Fixed Issues

The following table lists release numbers and the PRS numbers with the summary of the issue fixed during that release:

Problem Report Number

Summary

Release 9.1R13.1 PRs

PRS-404658

Advanced HTML5 SSH Sessions and do not support scroll bar.

PRS-404298

Advanced HTML5 Copy/Paste does not work for SSH.

PRS-402150

Suddenly new L3 ESP/SSL VPN connection request fails for users due to auto-generation of Dsagentd cores.

Release 9.1R13 PRs

PRS-403552

Client certificate information (serial number and certificate) is not available in PCS user access logs.

PRS-403495

Browser based end user UI error message for invalid credentials is not seen.

PRS-403462

Warn customers to follow mandatory steps before upgrading PCS/PPS.

PRS-403370

PDF files with streams having no Length attribute create segmentation fault causing rewriter server core.

PRS-403036

Source IP restriction for IPV6 Subnet in Roles restriction is not working.

PRS-403027

Core Access: SSO redirect with concur is not working

PRS-402999

XML import fails when config with the connection set containing option "Connect to URL of this server only" is disabled. This is due to improper initialization

PRS-402922

Improvements for ICT

PRS-402855

PCS archiving is not happening on Azure server

PRS-402633

DSDID length is not calculated properly causing Process web crash in FIPS mode.

PRS-402583

ICT page is skewed to left in classic UI but OK in new UI

PRS-402338

"Bookmarks open in new window" option is not exported in XML Export.

PRS-402271

While creating citrix profiles and change the options from java/html5/non-java, the auto policies created are not being handled as expected.

PRS-402253

Display a log message when the Root Partition gets into Read/Write Mode

PRS-402218

Unable to open Sharepoint documents using MS office native apps.

PRS-402075

HTML5: Option needed to hide basic HTML5 bookmarks/RDP launcher

PRS-401872

File download fail as file URL is getting truncated where newline exist in file name.

PRS-401553

When launching the Citrix client, 60 seconds delay is seen with no UI feedback, before PSAL download link appears.

PRS-401376

dsTermServ.exe crashes and unable to access terminal services with Applocker installed.

PRS-401160

Import of configs from older software to 9.1R11.4 may generate some error logs along with 'import done' message.

PRS-400261

REST API incorrectly responding to queries with ascii symbols

PRS-400152

With Recursive DNS domain name resolution for LDAP server is not successful.

PRS-399042

Process dswsd crashed during network fluctuation when some of the variable is not set correctly.

PRS-398648

Enabling/Disabling ICE license on PSA7000 increases the CPU usage

PRS-392135

Pulse One disconnected from PCS after PCS upgrade

PRS-390822

Page rendering issue due to Cross-origin Object.

Release 9.1R12.1 PRs

PRS-403735

Lost connections and dsagent process restarts due to a malformed IKEv2 packet.

PRS-403191

Unable to assign NCIP from the static IP pool in PCS 9.1R12.

Release 9.1R12 PRs

PRS-401930

Authentication fails with no authentication prompt even though “Allow Smartcard with Network Level Authentication” shows enabled in the UI. However, XML export shows it as "Disabled".

PRS-401673

Due to Password Policy Control Changes introduced in 9.1R5, if we do not receive the proper response from LDAP server the authentication fails and associated process crashes.

PRS-401574

Duplicated Named User Licenses as usernames are treated case sensitive.

PRS-401421

PCS does not send DSID cookie to Pulse Client (SiteMinder authentication).

PRS-401356

The default admin realm is enabled with source IP restriction which restricts the access from a public network..

PRS-401318

Event log modification from “info to critical” for SYS30948 and from “critical to major” for SYS30912.

PRS- 401294

Log ERR32037 “Server name contains unsupported/unsfe characters”, is seen even if the server name is valid and spelling unsafe is corrected in 9.1R12.

PRS-401213

Web crashes (restart) due to a problem in JSAM/WSAM data path leading to user disconnection and reconnection.

PRS-401185

Multiple Syslog entries are seen under in A/A clusters having more than 2 nodes.

PRS-401064

PSA7000 shows improper interface speeds when VLAN is configured.

PRS-400976

Multiple monitors, sound does not work when HTML5 is configured with NLA and no SSO set.

PRS-400960

Static IP via Radius Attributes not working as expected.

PRS-400951

Static IP allocation fails when there are IP pools which overlap with other IP pools.

PRS-400771

Windows Terminal Services client disconnects the sessions intermittently.

PRS-400725

Windows Terminal Services client disconnects when copying the files.

PRS-400655

Importing certificates from system config fails when there is no password set during config export.

PRS-400495

Azure PCS instance goes unresponsive intermittently.

PRS-400285

Added an event log to monitor internal shard usage.

PRS-400243

VIP status change notification event sent by passive node on reboot is treated as VIP status change notification from Active node, and users notice VPN reconnection.

PRS-400229

Session extension using PDC through SAML authentication server does not work.

PRS-400206

Changes to entity ID and SAML auth server instances are not recorded in the admin access log.

PRS-400067

Windows Pulse Client 9.1r11 with Avaya One-X causes BSOD.

PRS-400023

when User role is duplicated, VPN tunneling option is reset to default options and not updated.

PRS-399963

Impexserver crash is observed when importing PCS is having a duplicate certificate.

PRS-399925

Yearly graph shows incorrect data for active user sessions.

PRS-399842

After upgrade to 9.1R11, IP Assignments through LDAP/Radius Attributes is failing but Static Pool works fine.

PRS-399626

PSA7000f server restarts unexpectedly and user connection fails. Additional logs added to determine the Root Cause.

PRS-399559

Static IP allocation issue when multi session is enabled.

PRS-399450

Citrix VDI not working in the first attempt, Second attempt starts working and CTS launches and connects.

PRS-399409

Only ntpd Client service runs going further (Previously both server and client services were run).

PRS-399192

Failed to upload configuration on the newly registered PSA device on pulse one.

PRS-399136

Redirected URLS encoded not passing properly.

PRS-399021

When creating an admin role, User roles in the Users delegation displays incorrect number of selected roles.

PRS-398969

Bandwidth management policy does not work in the SSL Mode.

PRS-398814

guacd process protection mechanism where each instance of guacd instance is monitored and killed if the instance takes 100% CPU till the grace time.

PRS-398703

Healthcheck.cgi does not work from F5 load balancer.

