Announcement date: February 6, 2024
What's new
Support for provisioning Service Points on Nutanix Acropolis
Starting in Service Point 4.6.2, you can now provision the service point on Nutanix Acropolis v6.5.3.6 LTS or greater.
Support for provisioning Service Points on BlueCat hardware appliances
- XMB4
- BDDS-25
- BDDS-50
- BDDS-75
- BDDS-125
Resolved issues
Cannot redeploy service instances on a Service Point after the service had been deployed and deleted
Service Point v4.6.2 introduces a fix for an issue discovered where redeployment of service instances to a Service Point would fail if the service instance was previously deployed to the Service Point and deleted.
CVE-2023-48795: SSH Terrapin vulnerability
Service Point v4.6.2 includes a fix for CVE-2023-48795.
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers.
Changes to service point health check reporting of nameservers
Previously, the service point health check of nameservers would report an UNHEALTHY status if one or more nameservers were unreachable or not functioning correctly. Service Point v4.6.2 introduces a relaxed validation of the nameservers health check and will report a HEALTHY status if at least one nameserver is functioning.
Memory requirements for Threat Protection and large domain lists
After upgrading to service point v3.3.1 or greater, BlueCat recommends configuring an additional 4 GB of memory when using Threat Protection policies or larger domain lists.