Cisco Cisco Secure Access Control System 5.1 Release Notes

Page of 54
 
19
Release Notes for the Cisco Secure Access Control System 5.1
OL-18997-01
  Resolved Issues in Cumulative Patch ACS 5.1.0.44.4
Resolved Issues in Cumulative Patch ACS 5.1.0.44.4 
 lists the issues that are resolved in the ACS 5.1.0.44.4 cumulative patch.
You can download the ACS 5.1.0.44.4 cumulative patch from the following location:
Refer to 
 for instructions on how to apply the patch to 
your system
.
Table 8
Resolved Issues in Cumulative Patch ACS 5.1.0.44.4
Bug ID
Description
CSCtf72641
ACS 5.x does not allow LEAP-first authentication
 CSCtf08567
ACS 5.1 permits command without arguments where it should deny it.
 CSCtg15941
ACS 5.1 high memory usage. More than 90% memory is used when idle or with less load.
 CSCtd46884
ACS 5.x AD save changes fail if admin password contains a space.
 CSCtg38950
EAP-GTC always use hardcoded password prompt 'password:'
 CSCtg52633
ADClient fixed to be able to handle duplicate CLDAP on UDP port 329.
 CSCtf78048
Optimize discovery of host's account domain.
 CSCtf23507
Support non-MS Kerberos (MIT).
 CSCth59823
Replication is broken due to ActiveMQ exception.
 CSCtg58234
EAP-FAST do not work if username case is different between PAC, inner method.
 CSCtg38987
Password/passcode is not configurable for RSA Identity Store.
 CSCtg87278
ACS not able to establish SSL tunnel with LDAP server with CRL verification.
 CSCte95063
After "clock set" view log processor goes to 'not monitored' state.
 CSCth82664
ACS database needs to be compressed as a maintenance operation.
Follow these steps to compress the ACS database:
1.
Move all the secondary nodes to local mode. 
2.
On the primary node run the command:
acs-config database-compress [truncate_log]
This maintenance operation compresses the ACS database by rebuilding each table in the database 
and releasing unused space. The command also has the option to release the replication transaction 
table. 
3.
After the database compression is completed and all the services are up again, reconnect the 
secondary nodes one by one.
After reconnecting the secondaries, full-sync between the primary and the secondary will be 
initiated automatically. 
 CSCth77468
ACS 5.1 do not include 'C' and 'V' values in MS-CHAP-v2 Failure Packet.
 CSCth72626
MS-CHAPv2 responses with bad flag values will not be dropped.
 CSCth62273
ACS database can become large due to incomplete user password changes.
 CSCth62139
ACS authentication rate decreases with internal user attributes.
 CSCtf43054
Group assignment dialog does not allow "+" symbol in group name.