Release date: 2026-09-10
For installations using docker-compose (that is, not Swarm or Podman), please contact support for instructions on how to proceed with this upgrade.
Database backup recommended before upgrade:
This release introduces schema changes (OAuth 2.0 JWT access-token support and widened id_token columns for ML-DSA-signed tokens).
Also, if upgrading from a version below 6.13.0, password hashing will be carried out which also strongly suggests database backup of the databases. Rollback requires restoring the pre-upgrade database state.
Oracle-specific note:
id_token column widening is performed by dropping/recreating the column (Oracle does not support in-place conversion for this case). Existing id_token values are intentionally not preserved. These values are short-lived/single-use, so practical impact is limited to users mid-login during upgrade.
TLS protocol changes:
TLS 1.0/1.1 options were removed from Access Point inbound TLS configuration and admin UI. Existing TLS 1.0/1.1 settings are removed on upgrade. Validate legacy-client compatibility before enforcing quantum-safe TLS posture.
New Features
|
Jira ticket number |
Description |
|---|---|
|
DA-2837 |
Post-Quantum OIDC tokens
|
|
DA-2836 |
Post-Quantum TLS on the Access Point (hybrid ML-KEM)
|
|
DA-814 |
64-bit (x86_64) Access Point
|
|
DA-2747 |
JWT Profile for OAuth 2.0 access tokens
|
|
DA-2806 |
OpenID Federation (Sweden Connect) RP support
|
|
DA-2637 |
CORS response headers for OIDC
|
|
DA-2847 |
Back-Channel Logout: typ header and jti replay prevention
|
Corrected bugs and hardening tasks
|
Jira ticket number |
Description |
|---|---|
|
DA-2865 |
Certificate authentication fix after 6.13 upgrade (TLS 1.2)
|
|
DA-2587 |
Nested AD groups missing from OIDC claims
|
|
DA-2843 |
Secure OATH showed a hardcoded issuer
|
|
DA-2857 |
Access Point ignored host time zone in logs
|
|
DA-2833 |
Slow upgrades
|
|
DA-2770 |
OIDC scope-name validation
|
|
DA-2811 |
Reserved "openid" scope creation blocked via API
|
|
DA-2825 |
Input validation added to Admin REST API v3
|
|
DA-2832, DA-2834 |
Container image hardening
|
|
DA-2851 |
XML External Entity (XXE) hardening
|
|
DA-2852 |
User Directory lookup validation
|
|
DA-2856 |
Updated jackson-databind to address HIGH-severity advisories
|
|
DA-2864 |
Vulnerability fixes in Java libraries and base images
|
|
DA-2866 |
OpenID Connect login no longer fails with "State does not match"
|