<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
    <channel>
        <title>Release notes | PingDirectory</title>
        <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html</link>
        <description>Release notes</description>
        <lastBuildDate>Fri, 28 Aug 2026 21:46:06 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <ttl>5</ttl>
        <copyright>Copyright 2026 Ping Identity. All rights reserved.</copyright>
        <item>
            <title><![CDATA[PingDirectory suite of products 10.3.0.5 (August 2026)]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-5-august-2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-5-august-2026</guid>
            <pubDate>Fri, 28 Aug 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="sect2">
<h3 id="fixed-a-critical-issue-with-the-pingone-real-time-sync-source"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-critical-issue-with-the-pingone-real-time-sync-source"></a>Fixed a critical issue with the PingOne real-time sync source</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51712</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed a critical issue where a PingOne real-time sync source could stall and stop processing changes until an administrator manually restarted the affected sync pipes. The source intermittently computed invalid filter bounds or polling windows too small to retrieve entries.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-server-updates-in-containerized-environments"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-server-updates-in-containerized-environments"></a>Fixed an issue with server updates in containerized environments</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51723</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue introduced in 10.3.0.1 where running <code class="cmdname"><strong>update</strong></code> or <code class="cmdname"><strong>revert-update</strong></code> in a containerized environment could fail with an <code class="msgph">Error determining current build information</code>. This error could occur if the JVM path recorded in <code class="filepath">config/java.properties</code> wasn’t present in the current container image.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-missing-attribute-updates-after-a-repair"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-missing-attribute-updates-after-a-repair"></a>Fixed an issue with missing attribute updates after a repair</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51487</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where a replica could silently miss attribute updates after the Replication Repair control was used to delete an entry on that replica, and then the entry was later re-added. Other replicas would have the updated attribute, while the affected replica didn’t.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-server-shutdown-delay-issue"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-server-shutdown-delay-issue"></a>Fixed a server shutdown delay issue</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51291</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where a large number of peer connections or unresponsive peers could cause excessively long server shutdown times.</p>
</div>
</div>
<div class="sect2">
<h3 id="improved-verify-index-schema-consistency-detection"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#improved-verify-index-schema-consistency-detection"></a>Improved <code class="cmdname"><strong>verify-index</strong></code> schema consistency detection</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-51409</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>The <code class="cmdname"><strong>verify-index</strong></code> tool now checks for entries whose DN2ID index key can’t be found because an attribute syntax or matching rule was altered after the entry was created.</p>
</div>
<div class="admonitionblock important">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-important" title="Important"></i>
</td>
<td class="content">
<div class="paragraph">
<p>Altering the schema definition of an attribute syntax or matching rule might cause existing entries to become inaccessible through LDAP search until the backend contents are exported to LDIF and re-imported.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect2">
<h3 id="update-tool-logs-a-benign-warning"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#update-tool-logs-a-benign-warning"></a><code class="cmdname"><strong>update</strong></code> tool logs a benign warning</h3>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_ticket">DS-51930</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>When you run <code class="cmdname"><strong>update</strong></code> to apply a server update, the tool logs a benign <code class="msgph">Unexpected non-EA suffix</code> warning. The warning has no effect on the update and can be safely ignored.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[PingDirectory suite of products 10.3.0.4 (May 2026)]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-4-may-2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-4-may-2026</guid>
            <pubDate>Fri, 29 May 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="sect2">
<h3 id="updated-the-version-of-the-psa-included-with-the-server"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#updated-the-version-of-the-psa-included-with-the-server"></a>Updated the version of the PSA included with the server</h3>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_ticket">DS-13850</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We updated the Password Sync Agent to version 4.8.</p>
</div>
</div>
<div class="sect2">
<h3 id="server-tuning-improvements-for-rate-limiting"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#server-tuning-improvements-for-rate-limiting"></a>Server tuning improvements for rate-limiting</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-50863</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>To help you tune the server’s rate-limiting operations, and to identify unusual client activity, you can now allow operations to exceed the configured per-connection and per-policy operation rates in a log mode. The server adds information about the client connections that exceed those rates to the error log.</p>
</div>
<div class="paragraph">
<p>To learn more, refer to the configuration documentation included with the server for the following client connection policy properties:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><code class="codeph">connection-operation-rate-exceeded-behavior</code></p>
</li>
<li>
<p><code class="codeph">policy-operation-rate-exceeded-behavior</code></p>
</li>
</ul>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-subtree-deletions-in-the-changelog"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-subtree-deletions-in-the-changelog"></a>Fixed an issue with subtree deletions in the changelog</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50986</span>
<span class="ping_product">PingDirectory, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where subtree delete operations were recorded out of order in the changelog for servers in a replication topology.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-ldap-changelog-issue-with-subtree-deletions"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-ldap-changelog-issue-with-subtree-deletions"></a>Fixed an LDAP changelog issue with subtree deletions</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51456</span>
<span class="ping_product">PingDirectory, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the server didn’t correctly generate LDAP changelog records for subtree deletions. On the target server, records could be written out of order, preventing reliable replay on other destinations. Servers replicating the request might include only the base subtree deletion without records for subordinate entry deletions.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-encrypted-changelog-recovery"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-encrypted-changelog-recovery"></a>Fixed an issue with encrypted changelog recovery</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51147</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the server didn’t initialize the changelog backend’s encryption tokenizer when data encryption was enabled, preventing encrypted changelog recovery after unscheduled shutdowns.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-password-change-time-issue-during-reencoding"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-password-change-time-issue-during-reencoding"></a>Fixed a password change time issue during reencoding</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51349</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where reencoding an entry’s password also updated the value of its <code class="codeph">pwdChangedTime</code> attribute.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-manage-profile-replace-profile-error"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-manage-profile-replace-profile-error"></a>Fixed a <strong class="cmdname"><code>manage-profile replace-profile</code></strong> error</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51396</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the <strong class="cmdname"><code>manage-profile replace-profile</code></strong> tool could fail with a <code class="msgph">DirectoryNotEmptyException</code> error during upgrades in environments where the <code class="filepath">logs</code> directory was mounted as a separate volume. This failure was caused by the tool holding an internal lock on a background optimization file during the upgrade process. Now, the tool correctly releases these locks and skips the migration of non-essential cache files.</p>
</div>
<div class="paragraph">
<p>Additionally, we fixed a defect where the <strong class="cmdname"><code>setup</code></strong> tool didn’t always correctly apply the <code class="codeph">--optionCacheDirectory</code> argument.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-the-pluggable-pass-through-authentication-plugin"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-the-pluggable-pass-through-authentication-plugin"></a>Fixed an issue with the Pluggable Pass-Through Authentication plugin</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-51137</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue in the Pluggable Pass-Through Authentication plugin where successful sign-ons were recorded as authentication failures when <code class="codeph">try-local-bind</code> was enabled. Now, users won’t be incorrectly locked out due to valid pass-through authentications.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-psa-command-line-installation"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-psa-command-line-installation"></a>Fixed an issue with PSA command-line installation</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-13850</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the Password Sync Agent overrode or deleted values during command-line installation.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[PingDirectory suite of products 10.3.0.3 (March 2026)]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-3-march-2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-3-march-2026</guid>
            <pubDate>Tue, 26 May 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="sect2">
<h3 id="fixed-a-security-issue"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-security-issue"></a>Fixed a security issue</h3>
<div class="paragraph">
<p><span class="ping_changetype-security">Security</span>
<span class="ping_ticket">DS-51122</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed a security issue that could potentially affect customers using the PingDirectory, PingDirectoryProxy, or PingDataSync servers. We advise customers to apply this maintenance patch or upgrade to the latest version of the servers. Learn more in <a href="https://support.pingidentity.com/s/article/SECADV052-Denial-of-Service-via-copying-virtual-attributes" target="_blank" rel="noopener">SECADV052</a> (requires sign-on).</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[PingDirectory suite of products 10.3.0.2 (January 2026)]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-2-january-2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-2-january-2026</guid>
            <pubDate>Fri, 30 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="sect2">
<h3 id="improved-expired-certificate-handling-for-tls-negotiation"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#improved-expired-certificate-handling-for-tls-negotiation"></a>Improved expired certificate handling for TLS negotiation</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49269, DS-49270</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue that could cause the server to select an expired
