Fudo Enterprise 6.2 - System Documentation¶
Welcome!
The following are the enhancements and modifications introduced in version 6.2 of Fudo Enterprise. Remember to update to the latest available version to benefit from all improvements.
Version 6.2.1 (Latest)
In this release, the improvements focus on
AI Live Session Monitoring [BETA] - AI agents analyze an SSH session while it is still running, and a policy can react to their findings, up to pausing or terminating the session. Disabled by default; SSH only; session content is sent to the configured AI model, which may be self-hosted. After the beta stage it will be delivered as a separately licensed module. See AI Live Session Monitoring [BETA] and Live Session Analysis Policy [BETA].
Session sharing improvements (see Sharing Sessions):
Share links now work on the User Access Gateway address, not only on the Admin Panel address. Link generation returns both addresses, built from the same key - send whichever the recipient can reach.
Authenticated shares - the recipient must sign in to Fudo before viewing, and their identity is recorded. Anonymous, key-only shares remain available.
Users can share their own live sessions from the User Access Gateway (UAG), without an administrator. Enabled per safe with Allow users to share live sessions. Such shares always require sign-in, grant interactive access and expire when the session ends.
“Until the session ends” validity - shares of running sessions no longer need a time window.
Live supervision - a safe can require a set number of authenticated supervisors to watch a session. The session does not start until they connect, pauses if the count drops, and resumes automatically when it recovers. Supported for RDP, VNC, SSH shells, Telnet/TN3270/TN5250 and rendered HTTP. Anonymous viewers do not count towards the required number.
Access history - every viewer connection is recorded with identity or Anonymous, source IP, address used, and view, join and disconnect times. Entries survive link deactivation.
Redesigned sharing dialog.
Master key storage in an HSM. Fudo can use a Hardware Security Module (HSM) to provide hardware-backed protection for its master key. HSM integration supports key rotation and clustered deployments. See Storing the master key in an HSM and Master Key Protection with a Thales Luna HSM.
Note
KEK rotation is not supported for clusters in this release.
Oracle (TNS/TTC) protocol support [BETA] - native monitoring of Oracle databases with session recording, playback and SQL command policies. See Oracle [BETA].
Location-based access restrictions. Connections can now be allowed or blocked by the country and network they come from. A policy holds a list of countries and networks and is applied to users through groups, on top of a built-in global policy. See Location Policies.
Custom scopes in OpenID Connect configurations. An OpenID Connect configuration can now carry a custom scope, sent to that identity provider in addition to the standard
openid,profileandTime-based Just-in-Time approval - a Just-in-Time safe can now skip the approval step during the hours covered by the user’s Daily Access Policy, and require an approved access request only outside them. See Access Requests.
Enforced reason format for Just-in-Time requests. Administrators can now require users to provide access request reasons that match a predefined format. See Access Requests.
New RDP engine (FreeRDP 3). The RDP proxy has been reimplemented on FreeRDP 3. Existing listeners keep the previous engine after the upgrade - the Use legacy RDP implementation option on the listener stays selected. See Setting up the RDP Listener.
Audio in RDP recordings. Sound from the remote session is now captured and played back in the session player. See Sessions.
Redesigned Daily Access Policy editor - draw, move and resize access windows directly on the weekly grid with 30-minute precision, copy a day to the whole week, and choose explicitly whether a bulk edit merges with or overrides existing schedules. See Creating a Safe.
Time policies for users accessing safes through groups. Group-to-safe assignments now support the Blocked option and an Access time period, matching direct user-to-safe assignments. You can also configure an individual user’s time policy from the Access via groups section without assigning the user directly to the safe. See Creating a Safe and Access Resolution and Prioritization.
RFC 5424 syslog log format support - each external syslog server can now forward event log entries in either the RFC 3164 (BSD) or the RFC 5424 wire format. Existing servers keep their current behaviour. See External Syslog Servers.
The availability of the Productivity module is determined by the license file and can be disabled at the customer’s request, to comply with legal requirements restricting the monitoring of employee productivity.
Configurable scope for automatic interface routes. You can now decide whether routes derived from interface IP addresses are added to every routing table or only to the interface’s own table. See Network Interfaces Configuration.
French (AZERTY) keyboard layout support. See User Portal Configuration and RDP/SSH/VNC Login Screen Configuration.
JWT authentication support. Fudo Enterprise can now accept a signed JWT presented in an HTTP header as the credential for a request, which lets a web application firewall or reverse proxy authenticate users at the perimeter on Fudo’s behalf.
Optional domain appending for RADIUS authentication. A new Append domain to username option in the RADIUS external authentication server definition controls whether the user’s AD domain is appended to the login sent to the RADIUS server. See External Authentication Server Definition.
Note
The option is enabled by default - also for definitions that existed before the upgrade - so the current behavior is preserved. Clear it when the RADIUS server expects the bare username and resolves the domain on its own.
Administrator control over user-managed authentication methods in the User Access Gateway - administrators can now decide system-wide which authentication method types User Access Gateway users may add and remove on their own. See User-Managed Methods in the User Access Gateway.
Modules disabled for a user are now hidden and blocked in the User Access Gateway. A user whose PSM or Password Vault module is disabled sees the section greyed out and can no longer reach it - nor the module’s API. The block takes effect immediately and no longer waits out the 30-day active-user period.
Reworked assignment tables. The lists used to assign groups, pools and object rights now match the main lists and support working multi-select.
Password Vault improvements. Bulk delete, move and secret changer runs now report progress object by object, show which items failed without abandoning the rest, and can be stopped part-way. Smaller fixes across the vault interface round out the release. See Deleting Secrets.
