Release Notes for Snare Agent Manager v1.5.0

Snare Agent Manager v1.5.0 was released on 13th April 2021.

Security Updates

  • Security hardening of Agent to SAM communication: Digest Authentication was replaced with authentication over HTTPS

    After this change, the v5.5.0 agent will only be able to communicate with SAM v1.5.0 or newer. 
    SAM v1.5.0 is backward compatible, and supports communication with pre-v5.5.0 agents.

  • Security hardening of encryption keys storage, usage, export and import
  • Strengthened encryption of SAM API Key by using unique IV
  • SAM now uses higher entropy random numbers during agent scanning
  • 3rd party libraries upgraded:
    • OpenSSL upgraded to version 1.1.1i
    • curl upgraded to version 7.72.0
    • Boost upgraded to version 1.74

Enhancements

  • A new setting "Upgrade Timeout" has been added in SAM UI > Settings > Upgrade Agents. This setting controls the time of no response from the agent that started the remote upgrade, after which the upgrade is considered failed. The default value is 60 minutes. Allowed values are 1-4320 (3 days in minutes).

User Guide

The following is an offline version of the User Guide related to this release.

For an up-to-date version refer to the online version here.