PRS-398600

Named User Record/Database do not show up on license client.

PRS-398371

VLAN details are not removed from VLAN page after removing VLAN ID from management port.

PRS-398348

PCS device does not send the SNMPv3 trap out from the device.

PRS-398270

Expired certificates alarms for deleted certificates.

PRS-398262

Web process failures due to DSEvntTimer observed on PCS.

PRS-398002

Limitation on number of realms in sign in URL while connecting through PDC client.

PRS-397693

Compliance report for hostchecker policies mapped against realm/role is generated for user that does not belongs to that realm/role.

PRS-397676

License server low-level protocol error,Code=[6]: Could not resolve host name through external port.

PRS-397664

XML export of Admin/User realms shows the directory-server attribute same as authentication-server even though there is None in the UI.

PRS-397574

With Pre Host checker configured, if the Pulse credentials prompt times out, the session is extended instead of resumption.

PRS-397461

Basic HTML5 : Users not able to use mouse emulation with guacamole RDP sessions on iOS13 iPad.

PRS-397414

Extra fields appear under Role > Web Bookmark for new or existing bookmark prior to upgrade.

PRS-397380

User record synchronisation feature may not occur as-expected across all configured devices.

PRS-397349

User Record Sync clients disconnecting from green to grey status.

PRS-397346

Host Checker Re-Triggers with error message 'ESAP upgrade is needed or Patch Management policy configured' in event logs.

PRS-397290

SAML Single logout is failing.

PRS-397213

MSSP: watermark does not get reset, even if license client is not leasing licenses from the license server.

PRS-397059

AAA: X-forward-for IP is not evaluated/used when using geoLocationCountry rules.

PRS-397043

One cluster node stops accepting new VPN connections post getting deactivate/activated in cluster.

PRS-396972

Number of MC groups has been increased to 40 & 36 on Linux and Windows respectively.

PRS-396200

Upgrade fails when data partition does not have enough space to hold system configurations.

PRS-396062

Users unable to join hosted pulse collaboration meeting session through IE 11 browser.

PRS-395544

Upgrade failing for one node In A/P cluster.

PRS-395508

User gets disconnected when cert restriction policy is configured and SAML authentication server is used. This has been fixed as part of this PRS.

PRS-395347

Incorrect Source IP address used when sending packets to secondary radius server (When using “Traffic Decoupling” at “Auth Server Level”).

PRS-394657

Pulse Collaboration: Customer gets an error while scheduling the meeting if the localization set to French.

PRS-394572

SNMP alerts shows abnormal increase in device temperature.

PRS-394202

Manual failover takes time to resume user tunnel connections. This is now improved.

PRS-393712

Terminal Session stops working after upgrade to 9.1R8. Adding logs to improve debug ability.

PRS-393675

Failed to send API requests from PCS(MDM) to Microsoft Intune for device authorization.

PRS-391871

Openstack KVM deployment - after reboot only local subnet can connect, PCS ignoring other packets.

PRS-390315

Fed-Wide session sync delay between Replicas results in user session getting removed from Imported sessions within few minutes.

PRS-380985

Incorrect Interface Status sent by the PCS appliance while performing SNMP Walk after upgrade to 9.1R1.

Release 9.1R11.5 PRs

PRS-401116

Pulse Upgrade Helper tool upgrades Pulse Desktop Client once and terminates IE processes during the process.

PRS-400823

State Storage full and Program cache-server failed.

PRS-400746

Unable to see the details of package uploaded into Staging Area in Admin UI

PRS-400717

Improper titles for lines on HTML5 dashboard graph and some titles missing in Concurrent users graph.

PRS-400614

PSAL fails to launch Java Applets.

PRS-400653

In versions 9.1R11.4 and below, if the 'HTTP only cookie' option is enabled for admin role, the super admin session will not work.

PRS-400544

Program web recently failed on 9.1R11.3

PRS-399600

Users are not prompted to enter credentials as well as MFA on successful connection to VPN.

PRS-399576

The localization support is not available for new options on user created advanced HTML5 bookmarks.

PRS-399150

Host header Validation is failing for Virtual hostnames.

PRS-396923

PSA 5000 crashes with no access to UI or Console.

PRS-384770

GARP frames are not being sent under Default VLAN configured on an interface - VIP IP is not accessible after manual failover in A/P cluster.

Release 9.1R11.4 PRs

PRS-400095

Web crash due to empty session IDs.

PRS-399115

Warm restart of services is observed on two node PSA7K AA cluster when run continuously for multiple days causing L3 and L4 connection drops.

PRS-398510

Error code 1326 displays on Pulse Client when username/password is saved on Client and expired on AD server.

PCS-27395

Custom expression failure messages is flooding User Access Logs.

Release 9.1R11.3 PRs

PRS-400438

Code signing certificate fails globally when launching HC using browser. The certificate issue is addressed. For information refer KB44781.

Release 9.1R11 PRs

PRS-398532

During Kernel Panic (System stalls with no access to Admin UI), PCS/PPS devices will automatically reboot by default.

PRS-397979

Process snapshot gets generated for dsagentd/Web processes in 9.1R10. This issue can happen rarely when Client closes PSAM session with PCS server immediately just after closing TCP application connection.

PRS-397324

Dsagentd crashes when PCS System load average goes high.

PRS-397190

Rename all the places that contain WSAM keyword on the Admin UI to PSAM.

PRS-397171

Kernel panic is observed sometimes and PCS restarts.

PRS-397072

Host Check fails on macOS 11.1 when the policy is enforced.

For more information, refer KB44663.

PRS-397046

Background image and recaptcha is not loading through rewriter.

PRS-397000

Supporting corner cases for jquery usage in client side rewriter handling.

PRS-396944

WTS: End users unable to enable MIC on the user interface.

PRS-396870

PDC: Virtual adapter stops intercepting IPv6 packets on Mac/Windows/Linux platforms using PDC 9.1R9 build in ESP mix mode.

PRS-396773

Host Checker fails after upgrading ESAP version to 3.7.1 or 3.7.2 or 3.7.4 from any previous ESAP version on macOS endpoints (KB44643).

PRS-396675

Fixed rewriting for other elements of div tag caused due to Data-srcset support.

PRS-396389

User is not able to configure Azure as backup server in China region.

PRS-396262

Login button is not enabled when accessing web rewriter through IE browser.

