Kisco Systems
SafeNet/i : Support : Enhancements and New Features

The following is a list of recent changes and improvements made to SafeNet/i. Most changes are made as the direct result of a customer request. If you have changes you would like to see made to SafeNet/i, e-mail us at support@Kisco.com and we'll add your change to our list of possible implementations.


Register your E-mail address to receive an automatic notification when this product is updated.


SafeNet/i Recent Changes Log

Index:

SafeNet/i Release 12 Updates:

SafeNet/i Release 11 Updates:

SafeNet/i Release 10 Updates:


Release 12 Updates:

12.02: SQL Special Register logging, SIEM CEF support, and various fixes

  • Added support to log SQL Special Register data for custom reporting around SQL access from ACS, AI tools and other sources
  • Expanded built-in SIEM support to include CEF formatted feed data
  • Adds support for IBM-supplied QSECOFR_NC user profile in V7R6 only
  • Problems with the Print Security Report (PRTSECRPT) have been corrected
  • The Work User to Object Security (WRKUSROBJ) process could fail under certain conditions
  • Certain user reports could fail
  • The On-Line Transaction Testing (PCTESTR) was not parsing the SELECT FROM TABLE command correctly
  • A new DROP SQL statement was not being parsed correctly
  • Incorrect error messages could report that SAFELOGING was not running when starting the ransomware process when, in fact, it was already active
  • The PRTSECRPT report could indicate SSL=*YES when no SSL was in effect for Telnet
  • A CPF1035 message could show up during deactivate when all subsystem had already been stopped.

This update is available via the Internet as a PTF package PCPTF1202. Registered customers of SafeNet/i can obtain this PTF by requesting it from support@kisco.com.


12.01: Ransomware updates, bug fixes and more

  • Added Event Special Action and Event Special Rollback commands to each of the Ransomware Detection programs in the Ransomware module.
  • Ability to run the ENABLEIFS command from the Ransomware menu (SNRWD). This command allows you to easily reenable NetServer users from a command line.
  • Added the *NOCONNECT parm to the Change Alert Notification command (CHGNOTIFY). Used for ignoring *FILESRV Connect Failures.
  • Added a Server Prompt in the PCREVIEW display.
  • Added the ability to run all menu commands on the SNRWD menu. (Some commands would not work without adding the library first.)
  • Fixed the Security Report (PRTSECRPT) to work for Default *SPECIAL server.
  • Fixed a minor bug in the Swapping feature (cleared a field).
  • Added Ransomware statistics to Executive Summary & Diagnostic reports.

This update is available via the Internet as a PTF package PCPTF1201. Registered customers of SafeNet/i can obtain this PTF by requesting it from support@kisco.com.


Release 11 Updates:

11.64: Ease of use updates, and more

V7R3 is no longer supported. Customers upgrading to SafeNet 11.64 should be on V7R4 or higher.

This release includes these improvements and changes:

  • Added full support for the enhanced *FileSrv exit point PWFS0200. This allows for the better control of CopyTo, RenameTo and MoveTo IFS operations.
  • Ability to Omit certain IP Addresses from the Security Report.
  • Easier to run the Usage Reports over Archived Transaction Files.
  • New commands for Adding and Removing SafeNet Super Users.
  • Enhanced the Usage Report performance by converting to SQL from legacy I/O.
  • Enhanced Transaction Purge process when using *MINDISK option
  • Deprecated legacy support for *SHORT path names.

This update is available via the Internet as a PTF package PCPTF1164. Registered customers of SafeNet/i can obtain this PTF by requesting it from support@kisco.com. Instructions for installing the PTF will be provided. You must be current on all prior Release 11 PTFs before you can install this change.


11.59: Support for CL commands in SQL

This release adds support for SQL access controls based on CL commands parsed from a SQL request.

This update is available via the Internet as a PTF package PCPTF1159. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from support@kisco.com. Instructions for installing the PTF will be provided along with the file. You must be current on all prior Release 11 PTFs before you can install this change.

With this release requires OS 7.3 or higher. 7.2 is no longer supported.


11.57: Support for new SQL verbs

This release addresses a problem where several newer SQL verbs are not being recognized by SafeNet/i and are getting rejected. Changes made in 11.56 caused "Unknown" verbs to get rejected, leading to unexpected rejections with some customers. The new verbs are CREATE ALIAS, DROP ALIAS, CREATE OR REPLACE, and VALUES.

