Fixed a connection issue between Smart ID Agent and Identity Manager when reconnecting. In some situations, when having unstable network connections, the reconnect didn't work.
X
CRED-12139
Updated Log4J to version 2.17.1
X
CRED-12316
3rd party library "ehcache" was changing automatically for updates in the internet (calling terracotta.org). The automatic update check has been disabled now.
X
Release announcement
For details on the Smart ID configurations and deployment configurations, see here:
Smart ID configuration release note
-
Smart ID deployment configuration release note
Release notes for Smart ID deployment configuration
All notable changes to the deployment files downloadable from our support portal will be documented here.
[Release 26.07.3-2026-08-13]
Changed
simplified UID/GIDs for docker containers (except Digital Access and Postgres) [CRED-23369] [IDC-2762]
containers effectively run as SmartID's "docker host user" (i.e. either a user belonging to the docker group that can control a rootful docker daemon, or a user which runs the docker daemon in rootless mode)
for a rootful docker daemon the containers internally use the docker host user's UID/GID
for a rootless docker daemon the containers internally use the UID/GID 0
=> effectively file permissions of the host user directly apply inside the containers as well
filesystem ACLs are no longer used
included scripts no longer require sudo permissions (except for Digital Access and one script for upgrading from certain versions, see below)
replaced outdated bitnami rabbitmq docker image with official dockerhub image [CRED-23369] [IDC-2762]
a data migration script is provided (see below)
Added
added set-docker-identity.sh script to determine the UID and GID for most containers (except Digital Access and Postgres) [CRED-23369] [IDC-2762]
always run this as the docker host user without sudo
must be run at least once (most other scripts and docker compose files depend on it!), ./init-smartid.sh will automatically run it
also updates the docker socket volume mount required for Traefik, so it fits for a rootful or rootless docker daemon
added fix-volume-permissions.sh to remove previous changes made by set-rootless-volume-ownership.sh and remove users and groups created by the latter script [CRED-23369] [IDC-2762]
for IDM: only needed when upgrading from 26.04.0, 26.04.1, 26.07.0 and 26.07.1
for PA: only needed when upgrading from 26.04.1 or older, 26.07.0 and 26.07.1
this is the only script that requires to be run by root or a user with sudo permissions
before running this script, executing ./set-docker-identity.sh as the regular docker host user is required
added migrate-rabbitmq-data.sh to migrate data stored by the old bitnami rabbitmq image to the official dockerhub image [CRED-23369] [IDC-2762]
only needed if Physical Accesss is deployed
only needed for upgrades from 26.04.x versions before 26.04.2 or any other version before 26.07.2
execute as final step before starting containers for the first time on upgrade
added configurable port settings for physical access admin portal in smartid.env
fixed vulnerabilities [IDC-2738]
Added
added support for honeywell ebi pacs connector [IDC-2717]
[Release 26.01.4-2026-07-17]
Changed
make hermod-conf.yml use the proper format for Hermod 4.x [CRED-22971]
add missing pass-thru of MESSAGING_SWAGGER_ENABLE variable [CRED-22971]
Updated connectors version to 2607.0.0 in smartid.env [CRED-23001]
[Release 26.07.0-2026-07-02]
Changed
set user and group for Hermod scratch image in set-rootless-volume-ownership.sh. [CRED-23172]
added permissions update of selfservice/config in set-rootless-volume-ownership.sh. [CRED-23285]
[Release 25.11.1-2026-06-02]
Removed
Removed support for the old "docker-compose" notation. Use a recent docker engine version with "docker compose" available [CRED-22502]
[Release 26.04.0-2026-04-10]
Added
Added rootless container support for IdentityManager containers. See docker/compose/set-rootless-volume-ownership.sh. [CRED-21066]
Added memory limitation settings into env files. Users can define desired memory limits per docker instances. [CRED-22875]
Changed
make hermod-conf.yml use the proper format for Hermod 4.x [CRED-22971]
add missing pass-thru of MESSAGING_SWAGGER_ENABLE variable [CRED-22971]
[Release 26.01.2-2026-03-09]
Removed
Removed support for the old "docker-compose" notation. Use a recent docker engine version with "docker compose" available [CRED-22502]
[Release 26.01.0-2026-01-30]
Changed
added correlation-id pattern to log4j2.xml [CRED-21684]
[Release 25.11.0-2025-11-17]
Changed
increased Traefik version to 3.5 (latest patch version is used automatically) [CRED-20868]
Process tracker is now enabled/disabled via log4j2.xml
(via DEBUG level on the respective loggers, which now default to INFO).
