|
Unified Access Gateway 2503 | 15 APR 2025
|
Unified Access Gateway appliance helps enable secure remote access for virtual desktops, internal sites, applications, and file repositories users. To learn more, see Unified Access Gateway Documentation.
Omnissa Unified Access Gateway Release Notes provides information about the new features and enhancements in each release. This page contains a summary of the new capabilities, issues resolved, and known issues that are reported in each version.
What's New
Unified Access Gateway 2503 provides the following new features and enhancements:
- Important Security Update for Horizon Deployments
- This release resolves CVE-2025-25234. For more information on this vulnerability and its impact on Omnissa products, see OMSA-2025-0002.
- If the HTTP requests arriving to Unified Access Gateway have a HTTP header Origin, the value of this header is now mandatorily validated against an allowed list of permitted origins in the Horizon Settings. See Mandatory Validation of Origin HTTP Header.
- Horizon 8 on Amazon Workspaces Core
- Unified Access Gateway now supports FIPS version for Horizon 8 on Amazon Workspaces Core deployments.
- Administrators can now make use of PowerShell script enhancements to automate
.ovato.amiconversion. See PowerShell deployment to Amazon AWS EC2.
- Security improvements
- Administrators can now enable TLS 1.2 and TLS 1.3, independent of each other and the support for TLS 1.1 is removed. This is applicable only for Horizon Edge Service and Web Reverse Proxy Service.
- Extended Master Secret support is now enabled for the Admin interface.
- Enhancements to the default value of
Content-Security-PolicyHTTP header sent in HTTP responses from Unified Access Gateway.
- Admin UI Enhancements
- Administrators can now view and delete uploaded X.509 certificates from Admin UI.
- Enhancements to REST APIs Beta
- REST APIs now support Bearer token authentication.
- The REST APIs documentation is available on the Omnissa Developer Portal.
- AzureRM Support Deprecation
- Support for AzureRM module is deprecated by Microsoft on 29 February 2024. See Update your scripts to use Az PowerShell modules by 29 February 2024. Consequently, PowerShell script used to deploy Unified Access Gateway on Azure will no longer support AzureRM module starting with the next Unified Access Gateway release.
- Logging improvements
- Updates to OS package versions and Java component versions
- Omnissa Workspace ONE Tunnel
- Improvements to the Session Authentication with SAML workflow to simplify user session management. For more information, see Tunnel Documentation.
- Introduced
Alert.logandAudit.login addition to theAccess.logfor the Tunnel Gateway service. This can be downloaded as part of the UAG log bundle.
Before You Begin
-
Compatibility Notes
For more information about the compatibility of Unified Access Gateway with other products, see Product Interoperability Matrix. -
Install and Upgrade
To download the Unified Access Gateway, see the Product Download page. -
Security Scan
Owing to the OS update, special instructions are required to get accurate scan results of the operating system used by the Unified Access Gateway appliance. For more information, see Security scanning of Linux on Unified Access Gateway (UAG) version 2412 and beyond (6000738).
Resolved Issues
- UAG-11578: Modifying default gateway from the Admin UI does not take effect.
- UAG-11739: Configuring a second syslog server or modifying an existing syslog server configuration does not work.
- UAG-11697: Services fail to start on AWS with instances that support ENA.
- UAG-11556: Hourly log rotation of some log files does not work.
- UAG-11518: Grub password is same as root password.
Known Issues
-
ESC-63850: X.509 certificate authentication might fail with
Internal server errorunder high concurrent request load when revocation checking is enabled and CRL/OCSP endpoints exhibit slow response times.
Workaround-
Backup the configuration file.
cp /opt/omnissa/gateway/supervisor/conf/cas.ini /opt/omnissa/gateway/supervisor/conf/cas_backup -
Add the following property:
sed -i "s|-jar|-Dcertauth.business.concurrency.factor=2000 -jar|g" /opt/omnissa/gateway/supervisor/conf/cas.ini -
Run the command:
supervisorctl reread && supervisorctl update
-
-
UAG-12430: Importing UAG settings with Workspace ONE Intelligence fails with the error
Please select a valid WS1 intelligence credentials file for import. -
UAG-11798: Administrators are not notified if an error occurs while saving the network settings in the Admin UI.
Example: When Administrators save an IP that is already in use, Unified Access Gateway does not accept the IP. However, Administrators are not notified about the error.
- UAG-13396: Stack trace disclosure from an API, under certain conditions.
Workaround:
This issue has no functional impact. Currently, there is no workaround. - UAG-13953: When UAG SAML configuration is read through certain APIs, the system triggers false-positive
CONFIG_CHANGEaudit log entries.
Workaround: This issue has no functional impact. Currently, there is no workaround.
Documentation
Documentation for Unified Access Gateway is located at Omnissa Product Documentation.
Support Contact Information
To receive support, access Customer Connect.
For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge Base (KB) article 6000005.
Localization
For details on Omnissa’s localization strategy, see Announcing Omnissa Localization Support.
Was this page helpful?