This update is available via the Internet as a PTF package PCPTF1157. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from support@kisco.com. Instructions for installing the PTF will be provided along with the file. You must be current on all prior Release 11 PTFs before you can install this change.


11.56: SQL comments and new admin parameter

Updated the SQL parser code to bypass –double hyphened SQL statements (commented script lines).

Added a parameter to CHGSPCSET called RSTREGADM (Restrict Regular Admin?) The default is *YES restricted. This alternately allows you to turn OFF the normal regular admins restriction to *ALLLIB/*ALL object, *ALL Commands and the /* root IFS directory entries in WRKUSROBJ, WRKUSRCMD and WRKUSRPTH. It also removes the Regular Admin restriction to QGPL and QUSRSYS library entries in WRKUSROBJ.

This update is available via the Internet as a PTF package PCPTF1156. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from support@kisco.com. Instructions for installing the PTF will be provided along with the file. You must be current on all prior Release 11 PTFs before you can install this change.


11.55: SMS integration and FTP 2FA

SafeNet/i now integrates with our navtive IBM i SMS product, kConnect. This is a much more reliable way to send alerts and 2FA than the outdated email-to-text method. A separate product license is required.

This release also includes support to add 2FA authentication to FTP logins via the FTP exit point. See documentation for details.

This update is available via the Internet as a PTF package PCPTF1155. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 11 PTFs before you can install this change.)


11.53: SQL parsing updates.

A new SQL verb, "VALUES", is now supported.

If a SQL statement includes a verb that is unknown to SafeNet/i, it will be shown on the On-Line Transaction Tester as *Unknown. If the SQL exit point is set to level 4, it will be rejected.

This update is available via the Internet as a PTF package PCPTF1153. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 11 PTFs before you can install this change.)


New option to log rejects to QAUDJRN.

An option has been added to SafeNet/i that lets you optionally post SafeNet/i rejects to the IBM i OS system security journal (QAUDJRN).

This update is available via the Internet as a PTF package PCPTF1114. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 11 PTFs before you can install this change.)


Significant performance enhancement.

For customers running the most recent versions of the IBM i OS (7.3 with TR8 applied or later), we have added a new environment option to use the native IBM SQL parsing routine. Prior to this point we found that the IBM routine was not as efficient as our own home grown parser. With recent changes in the IBM i OS we now know that the IBM routine works much better. SafeNet/i has been updated to give customers a choice as to which SQL parsing routine to use to enforce object security.

This update is available via the Internet as a PTF package PCPTF1112. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 11 PTFs before you can install this change.)


Support Added for new SQL Verbs.

Support has been added for the SQL verbs "SET SESSION" and "SET SESSION_USER".

This update is available via the Internet as a PTF package PCPTF1111. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 11 PTFs before you can install this change.)


QRadar interface enhanced.

At the request of several customers, the QRadar interface has been enhanced to allow for all SafeNet/i Transaction History to be fed to QRadar. Prior to this update, only rejected transactions were made available.

This update is available via the Internet as a PTF package PCPTF1110. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 11 PTFs before you can install this change.)


Socket exit points now optional.

Several customer have reported that following upgrading to SafeNet/i Release 11, which now includes support for three TCP/IP Socket exit points, they were seeing performance issues on their system. Some customers apparently have a very high level of socket activity on their systems. To avoid performance issues and allow customers to phase in Socket exit point controls, we have now made implementation of the Socket exit points optional.

When you first upgrade to release level 11.08 or higher from Release 10 or earlier, the Socket exit points will not be activated. There is now an article on the FAQ page in SafeNet/i support with specific instructions on how to active (or de-activate) these specific exit points.


Two-Factor Authentication Feature Added.

A Two-Factor signon authentication (2FA) feature has been added to SafeNet/i. It can be used in conjunction with the SafeNet/i Web-Central browser interface for SafeNet/i administration and it can also be used for implemention of 2FA for your 5250 terminal signon processes.


New release now available.

Kisco announced a new release of SafeNet/i today, Release 11. The new release features new TCPIP socket access controls along with a redesigned user interface that brings all rules together in a single display. Please review the website for more details, including the press release section.


Release 10 Updates:

Two new support commands added to SafeNet/i.

Two new commands have been added to SafeNet/i that customers can use at their discretion.

The new LOGTOSAFE command can be used to create custom log entries in the SafeNet/i Transaction History file. This allows customers to add content to the Transaction History of their own authorship. This can help especially when the customer is also using the interface to IBM's QRadar software.