System properties are no longer used for this. [CRED-20176]
## [Release 25.08.0-2025-08-19]
### Added
Added OSIP Connector. [CRED-19378]
### Changed
increased Traefik version to 3.2.3
Move connectors to a dedicated connectors folder. [CRED-19378]
Postgres version is set as 16. It will automatically download latest minor version. [CRED-19718]
## Removed
Removed below tools for security vulnerabilities. [CRED-19718]
adminer
datadog
mailhog
[Release 23.10.14-2025-03-27]
Changed
Postgres version is set as 16. It will automatically download latest minor version. [CRED-19718]
Removed
Removed below tools for security vulnerabilities. [CRED-19718]
adminer
datadog
mailhog
[Release 24.11.1-2025-03-14]
Changed
Increased Traefik version to 3.2.3
[Release 23.10.12-2025-02-04]
Added
Added OSIP Connector. [CRED-19378]
Changed
Move connectors to a dedicated connectors folder. [CRED-19378]
[Release 23.10.11-2025-01-09]
Changed
Changed Traefik version to 3.2.3
[Release 23.04.27-2025-01-08]
Changed
Increased Traefik version to 3.2.3
[Release 24.11.0-2024-11-29]
Added
Added a Tomcat web.xml setting a Rate Limit Filter to prevent DoS Attacks. [CRED-16798]
Added the Nexus SVG logo in the selfservice app. [CRED-17286]
restart-all.sh detects whether sudo is needed for docker commands [CRED-18249]
Enable TLS 1.3 for Traefik (was TLS 1.2 only) [CRED-18049]
Updated prime-connectors to 2311.1.0 (based on Ubuntu 22.04) [CRED-13886]
Corrected Hermod and Selfservice setup in WSL dev readme and the configuration. [CRED-17952]
Descriptors in signencrypt.xml now reference P12 keystores created by bootstrapping
instead of dummy files from the respective IDM containers. [CRED-14971]
DNs of bootstrapped certificates cleaned up. [CRED-16809]
Bootstrapping creates separate P12 per use-case. [CRED-16809]
Bootstrapping bash scripts replaced with docker container. [CRED-16808]
Postgresql and cert bootstrap questions in init-smartid.sh default to "no". [CRED-16808]
Updated the selfservice theme file. [CRED-17286]
Changed Postgresql version to 14.12. [CRED-17538]
Changed traefik version to 3.0.2. [CRED-17538]
Removed
"ObjectHistorySigner" descriptor version 1 for expired dummy cert removed from signencrypt.xml. [CRED-14971]
Removed redundant size declaration from jws/jwt signer descriptors. [CRED-16808]
Bootstrapping of user certs for users removed. [CRED-16808]
DNs of bootstrapped certificates cleaned up. [CRED-16809]
The process tracker moved from package de.nexus.projectutils.processtracker
to package de.nexus.flowable.processtracker in the file log4j2.xml and has to be enabled via the
SYSTEM_PROPERTIES environment variable in the file identitymanager/operator/docker-compose.yml. [CRED-17203]
[Release 23.10.6-2024-07-15]
Added
Changed
upgrade to Postgres 16 [CRED-17704]
restart-all.sh detects whether sudo is needed for docker commands [CRED-18249]
Updated prime-connectors to 2311.1.0 (based on Ubuntu 22.04) [CRED-13886]
Corrected Hermod and Selfservice setup in WSL dev readme and the configuration. [CRED-17952]
Changed Postgresql version to 14.12. [CRED-17538]
Changed traefik version to 3.0.2. [CRED-17538]
[Release 23.04.19-2024-07-2]
Added
Changed
Changed Postgresql version to 14.12. [CRED-17538]
Changed traefik version to 3.0.2. [CRED-17538]
[Release 23.10.2-2023-10-30]
Added
Changed
Modified permissions of the 'certs' directory in init-smartid.sh to 755 (to allow Hermod to read the directory). [CRED-16526]
Updated Prime Connectors version. [CRED-16153]
[Release 23.04.7-2023-08-28]
Added
Added missing attestation key config to signencrypt.xml (fixes VSC). [CRED-16128]
Changed
[Release 23.04.5-2023-07-17]
Added
Added a readme-wsl-dev.txt how to setup SmartID Docker containers in a WSL environment. [CRED-15948]
Added environment variable to docker-compose.yml of authentication service.
