Nexus Documentation

Release notes Digital Access component 6.14.0

Release date: 2026-09-10

For installations using docker-compose (that is, not Swarm or Podman), please contact support for instructions on how to proceed with this upgrade.

Database backup recommended before upgrade:
This release introduces schema changes (OAuth 2.0 JWT access-token support and widened id_token columns for ML-DSA-signed tokens).

Also, if upgrading from a version below 6.13.0, password hashing will be carried out which also strongly suggests database backup of the databases. Rollback requires restoring the pre-upgrade database state.

Oracle-specific note:
id_token column widening is performed by dropping/recreating the column (Oracle does not support in-place conversion for this case). Existing id_token values are intentionally not preserved. These values are short-lived/single-use, so practical impact is limited to users mid-login during upgrade.

TLS protocol changes:
TLS 1.0/1.1 options were removed from Access Point inbound TLS configuration and admin UI. Existing TLS 1.0/1.1 settings are removed on upgrade. Validate legacy-client compatibility before enforcing quantum-safe TLS posture.

New Features

Jira ticket number

Description

DA-2837

Post-Quantum OIDC tokens
Smart ID Digital Access can now issue OpenID Connect access and identity tokens post-quantum-signed with ML-DSA (NIST FIPS-204) using the RFC 9964 JOSE algorithms ML-DSA-44/65/87

DA-2836

Post-Quantum TLS on the Access Point (hybrid ML-KEM)
Access Point TLS now supports custom Key Exchange Groups (e.g. X25519MLKEM768: NIST ML-KEM-768 + classical X25519). This can be used to enforce strict hybrid post-quantum key exchange, rejecting peers without ML-KEM support.

DA-814

64-bit (x86_64) Access Point
The Access Point is now built and shipped as a native 64-bit binary; build and packaging moved to amd64 as the primary artifact and the legacy i386 build is retired.

DA-2747

JWT Profile for OAuth 2.0 access tokens
Access tokens can now be issued as signed JWTs (RFC 9068), enabling local validation via JWKS, in addition to opaque tokens.

DA-2806

OpenID Federation (Sweden Connect) RP support
Adds experimental Relying Party support for OpenID Federation, preparing for the Swedish national e-identity Sverige-id, with improved OIDC logging.

DA-2637

CORS response headers for OIDC
DA now emits CORS (Cross-Origin Resource Sharing) response headers on its OIDC/OpenID Provider flow endpoints, enabling cross-origin browser-based applications to complete login flows.

DA-2847

Back-Channel Logout: typ header and jti replay prevention
Logout tokens now use the logout+jwt JOSE typ header, and received logout tokens are checked for jti replay, per OIDC Back-Channel Logout 1.0.

Corrected bugs and hardening tasks

Jira ticket number

Description

DA-2865

Certificate authentication fix after 6.13 upgrade (TLS 1.2)
Fixed a regression that could cause smart-card certificate logins to fail with HTTP 403 due to an unintended short certificate-selection timeout.

DA-2587

Nested AD groups missing from OIDC claims
Nested Active Directory group memberships are now correctly included in memberOf-based OIDC claims.

DA-2843

Secure OATH showed a hardcoded issuer
Secure OATH profiles again display the issuer configured under Policy Services > Global Policy Service Settings instead of a hardcoded value.

DA-2857

Access Point ignored host time zone in logs
The Access Point now logs in the host's local time zone instead of silently falling back to UTC.

DA-2833

Slow upgrades
Fixes excessively slow upgrades caused by inefficient use of reflection.

DA-2770

OIDC scope-name validation
Scope-name validation now follows RFC 6749 §3.3 (colon allowed; space, backslash and double-quote rejected).

DA-2811

Reserved "openid" scope creation blocked via API
The REST APIs now reject creating a scope named openid, matching the UI and preventing conflicts with built-in behavior.

DA-2825

Input validation added to Admin REST API v3
The Administration REST API v3 now validates inputs across Transaction Signature, ACME endpoint and SAML federation/attribute-template configuration (URL format, enum values, uniqueness, empty and XSS-unsafe values), rejecting malformed requests that were previously accepted.

DA-2832, DA-2834

Container image hardening
The Digital Access service container images have been hardened, reducing the attack surface of the shipped images.

DA-2851

XML External Entity (XXE) hardening
XML parsing is now securely configured (DTD and external entities disabled).

DA-2852

User Directory lookup validation
User-directory lookups now escape and validate user-supplied input

DA-2856

Updated jackson-databind to address HIGH-severity advisories
jackson-databind was upgraded (2.21.1 to 2.21.4) to resolve two HIGH-severity security advisories.

DA-2864

Vulnerability fixes in Java libraries and base images
Updated third-party Java libraries and container base images to clear known vulnerabilities.

DA-2866

OpenID Connect login no longer fails with "State does not match"
Fixes an OIDC authentication failure where the state value stored in the DA session could be overwritten, causing a spurious "State does not match" rejection.




Last updated: