We use cookies to ensure the proper functioning of our website (essential cookies) and, with your consent, for other purposes (functional and other cookies) as outlined in our Cookie Policy and Privacy Policy. You can update your cookie preferences at any time.
Share your feedback to help shape what we build next.
Product Roadmap
See what features and improvements we’re planning for ISL Online.
Delivered
macOS permissions & Native support for Apple Silicon (arm64)
Spawn macOS permissions for screen capture and accessibility on start of ISL Light session.
ISL Light currently runs on macOS ARM (Apple Silicon) via Rosetta 2, which translates Intel (x86) binaries to ARM at runtime. Apple plans to deprecate Rosetta (expected ~macOS 28), after which Intel-only apps will no longer run.
Customization Self-Service
Introduces initial options for branding and interface adjustments, enabling organizations to customize the appearance of ISL Online.
Generic Clipboard
Extend clipboard functionality in ISL Light to support generic clipboard data, including files, folders and images, not just plain text.
In progress
Persistent Login
Keeps users signed in across sessions to streamline access and reduce login repetition.
Shortcuts for “Ctrl+Alt+Del” and Paste Typing
Provide users with new built-in keyboard shortcuts: Right Ctrl + Alt + End for Send Ctrl + Alt + Delete, and Right Ctrl + Shift + V for Paste Typing (simulate keystrokes).
Launch installed app from browser
Introduce deep linking via ISL Light schema to enable launching the installed ISL Light application directly from the browser, instead of downloading a new executable.
Next
Show Logged-In User on Remote Computer
Displays the currently logged-in operating system user on the remote computer.
Device Lookup
Features to lookup for a device, such as advanced search, flexible filters, sortable columns, pagination, and bulk actions for improved management and navigation.
Shortcuts: Paste (type) & Ctrl+Alt+Del
Provide users with two new built‑in keyboard shortcuts that improve workflow efficiency and align with expectations from competing remote desktop tools: Right Ctrl + Alt + End → Send Ctrl + Alt + Delete to remote device Right Ctrl + Shift + V → Paste Typing (simulate keystrokes).
Note: All updates have the release date set to 2024-01-26. Your ESS should be the same or higher to be able to update your server. This release is available to all countries except for Japan.
ISL AlwaysOn 4.4.2332.54 provides new features and bug fixes.
New Features
Support for Direct Connection
ISL AlwaysOn introduces enhanced support for direct connection, known for its speed advantages.Note: This direct connection feature will become fully accessible upon the release of the upcoming ISL Light desktop app, which will also support direct connection.
ISSC clipboard improvements
Our clipboard implementation in ISSC has been upgraded. We now conduct multiple attempts when reading from and writing to the clipboard. Each attempt will be delayed for 13-20ms with a total of 50 attempts, compared to the previous 50ms delay and N attempts.For performance monitoring, we’ve introduced metrics that track the number of attempts required to open the clipboard, enabling the identification of potential lock loops over time.
Require email authorization for incoming connections
The latest update includes the ability to enable email authorization, requiring approval for incoming connections. Recipients will receive an email, providing them with the option to either approve or deny the connection. This feature adds an extra layer of control and security to your connection processes.
ISL AlwaysOn will no longer initiate the launch of ISL Light Fast, ISL Light Client, and tray processes. Instead, ISL AlwaysOn will utilize the ISSC daemon for these functions. This change enhances security by eliminating a local pipe previously used by the old ISL AlwaysOn Monitor to report the status of initiated processes.
Increase Notification Timeout limit for unattended access
In the latest update of ISL AlwaysOn, the Notification Timeout setting, found in the Desktop Sharing section of the settings, has been extended from 120 seconds to 500 seconds (8 minutes and 20 seconds). This extension allows for a more flexible and accommodating duration for unattended access notifications.
Optimized setting text for computer access with local consent
The setting previously labeled “Allow computer access also with local user consent and no access password” in the Desktop Sharing section has been refined and now reads as “Allow computer access without an access password (local user consent required).”
Upgrade QT to 5.15.11
QT version was upgraded to 5.15.11 in ISL AlwaysOn application.
Upgrade mbedtls to 2.28.5
We have upgraded mbedtls to version 2.28.5
Upgrade LibXML2 to 2.9.14 and LibXSLT to 1.1.37
Library LibXML2 was updated to version 2.9.14 and library LibXSLT was updated to version 1.1.37.