certificate when performing TLS negotiation with an external server
that has a key manager provider and requests a client certificate chain.</p>
</div>
<div class="paragraph">
<p>The server now presents an expired certificate only if the key store
doesn’t include any certificate chains with currently valid certificates.</p>
</div>
<div class="paragraph">
<p>We also added the <code class="codeph">ssl-cert-nickname</code> property to the external server configuration, which allows you to control which client certificate
chain the server presents to that external server. If this property isn’t configured, the server attempts to select an
appropriate certificate chain automatically.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-infinite-retries-for-ldap-sync-endpoints"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-infinite-retries-for-ldap-sync-endpoints"></a>Fixed an issue with infinite retries for LDAP sync endpoints</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50255</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the server would infinitely retry operations that would never succeed. This issue specifically affected sync pipes syncing to or from LDAP endpoints and could have prevented the server from processing other operations.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-performlocalcleanup-in-interactive-mode"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-performlocalcleanup-in-interactive-mode"></a>Fixed an issue with <code class="codeph">--performLocalCleanup</code> in interactive mode</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-48553</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>Running <code class="cmdname"><strong>remove-defunct-server --performLocalCleanup</strong></code> in interactive mode no longer attempts to establish a connection to another live server in the topology.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-delegated-admin-landing-page-error"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-delegated-admin-landing-page-error"></a>Fixed a Delegated Admin landing page error</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50473</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue that caused the Delegated Admin landing page to throw an error after server startup.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[PingDirectory suite of products 10.3.0.1 (October 2025)]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#rn10301</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#rn10301</guid>
            <pubDate>Fri, 21 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="sect2">
<h3 id="fixed-a-critical-ldap-request-issue"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-critical-ldap-request-issue"></a>Fixed a critical LDAP request issue</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50632</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed a critical server issue where some LDAP requests failed with a <code class="msgph">ConcurrentModificationException</code> in the <code class="codeph">AuthenticationInfo</code> module.</p>
</div>
<div class="admonitionblock important">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-important" title="Important"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This issue was introduced in version 10.1.0.0. Update affected servers.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-delegated-admin-landing-page-error-2"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-delegated-admin-landing-page-error-2"></a>Fixed a Delegated Admin landing page error</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50473</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue that caused the Delegated Admin landing page to throw an error after server startup.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-the-changelog-password-encryption-plugin"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-the-changelog-password-encryption-plugin"></a>Fixed an issue with the Changelog Password Encryption plugin</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50457</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the Changelog Password Encryption plugin didn’t add encrypted attributes to the changelog for entries created with the Generate Password request control.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-fips-compliant-server-upgrades"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-fips-compliant-server-upgrades"></a>Fixed an issue with FIPS-compliant server upgrades</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50372</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue with server upgrades failing for FIPS-compliant servers running in a Linux environment with native FIPS mode enabled.</p>
</div>
<div class="paragraph">
<p>You can identify this upgrade failure by the following error message:</p>
</div>
<div class="paragraph">
<p><code class="msgph">Error initializing update: Error determining build information for the server at /opt/PingDirectory:  1.  Output from /opt/PingDirectory/bin/status -F was:  .</code></p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-upgrade-issue-for-servers-without-a-userroot-backend"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-upgrade-issue-for-servers-without-a-userroot-backend"></a>Fixed an upgrade issue for servers without a <code class="codeph">userRoot</code> backend</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50541</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue that caused upgrades for servers running version 10.0.0.x or later with no <code class="codeph">userRoot</code> backend to fail.</p>
</div>
<div class="paragraph">
<p>During an upgrade, the update tool tried to delete some configuration entries for inverted static group support that didn’t exist.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-ldif-imports"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-ldif-imports"></a>Fixed an issue with LDIF imports</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50286</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue with running an LDIF import as an administrative task. Previously, the import process didn’t verify that the source LDIF file existed before clearing the backend.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-plugin-issue-with-delete-operations"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-plugin-issue-with-delete-operations"></a>Fixed a plugin issue with delete operations</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50377</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the Referential Integrity plugin rejected delete operations when the DN of the delete operation was out of scope.</p>