PRS-396134

NTP will not synchronize time when default VLAN ID is configured on the interface.

PRS-396116

Browser-based Host checker fails to get launched in 64 Bit Internet Explorer.

PRS-396097

Kernel panic “nf_udp_esp6” may be observed on PSA7000F.

PRS-395982

Rename all the places that contain WSAM keyword on the Admin UI to PSAM.

PRS-395902

Pulse Component Set is selected to NONE does not update the “connstore” in spite of changing the connection set. A warning message is displayed to guide configuring the “Connection Set”.

PRS-395813

Disabled DMI Inbound connections setting is not retained after reboot.

PRS-395330

SNMP query for “sysObjectID” is returning PSA7000F for PSA7000C platform.

PRS-394382

Handling rewriting of Data URLs at server side code to avoid rewriter crashes.

PRS-392135

Pulse One disconnected from PCS after PCS upgrade.

PRS-391667

Aligned the latest MaxMind DB pointer with local DB for Ueba package upgrade.

PRS-390324

Spikes are observed at regular intervals in the concurrent SSL connections graph.

Release 9.1R10 PRs

PRS-395039

License client reports the excess allowed usage while sending the usage to server.

This issue is fixed to limit the reported count to maximum lease limit.

PRS-394744

“Error updating data for chart hc_failure_reason/auth_mechanism” log on PCS is not seen.

The Exception that was causing this error is fixed.

PRS-394586

Administrator can set a guaranteed minimum users on a realm to allow an user from that realm to log into the PCS/PPS when the licensed concurrent user limit is reached.

From Release 9.1R10, guaranteed minimum users is applicable when no ICE license is installed or ICE license is installed and enabled.

PRS-393989

When the current MSP license expires, and customers installs a new MSP license, VLS needs to re-register with PCLS. This was not happening previously, and this resulted in billing against older authcode.

In 9.1R10, we have fixed this issue, so that VLS re-registers with the next active MSP license. Hence, the license usage is reported against the new authcode.

PRS-393140

Certificate authentication fails when the option 'Trusted for Client Authentication' is disabled in client CA certificate hierarchy.

Added a new user access log and an Admin UI note to alert the PCS administrator in such cases.

PRS-389455

Analytics Device OS graph does not show Windows 10 OS information.

This issue is fixed in 9.1R10 onwards.

PRS-387059

Unable to publish config when trusted client CA cert (using CRL) is deleted on Master appliance.

This issue is fixed in 9.1R10 onwards.

PRS-380696

Predefined Host Checker policy can now be configured with a ignore category based on the vendor.

PRS-390086

End-Points connected through slow internet now will not hit the incomplete ESAP package download scenario.

PRS-395701

Access to advanced HTML5 custom URL is not successful without user logging into PCS server.

The user is now prompted to log into PCS followed by log in prompt to target machine.

Release 9.1R9.1 PRs

PRS-396149

Web process restarts when Client Application profiles are configured under
SAM --> Resource Profiles.

PRS-396441

For advanced HTML5 sessions, web process restarts if the FQDN is not resolved.

PRS-396463

For advanced HTML5 sessions, login may fail if the target machine username or password contain special characters.

Release 9.1R9 PRs

PRS-395306

“Failed file system integrity check” warning appears on Admin UI when the file “integrity_check” is either not created or deleted. This is addressed in 9.1R9.

PRS-394759

DHCP Set option is added for AWS (If no DNS server configured in DHCP option set, it will take the second IP address as primary DNS server from the internal port subnet).

PRS-394604

Agent Type in active users page on PCS fails to show Windows OS version with 9.1R8 PDC builds.

PRS-394537

XML export shows virtual Platform for physical license clients. This is addressed in 9.1R9 release.

PRS-394242

Rewriter client side parser issue fixed for DanaGetURLUnencoded API.

PRS-394137

Performance tuning is incorporated for FQDN ACL feature.

PRS-394107

Pulse Client version does not display under "Active Users" tab for mobile devices. The issue is addressed in 9.1R9.

PRS-394075

Pulse Collaboration stops working after Setup Client download fails, after upgrading it to PCS 9.1R8.

PRS-393736

Dssecidcheck program fails. This is addressed in 9.1R9.

PRS-393649

If a session is no longer present in the system when the IP lease period is active, then the IP address is released back to the DHCP server.

PRS-393627

Host Checker: Compliance check fails when using Sophos Cloud Endpoint 2.8.6.

PRS-393624

SNMP polling on ifHighSpeed does not return the correct speed of a network interface, if default VLAN is enabled for that interface. This is resolved in 9.1R9.

PRS-393603

File Share: When a big file is uncompressed, PCS will ensure that all the chunks are read properly from 9.1R9.

PRS-393544

On the "Virtual Port" view page, if admin clicks "Cancel" button without saving any changes, then Network service is restarted. This is addressed in 9.1R9.

PRS-393437

From 9.1R9, if PCS VA is hosted by VMware, then NTP setting at "Date and Time" page will have an extra note which informs admin that the Virtual appliance should have only one source of Time Sync (VMware ESXi or NTP Server, NOT both).

PRS-393313

Web Process crash due to timer Library corruption is addressed in 9.1R9.

PRS-393269

PCS was unable to handle "Unknown" OCSP Response. This is addressed in 9.1R9.

PRS-393230

Sometimes, TCP Dump does not start. This is addressed in 9.1R9.

PRS-393070

Logical volume support is removed from KVM instances.

PRS-392547

Custom start page takes about a minute to show up when connected from IE with split tunnel and VPN auto-launch enabled. This is addressed in 9.1R9.

PRS-392359

The default password length has been increased and the same has been updated in the Azure ARM Template.

PRS-391949

In spite of installing the Meeting license on a virtual appliance running A/A cluster, the effective count of concurrent meeting users remain zero. This is addressed in 9.1R9.

PRS-391629

PSAL Linux is unable to connect to PCS. This is addressed in 9.1R9.

PRS-391573

During domain controller reachability test under LDAP Auth Server, PCS does not close the LDAP TCP socket connection with domain controller. This is addressed in 9.1R9.

PRS-391273

When SAML config has both SLS and SSO service types using same Location URL, Import XML fails causing SAML metadata publish to go into loop. This is addressed in 9.1R9.

