatibility with Unified Access Gateway 2412 FIPS mode, use Windows Tunnel version 24.05 or later and enable TLS 1.3 on the Windows device.
  • UAG-11556: Hourly log rotation of some log files does not work.
    Workaround
    To work around this issue, see the Knowledge Base article Unified Access Gateway (UAG): Hourly log rotation with logrotate does not work (6000754).

  • UAG-13953: When UAG SAML configuration is read through certain APIs, the system triggers false-positive CONFIG_CHANGE audit log entries.
    Workaround: This issue has no functional impact. Currently, there is no workaround.

Documentation

Documentation for Unified Access Gateway is located at Omnissa Product Documentation.

Support Contact Information

To receive support, access Customer Connect.

For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge Base (KB) article 6000005.

Localization

For details on Omnissa’s localization strategy, see Announcing Omnissa Localization Support.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…