Configurable OCR confidence threshold. A new system-wide setting controls the minimum confidence required for recognized text to be indexed. The threshold can be set from 0 to 100 and defaults to 95, preserving the existing behavior. Lower values can improve text detection in noisy sessions, with a higher chance of false matches.
Secure secret storage in Fudo Officer. Fudo 6.2 adds API endpoints that issue a per-device database key. An upcoming Fudo Officer release will use it to store the app’s data in an encrypted database rather than a file protected by the device PIN, removing its exposure to PIN brute-forcing.
Password Vault in Fudo Officer. An upcoming release of the Fudo Officer mobile app will bring the Password Vault to the phone: browsing and searching accessible collections, viewing secret details, sending an access request when approval is required, and filling a matching secret into another application on Android and iOS. Users will also be able to view, filter and create their own personal secrets - logins, SSH keys, notes and certificates - directly in the app.
TLS hostname verification for monitored servers. Fudo checks that a server’s certificate covers the address it connects to, controlled per server by the new Verify hostname option. The upgrade leaves the option off, so existing servers are unaffected.
Password Vault Browser Extension 1.1 (see Fudo Password Vault Browser Extension):
Added support for viewing, adding, and deleting secrets in Personal Vault.
Added 2FA (Two-Factor Authentication) support for authentication.
Updated the underlying FreeBSD base system to the latest supported 14.4 patch release, including recent security fixes.
Added the
Permissions-Policyheader to responses from the web interfaces, disabling browser features that are not used by Fudo Enterprise.Added the
Cache-Control: no-storeheader to application responses. The browser cache no longer has to be cleared manually after an upgrade.Changed the cipher preference in connections to monitored SSH servers, so that AES-GCM is offered before AES-CTR. This prevents connection failures with servers supporting only legacy MAC algorithms.
Table of Contents¶
- About Documentation
- Layout Themes of the Admin Panel
- Introduction
- System Deployment
- Quick Start
- Sessions
- Filtering Sessions
- Viewing Sessions
- Pausing Connection
- Terminating Connection
- Joining Live Session
- Sharing Sessions
- Commenting Sessions
- Sessions’ Retention Lockdown
- Exporting Sessions
- Deleting Sessions
- OCR Processing Sessions
- Session Data Replication
- Session Timestamping
- Require Approval for Access
- AI Behavioral Analysis in Sessions
- AI Session Summary
- Access Requests
- Reports
- User Management
- Session Management
- Servers
- Creating a Server
- Creating an HTTP Server
- Creating a Modbus Server
- Creating a MS SQL Server
- Creating a MySQL Server
- Creating an Oracle Server [BETA]
- Creating a PostgreSQL Server
- Creating an RDP Server
- Creating an SSH Server
- Creating a Telnet Server
- Creating a Telnet 3270 Server
- Creating a Telnet 5250 Server
- Creating a VNC Server
- Creating a TCP Server
- Port Ranges in Server Configuration
- Use SSH Tunnel - SSH Reverse Tunnel Server Configuration
- Importing a Server List from CSV File
- Editing a Server
- Blocking a Server
- Unblocking a Server
- Deleting a Server
- Creating a Server
- Pools
- Accounts
- Listeners
- Creating a Listener
- Setting up the SSH Listener
- Setting up the RDP Listener
- Setting up the VNC Listener
- Setting up the HTTP Listener
- Setting up the Modbus Listener
- Setting up the MySQL Listener
- Setting up the Oracle Listener [BETA]
- Setting up the PostgreSQL Listener
- Setting up the TCP Listener
- Setting up the MS SQL Listener
- Setting up the Telnet Listener
- Setting up the Telnet 3270 Listener
- Setting up the Telnet 5250 Listener
- Editing a Listener
- Blocking a Listener
- Unblocking a Listener
- Deleting a Listener
- Creating a Listener
- Safes
- Discovery
- Remote Applications
- Policies
- Downloads
- Productivity
- Servers
- Password Vault
- Settings
- System
- Network Settings
- Notifications
- Artificial Intelligence (AI)
- Authentication
- External Passwords Repositories
- External Storage
- Resources
- Backup and Retention
- Cluster Configuration
- Users Synchronization - User Directory
- SCIM 2.0 Provisioning
- Managing Access to the SCIM Configuration
- Configuring SCIM Provisioning
- Configuring the Identity Provider
- Rotating the API Key
- Disabling SCIM Provisioning
- SCIM-Managed Account Behavior
- Attribute Mapping
- Attributes That Are Not Supported
- Example Payloads
- Restrictions On Scim-Managed Objects
- Blocking Model
- Authentication with OIDC
- Auditing
- Certificate-based Authentication Scheme
- Login Timeout
- System Version Restore
- System Reboot
- Changing Encryption Passphrase
- Integration with CERB Server
- System Maintenance
- Events Log
- Account Activity in the User Access Gateway (UAG)
- Reference Information
- Fudo Officer 2.3
- Fudo ShareAccess
- Client Applications
- Troubleshooting
- Use Cases
- Two-Factor OATH Authentication with Google Authenticator
- OpenID Connect Authentication Definition with Microsoft Entra (Azure)
- Remote Desktop Services Configuration on Windows Server for Fudo Enterprise
- Custom RDP Hostname in the Session Title
- Managing RDP Server Certificates in Windows Server
- Configuring the Single Sign On (SSO)
- Handling Local Account Password Changes Using a Domain Account with WinRM Secret Changer
- Configuring SSH Key Rotation for an Account
- Configuring Kerberos Constrained Delegation for MSSQL(TDS) Server
- Establishing Connections to Servers via SSH Tunnel in Fudo Enterprise
- Master Key Protection with a Thales Luna HSM
- Frequently Asked Questions
- Glossary