PRS-389484

PCS appliance now sends IPv6 Neighbor Advertisement with correct VLAN tag for user roles mapped with sourceIP as VLAN interface.

PRS-389448

dsagentd process crashes when handling multicast traffic. This is addressed in 9.1R9.

PRS-388972

Session extension fails when custom sign-in page is configured for the sign-in policy. This is addressed in 9.1R9.

PRS-387807

When default VLAN is enabled, virtual port is not considered for the user role while calculating the source IP. So, default IP was assigned as source IP. This is addressed in 9.1R9.

Release 9.1R8.2 PRs

PRS-394540

A tactical fix was provided as part of 9.1R8.1 (PRS-393243). However, Custom Rule Expression evaluation is now made more robust with thread safety in 9.1R8.2.

PRS-394113

PCS can parse and store up to 32 IP addresses returned by DNS server.

PRS-393865

Running TCP Dumps can get the Disk Full as there is no Log Rotation in place. This is addressed in 9.1R8.2.

PRS-393666

Application level integrity check was missing on PCS for Fragmented EAP-TLS packets. This is addressed in 9.1R8.2.

PRS-393440

Host Checker fails with Error "Host checker did not get installed properly. Your computer does not meet requirements". This is addressed in 9.1R8.2.

PRS-392873

The desktop settings configured under terminal services bookmarks will not apply if the resource's Operating System is Windows 8 or later. This issue is seen in Pulse Client 9.1R8.1 or earlier. The issue is resolved after implementing new interfaces of the Microsoft MsTscAx component.

PRS-392156

Modified WebRequest code to prevent null pointer (Hprewrite-server) crashes.

PRS-391188

DHCP options disappear upon clicking “Refresh Now” button under Connection Profiles > Proxy Server Settings. This is addressed in 9.1R8.2.

PRS-391141

Duplicate syslog (SYS31407) messages appear in event logs. This is addressed in 9.1R8.2.

PRS-388494

Large Username XML Import now logs proper error message.

PRS-385110

Upgrade failure due to white spaces in the configuration is fixed in 9.1R8.2.

Release 9.1R8.1 PRs

PRS-393434

Time drift is observed when NTP is configured on Virtual Appliances. This can affect authentication, cluster sync, and cause licensing issues. This is addressed in 9.1R8.1 (KB44558).

PRS-393243

Host Checker policy evaluation fails very intermittently for some time if policy rules need to be evaluated based on Custom Rule expression. This is addressed in 9.1R8.1.

PRS-392995

dsagentd crashes occasionally in load condition during initial data channel establishment. This is addressed in 9.1R8.1.

PRS-392842

The Overview/cockpit graphs representation will now show data similar to the Classic UI (It will omit the duration for which the data is not available).

PRS-392593

Restriction of REST API commands via the internal port is now fixed.

PRS-392254

SNMP polling was not returning false PCS Model Number and device type. This is addressed in 9.1R8.1.

PRS-392153

Session Server failures due to cluster instability is fixed in 9.1R8.1.

PRS-392096

Winbindd crash seen due to an exception is fixed in 9.1R8.1.

PRS-391990

SSH/Netconf clients should now be able to connect PCS DMI Agent successfully.

PRS-391708

Quick navigation link added to Enable/Disable FQDN ACL. And the following warning message is also added:

“Ensure that there is no DNS latency/delay in the network to avoid performance issues”.

PRS-391690

When a license client surrenders a license, the expiry date of that surrendered license keeps changing in license server to keep the expiry date always as 10 days (default) ahead of current date. The change is reflected in “License Summary” page of license server admin UI. But the change is not always reflected correctly at the “Pool of available licenses” section under the “Configure Clients” tab as there is a sync-up issue. This is addressed in 9.1R8.1.

PRS-391253

When Pulse Desktop client is used, PCS server does not provide session ID in User Access log after a successful login. Here “session ID” denotes the last 8 characters of actual session ID in server, and it is used to differentiate a session from other sessions for one user. From 9.1R8.1, PCS server will provide this ID for all types of Pulse clients after successful logins.

PRS-390500

From 9.1R8.1, PCS end user name will appear as client name (instead of Localhost) in HTML5 RDP session.

PRS-389526

From 9.1R8.1, a warning message will be sent only when the lease request fails or no leasable license is left with the number of users reaching towards maximum concurrent users limit.

PRS-389251

Frequent warning message about “number of concurrent users is nearing system limit” creates confusion about actual issue with concurrent users limit. Form 9.1R8.1, a warning message will be sent only when lease request fails or no leasable license is left and number of users are reaching towards maximum concurrent users.

PRS-387936

Global session configuration values (Users > User Roles > Default Options) are used when individual user role is not configured with session options.

Release 9.1R8 PRs

PRS-392702

PRS-391725

Additional logging to debug web crashes.

PRS-392244

PRS-388907

Active users were not able to sync to the newly added node on a 3 node Active/Active cluster. This is addressed in 9.1R8.

PRS-392040

PRS-388907

User sessions are not synced across the nodes in an Active/Passive cluster. This is addressed in 9.1R8.

PRS-391902

Invalid packet processing in kernel is addressed in 9.1R8.

PRS-391879

Intermittent audio disconnect issue with HTML5 RDP session is addressed in 9.1R8.

PRS-391837

PRS-380638

tncs process crash with Host Checker caching enabled is addressed in 9.1R8.

PRS-391004

The dsunitysamlhandler process crash is addressed in 9.1R8.

PRS-390937

In 9.1R4 to 9.1R7, when multi monitor option is selected under the Terminal Services session/bookmark page as well as under Terminal Services Options page, XML config data shows incorrect value. This is addressed in 9.1R8.

PRS-390916

Kernel panic during upgrade on PSA5000-V running 9.1R3 on Hyper-V. This is addressed in 9.1R8.

PRS-390907

Log rollover is implemented for postgresd so that it does not cause the Disk to get full.

PRS-390831

SAML authentication is now successful when signing is enabled for SAML requests/responses using certificates.

PRS-390828

As dshealthstatsunity process was getting exited due to exceeding process size, data was not being sent to Pulse One for that particular interval and thus calculated cumulative count at Pulse One was incorrect. This issue is addressed in 9.1R8.

PRS-390769

Kernel logging options are added by default for better debuggability.

PRS-390426

As process was getting exited due to exceeding process size, data was not being sent to Pulse One for that particular interval. This issue is addressed in 9.1R8.