Bug Fixes
Improved error handling in Access History
In a recent update to ISL AlwaysOn, an issue related to corrupted entries in the sessions.xml file has been addressed. Previously, users encountering a corrupted sessions.xml file experienced an empty history window without any error messages.
With the recent enhancement, error handling has been improved. If the sessions.xml file is corrupted, users will now be promptly notified with an alert. This alert will also provide information about the specific line in which the corruption was detected, ensuring a more transparent and informative user experience.
Other fixes & improvements
Security updates, missing translations, bug fixes and other improvements.
Note: All updates have the release date set to 2024-01-16. Your ESS should be the same or higher to be able to update your server. This release is available to all countries except for Japan.
These are the server side updates, meaning hosted service users do not need to do anything. Server license users please check Upgrading Server License.
ISL Conference Proxy 4.4.2335.62 provides new features and bug fixes.
New Features
Single Sign-On/SAML per domain
ISL Conference Proxy now supports Single Sign-On login (SAML) for each domain.
New domain settings are available in the server administration (/conf -> Domain settings -> Security -> Organization). These settings help designate a specific domain as an organization:
Organization Login Enabled: If set to “Yes”, unique values for both organization name and description are required for all domains. SAML login must also be enabled for the domain.
Organization Name: Used for case-insensitive input in the field layout and internally for remembered organizations.
Organization Description: Displayed to users in remembered organization logins, combo box layout, and vertical chooser layout.
Organization Order Index: An optional setting to reorder organizations in combo box layout or vertical chooser layout in ascending order. An empty value places it first.
Server Administration > User Management > Organizations > Domain (greenbike) > Security
New global settings in server administration (/conf -> Security) include:
Login Layout: Options are Username & Password (default), Username & Password, Organization, and Organization.
Organization Login Layout: Options are Name Input Field (default), Description Combo Box, and Description Vertical Chooser.
Server Administration > Configuration > Security
Layout settings determine the user interface shown during logins. If “Login Layout” is set to “Username & Password” (default), organization login is disabled. If set to “Username & Password, Organization”, users can choose to log in with a username and password or an organization. When set to “Organization”, users can only log in using their organization.
ISL Conference Proxy Web Portal > Login > Sign in to organization (example with “Username & Password, Organization”)
When an organization login is selected, the “Organization Login Layout” setting is checked. If set to “Name Input Field” (default), users must manually enter the organization’s name. If set to “Description Combo Box” or “Description Vertical Chooser”, users can select the organization from a combo box or vertical chooser. The combo box has a limit of 1000 organizations, while the vertical chooser supports up to 20 organizations.
ISL Conference Proxy Web Portal > Login > Sign in to organization > Find Your Organization (example with “Name Input Field”)
Once a user selects an organization, it is used in all subsequent logins unless canceled. For users with a configured subdomain and default domain as an organization, organization login is automatically used when initiating login using the subdomain DNS name.
Additionally, users utilizing per-domain SAML or organization login can change their email without a password check, unless email changes are blocked in SAML login rules.
SSO/SAML username remapping
A per-user setting was added to system administration:
SSO domain username remap: SSO login (SAML) will try to match “username” key with this setting within the same “domain” and if it matches, “username” will be set to the matching account (duplicate match will abort the login)
A new rule was added to setting SAML login settings rules in system administration, which is useful for remapping username to a sanitized value, for example, replace all special characters with – and @ with _AT_:
Regex supports “(?g)” pattern to indicate global (all) match.
\\1 for match group replacement in TO
The following example shows how to map the user “tim.thomas@example.com” to user “\\testDomain\tim-thomas”: In the Server Administration, in the domain settings of “testDomain”, add the following to “SAML login settings rules”:
Server Administration > User Management > Domain > Sercurity (ctrl + f “SAML login settings rules”)
In the Server Administration, in the user settings of “\\testDomain\tim-thomas”, set “SSO domain username remap” to:
"tim-thomas_AT_example-com"
Server Administration > User Management > User > Security (ctrl + f “SSO domain”)
And now the result, tim.thomas@example.com is sanitized to tim-thomas _AT_example-com and then remapped to tim-thomas as shown on the image below.
ISL Conference Proxy Web Portal > Sessions > Example SSO/SAML username remapping
Custom Deployment Link
A new option, “Custom Deployment Link,” has been introduced to the “Computers pages” dropdown in “Set Unattended Access.” This feature provides a dedicated page with various options to assist in deploying the ISL AlwaysOn agent to remote computers.
