Skip to main content

September 4, 2026

Omnissa Unified Access Gateway Release Notes

Unified Access Gateway 2512 | 16 DEC 2025
Unified Access Gateway 2512.1 | 02 MAR 2026

Unified Access Gateway appliances provide users with secure remote access to virtual desktops, internal sites, applications, and file repositories. To learn more, see Unified Access Gateway Documentation.

Omnissa Unified Access Gateway Release Notes provide information about the new features and enhancements in each release. This page contains a summary of the new capabilities, issues resolved, and known issues that are reported in each version.

What's New - 2512.1

Updates to OS package versions

  • Updated security patch for OpenSSL package, which addresses CVE-2025-15467 and other vulnerabilities disclosed.
  • Upon evaluation, there is no impact on Unified Access Gateway. This release includes the latest OS security patches as part of our ongoing commitment to security best practices. For more information, see Omnissa Impact - OpenSSL Security Advisory (6001266).

Tunnel

  • Geolocation Policies with Workspace ONE Tunnel is now in Limited Availability

    • New geolocation-based access rules allow you to enforce access policies tailored to specific regions. This helps organizations maintain regulatory compliance and safeguard sensitive data across different locations while still enabling limited access for traveling users.
    • Contact your Omnissa representative for additional details on the feature and guidance on enablement.

What's New - 2512

Unified Access Gateway 2512 provides the following new features and enhancements:

  • Support for Horizon in extra-large configuration
    Unified Access Gateway now supports extra large configuration for Horizon 8 deployments and can handle up to 4000 Horizon connections. See Unified Access Gateway Sizing Options.

  • Support for adding multiple TLS certificates for Internet interface
    Unified Access Gateway now supports binding up to 10 TLS certificates to the Internet interface for Horizon and Web Reverse Proxy end user flows, with automatic certificate selection using SNI. For more information, see TLS/SSL certificates.

  • Enhancements to Origin HTTP Header feature
    Auto generated origin list now considers URLs specified without a scheme and port as both HTTPS and HTTP, while any origin with a port is considered HTTPS only (even if it is port 80). For more information, see Mandatory Validation of Origin HTTP Header.

  • Enhancements to Host HTTP Header feature
    Unified Access Gateway now validates ports (in addition to the existing validation of hostname) in the Host and X-Forwarded-Host headers of incoming HTTP requests against an allowed list. Previously, only hostnames were considered during validation. For more information, see Host Header Validation on Unified Access Gateway.

  • Enhancements to Tunnel and Blast URLs on Horizon Settings
    Added support for validating Host headers with port numbers, auto generated from the values specified against the Tunnel and Blast External URLs (including additional external URLs), ensuring correct matching when port is present in Host header of the HTTP request arriving at Unified Access Gateway. For more information, see Configure Horizon Settings.

  • Improvements related to deployment on Nutanix

    • Added support for deployment on Nutanix 7.3.
    • Enhanced PowerShell script for Nutanix with a configuration option to disable TLS certificate validation. With this, you are no longer required to follow the workaround if the Nutanix Server is not using a Trusted TLS Certificate. See PowerShell deployment to Nutanix.
  • Enhancements to periodic health check
    The periodic health check interval now accepts values only greater than 10 seconds. Setting the interval to 0 is no longer supported, as this stops periodic health checks and results in Unified Access Gateway being reported as unavailable for serving requests.

  • PCoIP deprecation
    PCoIP is going to be deprecated from Horizon Clients in an upcoming release. Consider switching to Horizon Blast Protocol. See End of support for PCoIP in Horizon in 2025 (6000812).

  • Logging and troubleshooting improvements

  • Updates to OS package versions and Java component versions

    • Updated open-vm-tools to 12.1.5-1, which addresses CVE-2025-41244.
  • Content Gateway
    Support for Certificate-based authentication (CBA) for WebDAV repository.

  • Tunnel
    New server KVP to support TLS 1.3 ciphers. This is separate for the KVP to support TLS 1.2 cipher suites.

    • KVP: openssl_1_3_cipher_list
    • Example:
      • KVP: openssl_1_3_cipher_list
      • Value: TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_AES_128_CCM_SHA256
  • Secure Email Gateway
    Secure Email Gateway logs are now automatically compressed and stored in .gz format.

Before You Begin

Resolved Issues - 2512

  • UAG-12246: When Workspace ONE Tunnel Settings are turned on, DNS resolution for configured host entries might not work as expected.

  • UAG-12430: Importing UAG settings with Workspace ONE Intelligence fails with the error Please select a valid WS1 intelligence credentials file for import.

  • UAG-12542: While deploying using PowerShell script, specifying values against blastUrls and tunnelUrls keys in .ini file do not work.

  • UAG-12244: Gray color radio button (instead of green) displayed against healthy Tunnel Settings on Admin UI.

  • ESC-63850: X.509 certificate authentication might fail with Internal server error under high concurrent request load when revocation checking is enabled and CRL/OCSP endpoints exhibit slow response times.

  • PPAT-20103: UEM Tunnel Dashboard does not populate data throughput widget.

Known Issues - 2512

  • UAG-13054: OIDC authentication fails when launching Horizon native client from Horizon client selector landing page.
    Workaround: Run adminreset --force --advancedFeature disable SamlClientLocationIdValidation through root console (SSH or vSphere web console).
  • UAG-12971: The bottom part of the background of the UAG Admin UI login page is displayed as blank when the web browser's window height is less than 1430 pixels.
    Workaround: No workaround exists for this issue.
  • UAG-13263: "Internal server error" when space is entered as RADIUS password on Horizon client.
    Workaround: No workaround exists for this issue.
  • UAG-13396: Stack trace disclosure from an API, under certain conditions.
    Workaround:
    This issue has no functional impact. Currently, there is no workaround.
  • UAG-13953: When UAG SAML configuration is read through certain APIs, the system triggers false-positive CONFIG_CHANGE audit log entries.
    Workaround: This issue has no functional impact. Currently, there is no workaround.

Documentation

Documentation for Unified Access Gateway is located at Omnissa Product Documentation.

Support Contact Information

To receive support, access Customer Connect.

For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge Base (KB) article 6000005.

Localization

For details on Omnissa’s localization strategy, see the Knowledge Base (KB) article Announcing Omnissa Localization Support.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…