PRS-390274

For config elements with unicode characters and having length exceeding 4096 bytes, the config import fails on Pulse One client. This issue is addressed in 9.1R8.

PRS-390217

Tunnels get dropped during connection resumption due to a server error. This is addressed in 9.1R8.

PRS-389927

The TCPDump filter expression can now contain characters from the set "<>|;()[]?#$^&*=\'`"" .

PRS-389897

Kernel Panic hrtimer_interrupt issue is fixed.

PRS-389771

Multiple VIP fail over was seen on Virtual A/P cluster due to the time drift between system clock and hardware clock. This is addressed in 9.1R7 (KB44457).

PRS-389756

The dsagentd process crash during assignment of IP address from DHCP server is addressed in 9.1R8.

PRS-388630

With current OPSWAT library code, the verification of update functionality was not working. OPSWAT has fixed the issue and provided a new library.

PRS-388104

The top-roles section displayed on dashboard was not showing the roles name in Japanese and other languages. This issue is fixed for both Classic UI and New UI in 9.1R8.

PRS-385646

Whenever a user tries to access the VDI resource, a wrong error code for timeout was written in the logfile. The user sees the message "Missing host name/IP, Invalid host name/IP: "

To address the issue:

1. Timeout error ID is passed to write in logfile.

2. A proper validation has been done for the wrong false alarm.

PRS-364693

Bandwidth Management policy not getting enforced for VPN tunneling users is fixed in 9.1R8 - https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44402/?kA13Z000000L3Dc.

PCS-20480

PCS was returning "Incorrect ICE action" error message when trying to execute api/v1license/ice REST API to fetch the current status of ICE. This is addressed in 9.1R8.

Release 9.1R7 PRs

PRS-391296

Application access using Citrix Terminal Services through IE browser fails in 9.1R5-9.1R6 PCS versions. This is addressed in 9.1R7.

PRS-390778

Host Checker support for OS version check is added for iOS versions 13.4 and 13.4.1.

PRS-390775

PCS syslog forwarder does not work if connection to syslog server fails during startup of the syslog forwarder process. This is addressed in 9.1R7.

PRS-390530

Enterprise user onboarding fails in Mac OS Catalina as the filename extension was not populated as '.mobileconfig'. This extension is added in 9.1R7.

PRS-390475

Noticeable slowness was seen in several applications including Citrix HTML5 video rendering in 9.1R3-9.1R6 PCS versions. This is addressed in 9.1R7.

PRS-390401

SNMP functionality was not working after cache sync. This is addressed in 9.1R7.

PRS-390234

User access log now shows real-time active HTML5 sessions count.

PRS-390118

In PCS A/P cluster split and joined scenario, lease license IDs are validated to reset the stale ID and license client will be able to lease licenses successfully.

PRS-389481

Cloud Platforms: Improved SNAT performance by tuning kernel module parameters based on the memory available in the device.

PRS-389209

With PCS 9.0R2-9.1R6 and Pulse 9.0R2-9.1R3, the client continues to send the CAV traffic to PCS every 300 seconds even when Cloud Secure license is not installed. From PCS 9.1R7 onwards, the PDC client (Pulse 9.0R2-9.1R3) will contact the PCS server only once per user session - KB44410.

PRS-388932

From PCS 9.1R7, the "Synchronization of last access time in user sessions" option in A/A Cluster mode will be auto-enabled and grayed out when the "Synchronize user sessions" option is enabled (otherwise, it can affect session migration). Existing cluster configuration is not modified during upgrade, so we recommend admins to enable this option for existing configurations as well.

PRS-388455

If epupdate_hist.xml is hosted internally with no authentication and if "Use Proxy Server" (With/without auth) is enabled with FQDN or IP Address, the first 3 characters are ignored thus causing it to fail. For example, proxy.domain.net is taken as xy.domain.net. This issue is now fixed for both PCS and PPS.

PRS-382777

Client's original Source IP was not logged if Load Balancer is used. Client's Source IP is now retrieved from 'X-Forwarded-For' header and logged in user access logs.

Release 9.1R6 PRs

PRS-390370

PRS-390145

Java Script is displayed after the user scans the QR code only during the TOTP user registration.

PRS-390352

Hostname resolution for an FQDN with up to 255 characters was not supported through the L3 tunnel in PCS 9.1R5.

PRS-390198

Admin cannot download reports in PDF format for PCS.

PRS-389973

HTML5 connections cause memory leak in Guacamole server and result in high memory usage and swap memory usage

PRS-389811

CPU Allocation issue on PSA-7000 (all flavors/varieties) appliances in case of Single-Arm mode VA deployments is now resolved on PSA-7000 HW and ESXi (VMWare) solutions.

Refer KB44446 for more details.

PRS-389744

Process snapshot for "dsserver-tasks" is generated while deleting meeting objects for corresponding users.

PRS-389544

Some of the examples listed under "Split Tunneling Networks" policies are not supported.

PRS-389523

External backend resource access using HTTP GET request with username in the URL for the file login.cgi fails through Rewriter.

PRS-389517

Web server crashes and results in User disconnections due to webSocket upgrade related messages during Auth Only URL access.

PRS-389440

User Accounts under TOTP Auth server Users section cannot be exported.

PRS-389406

Delayed or no response from PCS for SNMP queries under load condition.

PRS-389276

The corruption of blob during the epupdate results in Host Checker scan failure for users until the next successful epupdate.

PRS-389262

Web process snapshot is generated while sending POST request by REST API with an empty body.

PRS-389127

Garbled text in Citrix VDI profiles page when accessed using bookmark with the Japanese language.

PRS-388796

The dsagentd process (client server process) crashes and frequently disconnects in 9.1R4 when there are more than 1024 tunnels including MobIKE IKEv2 tunnels.

PRS-388645

After upgrading PCS/PPS to 9.1R3-9.1R5, slow Host Checker response is observed due to a very frequent re-evaluation of Cybereason Active Probe product.

PRS-388542

Garbled text in file share page when accessed using bookmark with the Japanese language.

PRS-374603

During system downtime activities such as an upgrade, Event IDs such as 20412/20413 are missing in the Syslog server.

Release 9.1R5 PRs

PRS-389938

9.1R4.3 Radius crashing, unable to authenticate Pulse.

PRS-389550

Intermittently, the system throughput falls drastically and user connections fail.