The new SNIRESYNC command can be used by customers for force reindexing of user indexes and user spaces when control files use by SafeNet/i are updated by a process other than the menu options or web interface provided in SafeNet/i. This can happen when files are updated on one system and then automatically transferred to another system that is also running SafeNet/i.


Utilization Reports by Group Profile.

When running the utilization reports from the SN4 menu, you can now specify a single Group Profile as a selection and all activity for that profile will then be included in the utilization report.

Also included in this update, all activate and de-activate processes in SafeNet/i are now being logged to the Transaction History file.

This update is available via the Internet as a PTF package PCPTF1046. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.)


Utilization Reports *OUTFILE option enhanced.

When running the utilization reports from the SN4 menu, a new option has now been added when you specify to create an *OUTFILE rather than a printed report. The new option will allow you to either *ADD records to a pre-existing file or *REPLACE records in the file. Using this option, multiple reports and be run on selected users to build up a comprehensive database for your reporting.

This update is available via the Internet as a PTF package PCPTF1044. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.)


User exit parameters updated for the FTP Logon point.

The optional user exit program for the FTP Logon point has been changed so that the parameters passed match those used by the IBM OS exit point. See the PTF documentation for more details. If a customer has a user exit registered to the FTP Logon point through SafeNet/i, advance planning for this change is required.

This update is available via the Internet as a PTF package PCPTF1042. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.)


New Copy To Remote (CPYTORMT) command added.

A new command has been added to the SafeNet/i product to facilitate copying rules and rule sets from one system to another that is also using SafeNet/i.

This update is available via the Internet as a PTF package PCPTF1042. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.)


Logging of profile swap activity added.

SafeNet/i has now been updated to log user profile swap activity. Prior to this update, customers had to verify swap information using the system security audit journal. Now, swap activity will be logged in the SafeNet/i Transaction History file and can be viewed and reported.

This update is available via the Internet as a PTF package PCPTF1041. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.)


Performance Improvements, FTP Logon change, Super-User Lookup change, IPv6 address resolution change.

With this release update, SafeNet/i includes the following changes:

  1. Several performance improvements have been implemented that will help across all applications by implementing user spaces and user indexes to replace traditional file I/O when doing security authentication processing.
  2. The FTP logon process can now optionally log user profile activity in the profile information on the system.
  3. The Super-User authentication process has been streamlined to improve performance.
  4. The IPv6 network address process has been streamlined to improve performance.

This update is available via the Internet as Release 10.40. Registered customers of SafeNet/i can obtain this upgrade by just requesting it from us. It is NOT available as a PTF due to the complexity of the change. To request the upgrade, click on the E-mail link at the start of this page. New customers ordering Release 10.40 or higher will have this new feature included.


Support added for IPv6.

With this release update, SafeNet/i can now capture and report network activity made using the IPv6 Internet protocol for device addressing.

This update is available via the Internet as Release 10.39. Registered customers of SafeNet/i can obtain this upgrade by just requesting it from us. It is NOT available as a PTF due to the complexity of the change. To request the upgrade, click on the E-mail link at the start of this page. New customers ordering Release 10.39 or higher will have this new feature included.


New SQL verb support added & more.

The SQL verb "MERGE INTO" is now supported by SafeNet/i.

In addition, the core object authorization routines have been recoded and optimized to improve performance. The result is even better performance overall for SafeNet/i and better storage use efficiency.

This update is available via the Internet as Release 10.35. Registered customers of SafeNet/i can obtain this upgrade by just requesting it from us. It is NOT available as a PTF due to the complexity of the change. To request the upgrade, click on the E-mail link at the start of this page. New customers ordering Release 10.35 or higher will have this new feature included.


Three significant enhancements added to SafeNet/i.

Three major enhancements have been added to SafeNet/i with this announcement.

First, SafeNet/i now supports context sensitive source IP address access controls. SafeNet/i has always supported source IP address controls for accessing by Telnet and FTP. With this change, this control is extended out to all server functions where the source IP address is available, which means almost all of the security related exit points. And, these controls can be implemented by user profile.

Using this feature, a user profile might be granted access to the system for FTP, but denied access for ODBC from a given source IP address (or IP address range). This will allow customers, for example, to limit ODBC connections to users when they are on site and deny similar access when they are working remotely.

The second enhancement implemented today is that remote Telnet users can now be restricted to only those users who are using an SSL protected connection. For customers using SSL for Telnet sessions, this can guarantee that those 5250 data streams are secure.