Changed
Restored environment references for Digital Access and Physical Access containers [CRED-15915]
[Release 23.04.4-2023-06-30]
Added
Added restart-all.sh for easy stopping and starting of all containers or a subset of them. [CRED-15854]
Changed
The variable DOCKER_NETWORK_MTU has the default value 1500 now. You are not forced to choose between several options. [CRED-15854]
When executing init-smartid.sh a message informs you about the current MTU value and when it is recommended to reduce it. [CRED-15854]
The names of most of the docker containers start with "smartid-" by default. This prefix can be changed now via variable DOCKER_CONTAINER_BASE_NAME in file smartid.env. [CRED-15854]
The hostname of the postgresql container now has the DOCKER_CONTAINER_BASE_NAME prefix as well.
Added file .gitattributes to make \.sh and \.env files always containing only LF instead of any CRLF. Fixed file datadog.env accordingly. [CRED-15795]
Changed
Escaped the ESC character (0x1B) in echo statements of shell scripts to avoid problems with Azure file preview and git diff output. [CRED-15795]
[Release 23.04.2-2023-06-02]
Added
Changed
[Release 23.04.1-2023-05-11]
Added
Added init-smartid.env to configure the docker network MTU. [CRED-14088 via CRED-15316]
Added helperFunctions.sh and helperCreateLink.sh to be used by init-smartid.sh. [CRED-14088 via CRED-15316]
Changed
Replace deprecated docker network syntax in docker-compose.yml files. [CRED-14088 via CRED-15316]
init-smartid.sh / stop-smartid.sh detect if docker needs sudo. [CRED-14088 via CRED-15316]
init-smartid.sh now optionally removes files created by previous runs (postgres db, bootstrapped certs, etc). [CRED-14088 via CRED-15316]
No explicit setting of env_file in docker-compose.yml files. [CRED-14088 via CRED-15316]
Messaging database is now configured via MESSAGING_DB_URL var. [CRED-14088 via CRED-15316]
stop-smartid.sh now uses the compose command "down" instead of "stop", which also removes the containers after shutting them down. [CRED-14088 via CRED-15316]
[Release 23.04.0-2023-04-28]
Added
Added Workspace One Connector Docker image. [CRED-14215]
Changed
[Release 22.10.0-2022-09-20]
Added
Added ContentProviderJWSSigner descriptor in signencrypt.xml. [CRED-12232]
Added renewFromKeypairs.sh to renew end-entity certs.
WARNING:
This only works if you (re-)bootstrap with the updated createca.sh, as the old version discarded data required for renewal.
Re-bootstrapping will invalidate any encrypted secrets and history signatures in IDM due to chaning the keys.
Re-bootstrapping will also overwrite the certificates and keys in the docker deployment folder, so make a backup first,
so you can use the respective tools for re-signing and re-encrypting existing history/secrets.
Changed
automatically (re-)start mailhog
fixed naming of traefik rules for mobile-iron
Changed createca.sh to retain keypairs and CA metadata, so we can enable renewal (see above).
Removed cRLSign attribute from ca.conf to avoid issues with failing CRL checks.
NOTE: This only has an effect on newly bootstrapped CAs.
[Release 22.04.0-2022-05-05]
Added
Added Mobile Iron Docker image. [CRED-11817]
Added new properties for MI image in smartid.env. [CRED-11817]
Changed
Changed properties for Nexus GO Cards API V2. [CRED-12951]
[Release 21.10.0-2021-11-09]
Added
Added Digicert Global Root CA certificate. [CRED-11688]
Added some Let's Encrypt root certificates. [DEVOPS-971]
Added documentation for maxProfiles option to hermod-conf.yml
Added .yamllint file to set default YAML linting config. [DEVOPS-1085]
Added volume mapping for logs folder in IDM and Self Service. [DEVOPS-403]
Fixed cacerts folder permissions in init-smartid.sh script.