PRS-389246

“500 Internal Error” is displayed when opening Authentication related pages.

PRS-389212

Intuitive Customer friendly ways and relevant logs to avoid customers configuring single core.

PRS-388958

Idle timeout session is not working, OWA 2016 keepalives not ignored through web-rewrite.

PRS-388885

License Surrendering not happening due to the heartbeat not sent.

PRS-388743

Host Checker :: OS Checks :: MAC :: Add support to configure Minimum Service Pack/Version for MAC Catalina(10.15).

PRS-388734

PSA7000 at 30% total CPU due to two guacd processes at 100% CPU, planning pandemic and wanted to know root cause.

PRS-388536

One node in Cluster is surrendering the licenses to the License server. However, the increment of the surrendered time is not happening.

PRS-388479

PSA5000 : 9.1R4 : A/P Cluster : REST API calls are failing intermittently when they are executed in a loop continuously.

PRS-388429

Text corrected under Log/Monitoring > Admin Access > Settings.

PRS-388421

PCS 9.1R4 incorrectly reporting duplicate machine ID.

PRS-388409

Unable to upload config to Pulse One: Configuration changed while preparing configuration to upload.

PRS-388331

After upgrade VA-DTE & PSA-V to 9.1R4, nfqueue unable to create IPTables when VM is configured with 1 CPU core only.

PRS-388244

FileShare:: Customer unable to download direct file from FileShare on 9.1R4 PCS version.

PRS-387954

Rewrite: Web page of the maps web applications fails to load via rewrite.

PRS-387780

Registered PCS Appliance failing with Pulse one communication after importing user config and shows registration expired error message.

PRS-387641

"Sign Out message" does not properly display unicode text (Japanese, Korean, Chinese, etc.) with Sign-In Pages via browser.

PRS-387359

Unable to authenticate user using certificate. Reason: Wrong Certificate::unsupported name constraint type.

PRS-387349

System: Built-in Trusted Server CAs cannot be removed if they have subCAs.

PRS-387062

PSAM sending unintended traffic via tunnel to VPN in 9.1R3.

PRS-386875

User Sessions get disconnected after upgrading to 9.1R3HF1.

PRS-385747

Program dsdashsummary failing continuously on PCS running on 9.0R4.1.

PRS-385466

Sharepoint 2019 is not loading properly through web-rewrite.

PRS-385027

VDI Bookmark would not establish connection to the VDI resource without host entry on the client machine.

PRS-384955

XML Import of trusted server CAs generates a spurious admin log message for each unchanged CA.

PRS-382364

System: Device does not boot up when upgrading from 8.3R7.1 to 9.0R5 with option DELETES all system and user configuration data before installing the service package is selected.

PRS-381972

System : Licensing : "License server low-level protocol error, server=, Code = [6] :Could not resolve host name" populated in event logs of license server.

PRS-381905

After upgrading to iOS 13, HTML5 Access users seems to have broken the on-screen mouse pointer.

PRS-381716

AAA::Issues with host checker when user logs in to a different realm with TOTP auth server enabled.

PRS-381699

Pulse One 2.0.1902: Certificate > Trusted Server CA changes not being distributed (deleted expired CA).

PRS-381678

VIP became unreachable from enforcer when upgrading from 5.4R7 to 9.1R2.

PRS-381046

Rewrite: Dynamic365 menu tabs do not render when on 9.1R1.

PRS-380298

User access log indicates Login failed using auth server LDAP Server (Failed::unable to verify the first certificate) for wrong password.

PRS-380225

"Program fqdnacl recently failed" event failure on PCS 9.0R4.

PRS-379752

Reboot failed on PSA7000f.

PRS-379137

Gliffy Plugin in Confluence does not work via Web Rewrite.

PRS-376852

IPV4 Settings change in External or Internal port keeping Default VLAN ID same does not reflect under VLAN tab..

PRS-365669

SNMP: ifAdEntAddr mapped to wrong ifAdEntIndex values.

Release 9.1R4.3 PRs

PRS-389246

“500 Internal Error” is displayed when opening Authentication related pages.

Release 9.1R4.2 PRs

PRS-380298

User Access log indicates “Login failed using Auth. server LDAP server (Failed: unable to verify the first certificate)” for wrong password.

PRS-387780

Registered PCS Appliance fails with Pulse One communication after importing user config and shows “Registration Expired” error message.

Release 9.1R4.1 PRs

PRS-382268

PDC throws Authentication rejected by server [Error : 1319] when using global PCS url.

PRS-387062

PSAM sending unintended traffic via tunnel to VPN in 9.1R3.

Release 9.1R4 PRs

PRS-365669

SNMP: ifAdEntAddr mapped to wrong ifAdEntIndex values.

PRS-367786

Device locked up and dropped all connections due to Web process consuming CPU.

PRS-375181

VLS does not throw any error if there is no response for Heartbeats sent to PCLS.

PRS-377456

EasyPrint feature using the Premier Java RDP Applet not working.

PRS-379345

Program dsagentd failed.

PRS-379411

PCS not sending any Syslog traffic to configured Syslog servers.

PRS-379801

Active Sync stopped working after upgrading the device to 9.0R4.

PRS-380136

Cluster communication and state storage problems on A/A cluster.

PRS-380765

Program dsagentd recently failed after upgrading PCS from 9.0R3.2 to 9.0R4.

PRS-380796

PCS-VA sending critical SNMP alerts while leasing license.

PRS-380993

DFS: process snapshot generated by snmptrap process.

PRS-381100

Program dsagentd recently failed while running Mixed [V4 and V6] 60K VPN Tunneling ACL's throughput test on PSA5k for secure cache build-3164.

PRS-381366

Multiple users getting disconnected from Pulse Client.

PRS-381403

Sharing Feature is not working in macOS Catalina.

PRS-381579

Sometimes empty logs are seen under "Log/Monitoring".

PRS-381621

9.0R4 and 9.0R5 SPE (PSA-V) do not show the User Record Sync column in Admin UI > Auth Server page.

PRS-381633

Host Checker checking for virus definition file based on Number of updates fails for Sophos Endpoint Security and Control 10.8.4.

PRS-381736

After Upgrade from 8.3R7.1 to 9.1R1, error encountered while upgrading cache (in Host Checker).

