VeridiumID 3.9.1 is a focused enhancement and maintenance release that improves FIDO and passkey authentication, RADIUS integrations, privacy controls, certificate management, and operational troubleshooting.
The release also delivers reliability and usability improvements across authentication, Identity Provider integrations, administrator workflows, FreeRADIUS, reporting, and upgrade procedures.
Together, these changes make VeridiumID 3.9.1 easier to configure and troubleshoot, more predictable during authentication, and more resilient during installation and upgrade operations, while extending the security and administrative capabilities introduced in VeridiumID 3.9.
Key Highlights in This Release
-
Phone Manufacturer Enrollment Restrictions — Administrators can now explicitly configure mobile device manufacturer lists as either an allowlist or a blocklist. Manufacturer matching is case-insensitive, providing more predictable control over which devices are permitted to enroll.
-
Smarter FIDO Sign-In Prompts — FIDO Relying Parties can now prioritize supported authenticator transports, including
hybrid, and optionally tailor authentication options to the transports supported by each registered credential. Frequently used credentials are also prioritized, providing a more relevant and streamlined FIDO and passkey sign-in experience. -
OIDC Keys in the Certificate Validity Dashboard — The Certificate Validity Dashboard now includes Shibboleth IdP OIDC signing and encryption keys, allowing administrators to monitor their expiration alongside existing IdP certificates and quickly navigate to the corresponding OIDC security settings.
-
Control Location Data Collection — A new global Geolocation setting allows administrators to disable the collection, processing, and storage of geographic location information. When disabled, VeridiumID no longer derives locations from IP addresses or stores location data in newly processed sessions, tokens, history, and audit records.
-
Centralized FreeRADIUS Client Management — RADIUS clients can now be managed centrally from Veridium Manager, including their network addresses, shared secrets, and permitted authentication methods. Existing client definitions can be migrated into the centralized configuration and changes propagated consistently across FreeRADIUS nodes.
-
Enhanced FreeRADIUS Multi-Factor Authentication — FreeRADIUS authentication can now combine an LDAP or Active Directory password with Veridium OTP or Push authentication. Password + OTP can be submitted in a single RADIUS request, while Password + Push validates the directory password before requesting mobile approval.
Other New Features & Enhancements
Administration and Troubleshooting
-
Export Troubleshooting Logs — Administrators can export application and access logs associated with a selected identity, phone or desktop device, authentication session, or passkey session. Logs for the selected period are downloaded in a ZIP archive containing NDJSON files and an export manifest, simplifying troubleshooting and support investigations.
-
Runtime Log-Level Configuration — Logging levels for supported VeridiumID services can be adjusted from Veridium Manager → Advanced Settings for specific packages or classes without restarting the affected application. Changes are validated, audit-logged, and retained across application restarts.
-
Offline QR Reporting — The Authentication Sessions report under Audit → Reports includes Transaction Type information, allowing administrators to identify Offline QR sessions through the
B2B_OFFLINEvalue in the exported report. -
Deprovisioning Log Traceability — Identity and administrator deprovisioning logs include identity identifiers, making it easier to correlate deprovisioning activity with the affected accounts during troubleshooting and review.
Certificates and Directory Integration
-
Direct LDAP Certificate Import — Administrators can retrieve an LDAP server certificate directly from the configured connection and import it into the VeridiumID truststore. The capability is available from both the Quick Action and LDAP configuration workflows, simplifying certificate setup for secure directory connections.
-
External CA Upload Validation — The external Certificate Authority upload workflow provides a more consistent certificate-import experience and verifies that the certificate associated with the supplied private key is a CA certificate, helping prevent unsuitable certificates from being configured as a Certificate Authority.
-
Persistence Certificate Management — Veridium Manager supports certificate upload and renewal operations for the persistence layer, including the persistence Certificate Authority, Cassandra and Elasticsearch certificates, and associated truststore updates. This reduces the manual configuration required to maintain certificates across the affected services.
Security and Configuration
-
SMS service passwords are now handled as encrypted sensitive values in the corresponding configuration.
-
Veridium Manager communication has been improved for environments using TLS 1.3.
Bug Fixes
Authentication and FIDO
-
FIDO authentication is now displayed correctly as an available authentication method when the user has an enrolled FIDO authenticator.
-
The FIDO Reinitialize operation now completes correctly instead of producing an internal exception.
-
Adding FIDO Client Extensions no longer results in the previously reported Java exception.
-
Offline QR authentication now updates the user's Last Login information correctly.
-
Passkey Session search now returns the expected results.
Identity Provider, SSO, and Integrations
-
OIDC applications are now displayed correctly in the Self Service Portal alongside SAML applications.
-
Shibboleth mapped attributes can now be enabled correctly for both SAML and OIDC configurations.
-
Certificate authentication through Shibboleth no longer fails because of the previously identified CORS validation issue.
-
CORS header handling has been improved to treat header names consistently regardless of capitalization.
-
Admin authentication using OIDC now handles configured response headers correctly when the application URI contains a port.
-
The Enable force authentication setting now applies as expected.
-
SSO session stages are now recorded with the correct completed state.
-
FortiGate VPN mobile authentication no longer remains on a stale page after a successful login.
-
Generic integrations are now displayed correctly in Veridium Manager when they are active and enabled.
-
SAML authentication sessions used by Veridium Manager and the Self Service Portal are handled independently, preventing a logout from one application from unexpectedly disconnecting the other.
Administration and Reporting
-
Administrator details no longer produce an error when historical administrator records no longer contain the corresponding account data.
-
Administrator deprovisioning views and administrator cleanup have been corrected for previously reported inconsistent states.
-
Invitation-code CSV exports now provide the correct error information.
-
Session details now present ILP criteria more consistently, reducing ambiguity when reviewing risk and delegated-authentication information.
-
Storage-protection changes now provide the expected visual feedback in Veridium Manager.
FreeRADIUS, Installation, and Upgrades
-
FreeRADIUS now starts correctly following a fresh VeridiumID installation.
-
FreeRADIUS configuration loading is more resilient to temporary configuration-read and decryption issues.
-
FreeRADIUS updates now preserve the intended centrally managed configuration files without restoring unrelated files.
-
Environment upgrades no longer fail because of the previously identified migration-script issue.
-
Upgrade processing now handles temporary Kibana unavailability more reliably.
-
Several data-migration operations used during upgrades have been corrected to improve update reliability.