@product.name@ : An Open Source Identity and Entitlement Management Server
@product.name@ v@product.version@ Released !
January 2017
@product.name@ team is pleased to announce the release of version @product.version@ of
the @product.name@ (IS).
@product.name@ is an open source Identity and Entitlement Management server. It supports a wide array of
authentication protocols such as SAML 2.0 Web SSO, OAuth 2.0/1.0a, OpenID Connect and WS-Federation Passive.
It supports role based authorization and fine grained authorization with XACML 2.0/3.0 while
inbound/outbound provisioning is supported through SCIM and SPML.
@product.name@ is developed on top of the revolutionary
WSO2 Carbon platform,
an OSGi based framework that provides seamless modularity to your SOA solution via componentization.
All the major features have been developed as pluggable Carbon components.
You can download this distribution from
http://wso2.com/products/identity-server/.
Online documentation is available at
http://docs.wso2.org/wiki/display/IS530/WSO2+Identity+Server+Documentation.
How to Run
- Extract the downloaded zip
- Go to the bin directory in the extracted folder
- Run the wso2server.sh or wso2server.bat as appropriate
- If you need to start the OSGi console with the server use the property
-DosgiConsole when starting the server.
New Features In This Release
- Improved Identity Management Capabilities : Identity management features in @product.name@ @product.version@,
has been re-designed to provide strong out-of-the-box support for key identity management use cases, including password policies, login policies and account management policies.
- Password policies
- Login policies
- Account management policies.
- Account suspension reminders and locking idle accounts. See
User Account Suspension.
- Password and username recovery with challenge questions or notifications. We also support challenge questions internalization. See
Password Recovery.
- Password reset via admin. For more information, See
Forced Password Reset.
- Google ReCaptcha support for password recovery flow and self sign up. See
Setting Up ReCaptcha.
- Login session monitoring and termination: WSO2 IS now supports monitoring user sessions and authentication activities via alerts, and manual termination of user sessions for better security. See
Terminating User Sessions.
- Rule based provisioning: WSO2 IS @product.version@ has the ability to adopt provision flows based on rules. These rules can be based on entities related to an event such as user, idp, sp as well as environmental factors like time and region.
- Prompt for missing predefined required attributes in the authentication flow: The user will be prompted to fill the missing attributes or claim values, in the event of a missing mandatory claim at the point of login. See
Configuring Claims for a Service Provider.
- OAuth 2.0/OpenID Connect Enhancements: Following OpenID Connect specifications were implemented to enrich the OpenID connect support in Identity Server.
- OAuth 2.0 client secret revocation and regeneration : See
OAuth2 /OpenID connect configurations
- REST profile of XACML. With IS @product.version@, we have added a REST layer on top of the Balana entitlement engine. See
Entitlement with APIs.
- SAML 2.0 Enhancements: Identity server @product.version@ added following specification support to its SAML feature list.
- SAML 2.0 Metadata Profile.
- SAML 2.0 Assertion Query/Request Profile
- Security Analytics: WSO2 IS now detects and provides alerting capability for abnormal and suspicious login sessions. See
Managing Alerts.
- SCIM 1.0 Enhancements : SCIM provisioning API improved to support attribute query.
- Engage access control policies in authentication flow : With WSO2 IS @product.version@ it's possible to evaluate access control policies against an authenticated user in authentication flow.
- Integrated Windows Authentication (IWA) for IS deployed on Linux servers : With this improvement we enable IS deployed on Linux servers to achieve IWA with external Kerberos/NTLM Servers. See
Configure IWA on Linux
- Claim Management Improvement: With this release we relieve the user from the painstaking task of having map claims from one dialect to another indirectly by manipulating mapped attributes. From IS @product.version@, users can easily map claims from two dialects directly without worrying about mapped attributes.
- Identity Management REST APIs : New RESTful interfaces to connect with account registration and recovery flows have been introduced with IS @product.version@.
Known Issues
All the open issues pertaining to @product.name@ are reported at the following locations:
How You Can Contribute
Mailing Lists
Join our mailing list and correspond with the developers directly.
Reporting Issues
We encourage you to report issues, documentation faults and feature requests regarding @product.name@ or in
the Carbon base framework through the public
@product.name@ JIRA or Carbon JIRA.
Support
We are committed to ensure your enterprise middleware deployment is completely supported from evaluation
to production. Our unique approach ensures that all support leverages our open development methodology and is
provided by the very same engineers who build the technology.
For more details and to take advantage of this unique opportunity
http://wso2.com/support/
For more information about @product.name@, please see http://wso2.com/products/identity-server or visit
the WSO2 Oxygen Tank developer portal for additional resources.
Thank you for your interest in @product.name@.
Copyright WSO2 Inc.