PRS-381795

[FQDN ACL / NFQUEUE] Request DEV help in determining why thousand of VPN Tunnels dropped traffic within.

PRS-381960

Facing slowness when accessing web application through Authorization-only access post upgrading to PCS OS 9.0R5.

PRS-381963

Group Names in the role mapping rule will get added with &, # and; special character if more than 5 groups are selected with AD as the auth server.

PRS-381984

The cookie setting should be included in the resource profile.

PRS-382001

UI: Description incorrect on default deny in 9.1R3 initial deployment.

PRS-382021

Button to dismiss the banner on PPS/PCS Dashboard for not accepting Perpetual license is not working.

PRS-382031

Need to replace VA-SPE|PSA-V in "Only EVAL licenses are allowed for manual installation in VA-SPE|PSA-V".

PRS-382035

Proper logging for NFQUEUE full and drops needed, also consider this situation for cluster A/P failover or add to healthcheck.

PRS-382191

Unable to ping the IPv6 VLAN-Gateway from the PCS device after changing the Gateway address.

PRS-382240

User dropped from the VPN tunnel connection ##g_dhcp_proxy_wbuf is maxed!.

PRS-382350

Unknown RAID status in PSA7000f due to no space left on device.

PRS-382804

Active node went unresponsive in A/P cluster and generated multiple Watchdog snapshots.

PRS-384939

“Invalid EKU text” error found while configuring "E-mail protection" under EKU text.

PRS-384963

Host checker: After upgrading to 9.1R3, HC "Successfully loaded" message is garbled when it is initiated in browser with Japanese language.

PRS-384967

healthcheck.api showing incorrect MAXIMUM-LICENSED-USER-COUNT in AA cluster.

PRS-385144

Web Rewrite: Images not loading on the web page for a web resource configured via rewrite.

PRS-385150

Access via SSH port forwarding fails.

PRS-385159

Home page of eTime (Timesheet) Web application is not rendering properly via Rewrite in all web browsers.

PRS-385203

Add iOS check for 13.2, 13.2.1, 13.2.2.

PRS-385496

Adding default policy for Citrix resources.

PRS-385500

VLS should use only MSP Authcode for registering with PCLS.

PRS-385526

Add iOS Check for 13.2.3.

PRS-385550

Users cannot see full display of shared screen, if the size of text, app and other items in the "Scale & layout" in Display settings is set to 150% (Recommended) on the client's machine.

PRS-385721

Unable to restore Local User Accounts Backup on PCS 9.0R5.

PRS-387517

DanaLoc appears to be missing when using IE11.

PRS-387541

Web Rewrite: Drop-down menu, Refresh button, Change Password option and Login button not working on the login page.

Release 9.1R3 PRs

PRS-366490

System| Temperature status value on SNMP server displaying wrong value.

PRS-371351

Citrix sessions drop regularly causing various issues. These issues are observed in PCS 9.0 with Citrix port 2598 via JSAM. This issue is not found in 8.2R8.

PRS-371699

Users unable to login as well as dropping users - LMDB full.

PRS-372805

Realm level certificate restriction skipped with SAML Auth.

PRS-372999

Host checker is failing for Host Checker (OS-Check only) for Chrome OS 71.0.3578.127 with PCS 9.0R1 firmware version.

PRS-373160

Dropdown option misses internal menu while accessing via web rewrite.

PRS-374124

VDI Session are not showing under Virtual Desktop Sessions.

PRS-374146

UNC path is not handled properly by HOB Applet.

PRS-374318

PCS deployed on the AWS Cloud showing speed 10 Mbps.

PRS-374344

Last core dumps being generated at customer after 9.0R2.1HF6 with fixes.

PRS-374603

Syslog missing event logging info when upgrading.

PRS-374765

PSA7000f RAID failed after upgrading.

PRS-374831

Login page is not rendering properly for a web resource configured through rewrite.

PRS-374992

PCS using DUO as secondary authentication fails the first authentication attempt after installation.

.PRS-375079

CORE.fqdnacl crashes continues to occur even after 9.0R2.1HF6 (with fix).

PRS-375880

None of the contents in the Azure web portal are loading through rewrite.

PRS-375906

Unable to load a sign-in page getting stuck in loading the web page while accessing a web resource configured through the rewrite.

PRS-376036

PCS evaluation of the custom expression "time.dayOfYear" is not working as expected.

PRS-376247

Factory-reset does not work in 9.1R1 instead it boot up PCS with current image.

PRS-376249

Logon page of SAP fiori portal displayed as blank in IE11 only via rewrite.

PRS-376343

Mails are not getting synced in Native Email Client in iOS when using SA as ActiveSync Proxy due to stale records present and crash is happening in aseproxy-server service.

PRS-376357

When extending Pulse Client sessions, it causes network drop.

PRS-376429

JSAM stuck on loading forever on IE - Java.

PRS-376458

HOB stuck on loading forever on IE - Java.

PRS-376500

Azure 9.0R3.1 - postgresd service restarts constantly after deployment.

PRS-376520

Host checker fails to detect FireEye Endpoint Agent 29.7.0.

PRS-376840

Running Add command when the Disk is missing will cause a minor error message which requires a reboot.

PRS-376869

Dns_cache process snapshots persist after upgrading to 9.0R4HF6.

PRS-376953

Unable to view PDF files in the myDocuments application.

PRS-377022

File Share accessing issue in 9.0R4.

PRS-377160

HTML-5 -RDP requires additional authentication.

PRS-377482

After upgrading to 9.1R1, host checker word is garbled when it is initiated in browser with Japanese language.

PRS-377681

PSA7000f reports HDDs missing and inactive after upgrade to 9.1R1.

PRS-377825

After upgrading to 9.1R1, the name of the user role displayed in submenu is broken if the language is in Korean.

PRS-377979

When accessing the resources via bookmark, contents are not displayed correctly.

PRS-378049

Failed filesystem integrity check message seen on PSA5K console after upgrading from 9.1R1 to 9.1R2-2119.

PRS-378882

Periodic Snapshot settings via REST fails with error "Modification of Attribute not Allowed".

PRS-378964

When the admin clicks on 'Agent', they receive an error "the page you requested could not be found".

PRS-379125

Pulse One 2.0.1901: With PCS 9.0R5 (EA) having failure in target importing SAML using Artifact - empty "Source Artifact Resolution Service URL".

PRS-379336

Chat option not working on the Medical application.