The third enhancement is that a new type of SafeNet/i Administrator account is now supported. This new Administrator function is a "read only" admin who can check and review security settings in SafeNet/i but is not permitted to make any changes. This is helpful when going through a security audit and will allow an auditor to review settings without letting them make any changes, accidental or otherwise.

This update is available via the Internet as a PTF package PCPTF1025. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.)


SSL status captured on Telnet connections.

At the request of a customer, we have added additional data about Telnet connections to the Transaction History file, including the SSL status of the connection. Initially, this information is only being displayed using the On-Line Transaction Tester process.

This update is available via the Internet as a PTF package PCPTF1019. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.) New customers ordering Release 10.19 or higher will have this new feature included.


New report command added.

A new report, Print ALL Usage Reports (PRTSNUSG) has been added to SafeNet/i. This will let you run all usage reports for selected profiles which can be helpful in checking to see exactly how a profile is being used on your system.

This update is available via the Internet as a PTF package PCPTF1016. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.) New customers ordering Release 10.16 or higher will have this new feature included.


New transaction testing options added.

At the request of a customer, we have added two new transaction testing options to SafeNet/i.

First, you can now set up a set of rules under the new special user profile of *TESTUSER. Then, using the On-Line Transaction Testing feature already built into SafeNet/i, you can test a set of transactions against this special user profile by asking the tester to do a profile swap with *TESTUSER. This will allow you to test rules changes safely before actually implementing them. The Copy SafeNet User command (CPYSNUSR) has been updated to allow you to copy a set of rules for a given user into *TESTUSER and then, when you are done, to copy the updated rules back to the live user profile.

The second testing change that has been implemented is that the Auto Enrollment reports for each server function (using the PRTxxxUSG commands) have all been updated so that you can test failing transactions. Using this feature, you can retest a failed transaction and discover all possible rules violations, not just the first one found through normal transaction testing.

This update is available via the Internet as a PTF package PCPTF1015. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.) New customers ordering Release 10.15 or higher will have this new feature included.


Several major enhancements implemented - see details.

This update includes the following enhancement to SafeNet/i Release 10:

  1. SafeNet/i can now be fully integrated into IBM's QRadar family of products. The new interface is now documented in a separate set of user instructions available via download from the SafeNet/i website.
  2. Customers can now select the sequence used by SafeNet/i when performing security authorization lookups. Multiple search sequences are now available.
  3. Path requests for QSYS.LIB objects are now standardized.
  4. The various PRTxxxUSG commands (including PRTSECRPT) can now be run against any archive library file.
  5. New performance options are now available when running the SafeNet/i log file purge process (STRPRGARC).
  6. Profile swapping has been enhanced to allow selection of a swap profile based on the server being accessed.

This update is available via the Internet as a PTF package PCPTF1011. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.) New customers ordering Release 10.11 or higher will have this new feature included.


Support for integration with SAP *SQL exit point registration.

Customers who run SAP on their IBM i platform have reported a conflict with the *SQL exit point when the SAP exit program is registered there. When this happens, SafeNet/i sees the SAP exit program and does not register the appropriate SafeNet/i program, flagging the point as level 5. Since the SAP exit point does not provide security features and controls, these customers will want to have SafeNet/i work when the SAP exit program is registered.

SafeNet/i has been upgrade to accomodate this change. Detailed instructions are now included telling our SAP customers how to configure this to use both the SAP exit program and the SafeNet/i exit controls for security.

This update is available via the Internet as a PTF package PCPTF1009. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.) New customers ordering Release 10.09 or higher will have this new feature included.


Limited support for Web-Central Interface added for SafeNet/i customers.

With this change, Kisco is now providing some limited support for the new Web-Central interface for our SafeNet/i Lite customers. The SafeNet/i dashboard will work and access to the transaction history logs is now supported.

This update is available via the Internet as a PTF package PCPTF1001. Registered customers of SafeNet/i can obtain this PTF as an E-mail attached file by just requesting it from us. Instructions for installing the PTF will be provided along with the file. To request the PTF, click on the E-mail link at the start of this page. (Note: You must be current on all prior Release 10 PTFs before you can install this change.) New customers ordering Release 10.01 or higher will have this new feature included.


New release now available.

Kisco announced a new release of SafeNet/i today, Release 10. The new release features a browser based interface to administer the software called "Web Central". Please review the website for more details, including the press release section.