Users can customize settings such as Computer Name/Alias, Computer Group, Tags, Access Password, and choose options for Silent Install and upgrading ISL AlwaysOn. The generated deployment link can be copied, or ISL AlwaysOn with the specified options can be downloaded.
ISL Conference Proxy Web Portal > Computers > Custom Deployment Link
Additionally, a new permission has been added to ISL AlwaysOn settings: “Allow access to Custom Deployment Link page.” By default, this setting is enabled, allowing users to access and utilize the Custom Deployment Link page.
ISL Conference Proxy Server Administration > Configuration > ISL AlwaysOn
Support for authorize remote access connections via email
ISL Conferenece Proxy (ISL AlwaysOn module) now includes support for authorization via email for remote access connections. When the ISL AlwaysOn remote agent is configured with email settings, it sends an email notification about incoming connections to specified addresses. This notification is triggered when a user attempts to connect to the remote computer, after the access password is verified but before obtaining remote user consent (if required).
ISL Conference Proxy > Request to Start Session
The connection request email provides basic information about the connecting user and the target computer. Recipients can conveniently review the request via the provided link and decide whether to allow or deny the connection. If allowed, the connection procedure proceeds as usual. In the case of denial or failure to allow within the specified time (default is 180 seconds), the connection is promptly closed.
The expiration time for authorized access emails is configurable on the remote computer through a new setting in ISL AlwaysOn. If a connection request email is sent to multiple addresses, only the first recipient to respond (allow or deny) has the authority to make a decision. Once a decision is made, the connection request becomes inaccessible for further review.
Furthermore, new setting “Mail template for authorize incoming connection” was added to ISL AlwaysOn settings in Server Administration, which can be used to set the custom email template.
Email example to request to start session
Setting “Collapse multiple repeated log lines”
A new setting, “Collapse multiple repeated log lines,” has been added to the server administration “Logs” section. This setting instructs the log writer to collapse multiple instances of repeated log lines as “- N -“, where N represents the number of repetitions. The default is set to “Yes,” preserving the previous behavior.
Additionally, a development flag, “no_collapse_log” (Force no collapse log lines), has been introduced. This flag overrides the server administration setting.
ISL Conference Proxy Server Administration > Configuration > Logs
Sign .extra file with CRC32
In the latest update, the program’s “.extra” file is now signed using CRC32 and is validated during extraction and parsing processes.
AKV Activity Logs Updates
In previous versions activity log was only possible by setting “Record activity log” setting in /conf -> Logs. Additionally, support for logs in AKV format was now added, which can be enabled by setting [Core] Activity log (core_activity_log) logging subsystem to Info.
Settings behavior:
Record activity log: Controls CSV activity log only.
Control activity logging scopes for both CSV and AKV logs: – Enable system activity log. – Enable admin activity log. – Enable user activity log.
Upgrade to Go 1.20.12
The Go version has been upgraded to 1.20.12.
Update to LibXML 2.11.6 and LibXSLT 1.1.39
LibXML has been updated to version 2.11.6, and LibXSLT has been updated to 1.1.39.
Upgrade to OpenSSL 3.0 LTS
The OpenSSL library has been upgraded to version 3.0.12.
Bug Fixes
Improved User List Loading in Share Dialog
In the previous version, the share computer/group modal sometimes failed to display all users due to a calculation error in determining the bottom of the scroll view. This issue has been resolved by redesigning the calculation, ensuring accurate computation of the bottom, and enabling the loading of additional users in the dialog when needed. The defect has been fixed.
Port ICP’s CPP HTTP Proxy Setting Parser to Go
In previous versions, parsing the value of the “HTTP proxy for web client” setting would fail if the value was not a valid URL. This issue has been addressed by porting ICP’s custom parser to Go. As a result, the problem should no longer occur. The defect has been fixed.
SSL Module: Increase z-index of Tooltips
In the previous version, tooltips in the SSL module’s “Install Certificate” modal were displayed behind the modal, causing visibility issues. This has been resolved by increasing the z-index of the tooltips, ensuring they are displayed correctly. The defect has been fixed.
Add Missing Permission Translation for Administration Page
In previous versions, the error message for missing Domain Admin permission (“To access Administration, you must have “Domain Admin” permission enabled. Please contact your administrator for assistance.”) was not translated. This issue has been addressed by redesigning the implementation, and the string should now be accurately recorded and translated. The defect has been fixed.
Other fixes & improvements
Security updates, bug fixes and other improvements. These changes are aimed at improving the stability, security, and performance.