PRS-379773

Syslog - If an appliance is rebooted, it cannot successfully reconnect to a P1 syslog server.

PRS-379974

Critical Events do not get displayed in System > Overview Page.

PRS-380009

REST API calls failing for RDWeb Profiles in PCS.

PRS-380148

When syslog server's FQDN resolves to two IP addresses, one of which is reachable, PCS/PPS may fail to connect.

PRS-380762

Delay during session failover of PCS in Active/Active cluster in AWS.

PRS-381014

Japanese words are garbled when we click on the File share bookmark.

PRS-381318

DMI get-config of RDWeb resource profile returns badly formed XML.

Release 9.1R2 PRs

PRS-367907

FQDNST denied IP is going via tunnel.

PRS-370210

Clear config on PSA 300 fails with unable to mount /webserver partition.

PRS-372439

Post failover, session resumption delayed with Pulse Client.

PRS-373290

Clear config on PSA 300 fails with unable to mount /webserver partition.

PRS-375013

Radius OTP as Secondary authentication fails for the Pulse Client.

PRS-375329

HOB failed to launch through Java in IE.

PRS-375886

JSAM launch failing for IE -JAVA.

PRS-376312

Factory reset from VMware VA console does not load the factory reset version and loads the current version.

PRS-376348

VMWare View 5.1 client does not connect after upgrade.

PRS-376859

Premier Java Applet for Terminal Service failed to download .jar file.

PRS-377945

Publishing for certain block types causes many log messages and other side effects.

Release 9.1R1 PRs

PCS-5064

Remove legacy mode from Active Directory auth. server.

PRS-375534

JSAM Stats value (Bytes count) is not getting displayed in IE - Activex.

PRS-375067

DNS resolution not working for alternate VPN connections.

PRS-374597

The definition update is not listed for Sentinelone product in "epupdate_hist.xml" file.

PRS-374057

Unable to add the resource <userAttr.Framed-Route> in IPV4 address under Split tunneling policy for PCS version 9.0Rx.

PRS-374037

Rewrite: PSAL launching Citrix app multiple times in an infinite loop on all the browsers.

PRS-373948

Contents of a web response are not getting compressed as content encoding header is missing in the response from PCS.

PRS-373769

Host Checker IMC detects the Antivirus Change in the client PC and report it to IMV even when Perform Check every min is set to 0.

PRS-373696

Split tunneling FQDN policy with special character, fails to save.

PRS-370953

Unable to edit word documents hosted on SharePoint 2013 via PTP using MS Edge.

PRS-371023

Resource access dropped (RDP, SSH etc.) intermittently on SAW environment.

PRS-373102

Core Access: E-mail web page getting stuck on "login processing".

PRS-373076

Core Access:Web page shows horizontal scrollbars at the bottom of screen.

PRS-372181

DanaLoc fails in case of old window object reference from a new window object.

PRS-372834

PSAM:Pulse SAM takes at least 40 seconds to open custom start up page in UI Options compared to WSAM.

PRS-372677

AAA/Security/Pulse: SAML AuthnRequest leaks data across users with "Reuse NC/Pulse session" enabled.

PRS-372595

User getting same IP address assigned from IP pool in few hours.

PRS-372489

Pulse browser Toolbar is flickering when accessing OWA 2016 resource on iOS device through webrewrite.

PRS-372285

PSA 7000f Frequently reports one of the power supplies is back up.

PRS-372055

Unable to save Citrix listed application using Hostname with port number.

PRS-371973

HC: Compliance fails using Pulse Desktop client 9.0.2 build 1151.

PRS-371970

Users with username in UPN format in System Local Authserver are unable to log in using TOTP after upgrading to 9.0R3.

PRS-371944

Killed user session admin log "ADM23534" does not display admin user but the actual user being terminated.

PRS-371800

PCS device is unable to get the enrolled mobile device attribute from MDM server.

PRS-371394

Setting the hash property of location object causes problem in IE, Edge and Firefox browsers because the URL is appended with fragment identifier. In chrome and Safari browsers things work fine.

PRS-371602

Post upgrade to PCS 9.0R3, "License server low-level protocol error Code = [47]" error is triggered on license client.

PRS-371513

Page does not load via IE browser.

PRS-371406

"Auto populate domain information" behavior when unchecked: blank first then if wrong password, auto populates domain.

PRS-371357

HTML5 RDP logging do not show realm and shows ().

PRS-371342

Add iOS Check 12.1.1.

PRS-371266

Menu is not loading when accessing the application through web-rewrite.

PRS-371231

PCS 9.0 VA-DTE :: Nodes in cluster gets disabled automatically.

PRS-371205

Multicast Traffic not working intermittently in the VPN Tunnel in 8.3R6 / 5.3R6 version and after restarting services, works fine for all users.

PRS-371154

Wrong information in the log messages for Authorization Only Access when source ip restriction is configured on role.

PRS-371114

Add support for adding parameters “client-name’ for HTML5 Access.

PRS-369351

LDAP authorization does not work when using ikev2 tunnel (handle 10K tunnels+few hundred ikev2 clients).

PRS-370138

Read-only admin sessions see an option as disabled that is actually enabled on user roles.

PRS-369960

Page displayed while PSAL downloads to a Mac client shows instruction for Mac; but then references Windows System Tray.

PRS-369200

Logs are not fully displayed if select the date as filter.

PRS-369142

File browsing SSO is not working with user details are given in variable form as well when configured to use system credentials.

PRS-369031

When a configuration object is renamed, not all of the resulting configuration changes are uploaded to Pulse One.

PRS-368927

Web process crashes and logs "ERR31093: Program web recently failed." in the event logs.

PRS-367879

Core Access: Unable to import or download the image using PTP.

PRS-367789

DMI agent not responding to netconf commands as expected.

PRS-367285

System| Active/Passive cluster responding to ICMP request even after shutdown.

PRS-366634

Randomly users are not able to access IPv6 resources through VPN device via VPN tunneling.

PRS-364219

PSA7000f interface status in Network Settings not working.

PRS-366490

System| Temperature status value on SNMP server displaying wrong value.

PRS-371351

Citrix sessions drop regularly causing various issues. These issues are observed in PCS 9.0 with Citrix port 2598 via JSAM. This issue is not found in 8.2R8.

PRS-371699

Users unable to login as well as dropping users - LMDB full.