Added support for docker compose v2 command in init-smartid.sh script.
Changed
New properties for CAAS credentials in smartid.env (placeholders must be replaced before using Nexus GO Cards). [CRED-11688]
Fixed some copy issues in the init-smartid.sh script.
Changed the default selfservice config to include auth methods params example.
It is now possible to change IDM language settings via system properties. [DEVOPS-860]
It is now possible to change Self-Service configuration via CONFIG_JSON environment variable. [DEVOPS-945]
Fixed typo. [DEVOPS-1090]
Replaced Self-Service IDM_URL, INSTANCE_ID, IDM_TENANT by APPLICATION_YAML json. [DEVOPS-1127]
Set logging driver to json-file (the default one) for all containers explicitly [DEVOPS-1136]
Fixed YAML format. [DEVOPS-1085]
IDM and SelfService now support custom translations and do not require mapping the whole translation files again. See doc for more info. [DEVOPS-1118]
Change Import Logger to correct class [DEVOPS-1143]
Switched to new image naming for IDM
nexus-prime/explorer changed to smartid/identitymanager/operator
nexus-prime/designer changed to smartid/identitymanager/admin
nexus-prime/tenant changed to smartid/identitymanager/tenant
nexus-prime/updatedb changed to smartid/identitymanager/updatedb
Removed translation files for IDM and SelfService. [DEVOPS-1118]
[Release 21.04.0-2021-05-20]
Added
Default values for Selfservice tenant id and instance id. [DEVOPS-738]
Added example format for MSSQL everywhere we build the DB URL (${DBHOST}/${XX_DB_NAME}) because MSSQL requires a different URL format. [DEVOPS-737]
Include SANs from CSR in bootstrap TLS cert in bootstrap/conf/ca.conf.
Generate tls certificate for non-treafik setup in bootstrap/createca.sh.
Log4j2 config and template for json layout [DEVOPS-758]
Datadog agent compose file, with some examples, see nexus and datadog documentation if you want to use it [DEVOPS-759]
Added a check in init-smartid.sh that exits the script if user didn't fill the mandatory properties in smartid.env (thoose with <XX> value pattern). [DEVOPS-759]
IDM DB will no longer be initialized through init-smartid.sh script. Initialisation has to be done manually by starting container in identitymanager/updatedb. [DEVOPS-739]
Rename containers to use dash instead of underscore, so containerName can work for DNS lookup (underscore is not allowed in DNS names).
WARNING! This can cause issues if you use the new config with existing containers using the old names!
Align idm update db naming to use the name "updatedb" everywhere
WARNING! This can cause issues if you use the new config with existing containers using the old names!
Align digital access directory names with service names
fix bootstrap cert folder permissions in init script
Changed all HERMOD*\* properties to MESSAGING*\*. [DEVOPS-751]
Moved each component's respective config into their own config folder. [DEVOPS-751]
Made all volume mappings static in compose file, no more properties. [DEVOPS-751]
Reorganized smartid.env to be split by component, making it easier to find component related properties. [DEVOPS-751]
Internal ports (inside docker) are now static in the compose file. [DEVOPS-751]
Moved postgres related properties outside smartid.env, because it is a separate tool not meant for production. [DEVOPS-751]
Renamed service names in compose files to match their container name. [DEVOPS-751]
Changed traefik version to 2.4.8. [DEVOPS-638]
Changed file extension of generated certificates from .base64 to .cer.
Updated translation files for IDM. [DEVOPS-761]
Updated Messaging config for 21.04 (Hermod version 3.1.1). [DEVOPS-802]
Changed chmod command to give permission 700 instead of 600, because hermod needs execute permission.
Updated SmartID version to 21.04
Fixed
Fixed typos in the strings that are echoed to the user during the initialisation. [DEVOPS-646]
Removed
Removed unused properties in smartid.env. [DEVOPS-751]
Removed unused ports for Physical Access. [DEVOPS-752]
Removed Physical Access config files. Configuration is now handled using environment variables. [DEVOPS-752]
Removed TZ from all docker-compose files. Since it is set in smartid.env which is mapped using env_file, declaring the variable a second time in env was not necessary.
[Release 20.11.2-2021-03-23]
Added
If you say Yes to the question if Digital Access shall be deployed in the host, it will make it possible for the containers to listen on 80 and 443. [DEVOPS-540]
Changed
Bump SmartID version to 20.11.2
Updated IDM translation files with newer ones. [DEVOPS-561]
Adjust volumes for hermod certificates. [DEVOPS-651]
Removed Selfservice hotfixes introduced in previous release. [DEVOPS-626]
Fixed
Fixed tenant startup by removing mapped sign encrypt configuration, so it uses the default one from inside the container. Since IDM Tenant uses less certificates, the same config as IDM operator or admin cannot be used.[DEVOPS-640]
Fixed the copy_files.sh script used in IDM operator, admin and tenant [DEVOPS-692] + [DEVOPS-656]
[Release 20.11.1-2021-02-18]
Added
Added issuing and root CA certificates to IDM containers for config signing (These certs should NEVER be used for production). [DEVOPS-549]
Added hotfix for SelfService -> IDM connection [DEVOPS-626] Has to be removed with 20.11.2+
Changed
Update sign-encrypt engine to the newest state. [DEVOPS-549]
Update version number to 20.11.1
[Release 20.11.0-2021-02-01]
Added
Added mailhog as tool in /tools/mailhog. The tool can be used to test to send emails in Digital Access and Identity Manager. [DEVOPS-482]
Changed
Set false on traefik network in the traefik, adminer and mailhog to be enabled in traefik by default. [DEVOPS-486]
Changed file extension of generated certificates from .crt to .base64
Changed so that identity manager Admin and Operator do not require signed configurations/modules for uploading and downloading them by default. [DEVOPS-515]
Added support for selfservice branding. [DEVOPS-471]
Added log4j volume mapping for idm containers. [DEVOPS-470]
Changed
Updated traefik version to 2.3.4 [DEVOPS-464]
Renamed selfservice container from "idm_selfservice" to "selfservice".
Renamed all environment variables starting with "IDM_SELFSERVICE_x" to "SELFSERVICE_x".
Changed Hermod config to disable by default some end-points and to hide sensitive data in logs. [DEVOPS-484]
Improved the stop-smartid.sh script to handle dynamically all docker-compose stop commands and to work regardless of where the script is called from.
Improved the init-smartid.sh script to work regardless of where the script is called from.
Improved the createca.sh script to work regardless of where the script is called from.
Renamed idm-selfservice-language.json to idm-selfservice-config.json.
Fixed
Fixed volume mapping for selfservice tomcat server.xml by using a separate variable than identitymanager.
Fixed French translations for IDM and Selfservice.
[Release 20.11.0-2020-12-07]
Added
Added postgres/init/init-smartid-databases.sql so that Physical Access database is created when starting up postgres. The "pauser" is created, and a default password is set.
Added LE CA Certificate to cacerts. [DEVOPS-455]
Added AJP port variables in smartid.env and use them in identitymanager docker-compose files. Also added AJP Connector in config/idm-tomcat-server.xml, which has to be enabled manually (and port set accordingly). [DEVOPS-348]
Add following new features to the identitymanager docker-compose files: [DEVOPS-406]
Support for new CA store volume mapping
Support for new system properties environment variable
Support for new DB properties environment variables
Support for new spring bean volume mapping. See IDM_VOLUME_PATH_SPRING in smartid.env.
Support for new jars volume mapping. See IDM_VOLUME_PATH_LIBS in smartid.env.
Support for new class files volume mapping. See IDM_VOLUME_PATH_CLASSES in smartid.env.
Add following new features to the selfservice docker-compose file: [DEVOPS-406]
Support for new CA store volume mapping
Support for new IDM url environment variable
Added adminer as tool [DEVOPS-407]
Added maxVersion for TLS to be 1.2 due to compatibility issues with some mobile devices. [DEVOPS-413]
Changed
Changed smartid version to 20.11.0.
Moved "/certs/boostrap" to "/boostrap".
Changed postgres version in smartid.env from 9.6.18 to 12.5. [DEVOPS-431]
Split identity manager containers into their own docker-compose files: [DEVOPS-382]
Added identitymanager/admin/docker-compose.yml
Added identitymanager/tenant/docker-compose.yml
Added identitymanager/init-db/docker-compose.yml
Added identitymanager/operator/docker-compose.yml
Adapted init-/stop-smartid.sh, and paths inside smartid.env and some docker-compose files to fit new docker-compose yaml files. [DEVOPS-382]
Change the ini-smartid.sh script to ask if traefik is going to be used as Ingress/proxy. [DEVOPS-408]
Changed in config/hermod-conf.yml some values to <IDM-HOST-HERE> and <DA-HOST-HERE> on client samples.
Removed
Removed MSSQL from deployment package, since Physical Access now support postgres. [DEVOPS-448]
Removed entrypoint definition from identitymanager docker-compose files. [DEVOPS-406]
Removed pgAdmin and portainer and its variables from smartid.env. [DEVOPS-407]
Removed modern and old options for tls in config/traefik/traefik-tls.yml. [DEVOPS-413]
Removed TRAEFIK_TLS_OPTION from smartid.env. [DEVOPS-413]
Removed identitymanager spring beans because we changed how handle them.
Removed samples.
[Release 20.06.1-2020-10-27]
Added
Added port forwarding to hermod container in the messaging docker-compose file.
Added spring bean files for identitymanager in config/idm/spring_operation and spring_admin.
Added translation files for identitymanager in config/idm/translation_idm and for selfservice in config/idm/translation_selfservice.
It is now possible to enable Strict SNI using TRAEFIK_TLS_STRICTSNI=true
Changed
changed smartid version to 20.06.1.
Changed HERMOD_DOMAIN_PREFIX from "mb" to "messaging".
Changed the DB init/update script behavior, can be controlled with IDM_DBUPDATE_SCRIPT in smartid.env.
Changed traefik-tls.toml file to YAML and used variables from .env file. Possibility to change TLS certificate file names TRAEFIK_TLS_DEFAULT_CERTIFICATE and TRAEFIK_TLS_DEFAULT_CERTIFICATEKEY.
Improved the init-smartid.sh script.
Moved seflservice to a separate docker-compose file.
Fixed
Fixed the jdbc url for config/da-admin-customize.conf.
Removed
Dropped restart: always for identittymanager init-db.
Removed explicit DBHOST naming in smartid.env to force user to set its own value.
[Release 20.06.0-2020-09-28]
Added
Added possibility to add custom-beans for IDM Operator and Admin, in config/idm.
Added possibility to change translation for IDM Operator, Admin, Selfservice and Tenant.
Added IDM_DB_QUARTZ example for MSSQL, Oracle and DB2.
Added container_name for all containers in:
identitymanager/docker-compose.yml
traefik/docker-compose.yml
Added docker hostname for postgresdb DB_HOST in postgres/docker-compose.yml, this will make test deployment work from start.
Added docker hostname for mssqldb PA_DB_HOST in mssql/docker-compose.yml.
Added restart: always to all containers. All containers will the start up after re-boot, if they have been started once before.
Included SAML example files for IDM in /samples/idm_saml.
Changed
Changed smartid version to 20.06.0.
Changed explorer/operator url in idm-selfservice-application.yml.
Changed location of Identity Manager SAML samples files from /docker/compose/examples to /samples/idm_saml.
Updated init-smartid.sh:
Now check if docker and docker-compose are installed, if not the script will exit.
Now asks if the deployment is a production deployment, if "Yes", the script will complete and deployment configuration can be done. If "No":
Ask if postgres and/or mssql shall be deployed and started.
Fixed
Moved comments in smartid.env file to be on a separate line instead of behind the value. This was breaking the applications since comments would be evaluated as part of the value.
Fixed init-smartid.sh so that it works properly on CentOS.
Fixed a typo for variable IDM_DB_QUARTZ.
Fixed typo in idm-operator container in identitymanager/docker-compose.yml, in the path to the castore.jks.
Removed
Removed init-smartid-test.sh, it is included in init-smartid.sh.
Contact
Contact Information
For information regarding support, training and other services in your area, please visit our website at www.nexusgroup.com/.
Support
Nexus offers maintenance and support services for Smart ID components to customers and partners. For more information, please refer to the Nexus Technical Support at www.nexusgroup.com/support/, or contact your local sales representative.