</div>
</div>
<div class="sect2">
<h3 id="improved-dsreplication-initialize-speed"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#improved-dsreplication-initialize-speed"></a>Improved <code class="cmdname">dsreplication initialize</code> speed</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-48416</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>To increase <code class="cmdname"><strong>dsreplication initialize</strong></code> speed for high-latency connections, the operating system now sets the optimal receive buffer size automatically, allowing a larger TCP window for initialization.</p>
</div>
<div class="paragraph">
<p>To set the receive buffer manually, configure the following Java property to the desired size:</p>
</div>
<div class="listingblock">
<div class="content">
<pre>com.unboundid.directory.server.replication.protocol.SessionFactory.RECEIVE_BUFFER_SIZE</pre>
</div>
</div>
<div class="paragraph">
<p>Supply a value of <code class="codeph">1000000</code> to revert to the default buffer size before this change.</p>
</div>
</div>
<div class="sect2">
<h3 id="improved-concurrent-bind-request-performance"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#improved-concurrent-bind-request-performance"></a>Improved concurrent bind request performance</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-50622</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We improved concurrent bind request throughput for heavy authentication workloads passing through PingDirectoryProxy.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[PingDirectory suite of products 10.3.0.0 (July 2025)]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-0-july-2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#pingdirectory-suite-of-products-10-3-0-0-july-2025</guid>
            <pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="sect2">
<h3 id="critical-ldap-request-issue"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#critical-ldap-request-issue"></a>Critical LDAP request issue</h3>
<div class="paragraph">
<p><span class="ping_changetype-issue">Issue</span>
<span class="ping_ticket">DS-50632</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We identified a critical server issue where some LDAP requests fail with a <code class="msgph">ConcurrentModificationException</code> in the <code class="codeph">AuthenticationInfo</code> module.</p>
</div>
<div class="admonitionblock important">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-important" title="Important"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This issue was introduced in version 10.1.0.0. A fix is now available in the <a href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#rn10301">10.3.0.1 maintenance release</a>. Update affected servers.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect2">
<h3 id="removed-support-for-java-11"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#removed-support-for-java-11"></a>Removed support for Java 11</h3>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_ticket">DS-49541</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>Support for Java 11 has been removed. You must be running Java 17 or a later supported version, as detailed in the <a href="https://docs.pingidentity.com/pingdirectory/10.3/installing_the_pingdirectory_suite_of_products/pd_ds_system_requirements.html" class="xref page">System requirements</a>. Learn more about upgrading a PingDirectory server running Java 11 in <a href="https://docs.pingidentity.com/pingdirectory/10.3/installing_the_pingdirectory_suite_of_products/pd_proxy_sync_upgrade_considerations.html" class="xref page">Considerations when upgrading to version 10.3</a>.</p>
</div>
</div>
<div class="sect2">
<h3 id="support-for-internet-explorer-11-has-been-deprecated"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#support-for-internet-explorer-11-has-been-deprecated"></a>Support for Internet Explorer 11 has been deprecated</h3>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>Support for Internet Explorer 11 has been deprecated and will be removed in a future release.</p>
</div>
</div>
<div class="sect2">
<h3 id="support-for-the-sync-pipe-view-tool-has-been-deprecated"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#support-for-the-sync-pipe-view-tool-has-been-deprecated"></a>Support for the <code class="cmdname">sync-pipe-view</code> tool has been deprecated</h3>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>Support for the <code class="cmdname">sync-pipe-view</code> tool has been deprecated, and the tool will be removed in a future release.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-user-entry-forwarding-for-easier-request-authorization"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-user-entry-forwarding-for-easier-request-authorization"></a>Added user entry forwarding for easier request authorization</h3>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_ticket">DS-49681</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We added a mechanism to forward the authenticated user’s entry to backend servers in an entry-balanced proxy configuration. This change makes it easier to authorize requests in backend sets that don’t contain the user’s entry.</p>
</div>
<div class="paragraph">
<p>You can use this mechanism instead of the <code class="codeph">authz-dn</code> property in the entry-balancing request processor configuration or the <code class="codeph">ds-authz-map-to-dn</code> operational attribute in user entries, which are both used to map requests as the authenticated user to a different surrogate user in the other backend sets.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingdirectory/10.3/pingdirectoryproxy_server_administration_guide/pd_proxy_fwd_authz_entry_control.html" class="xref page">Forwarding authorization identities in requests</a>.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-rest-api-request-controls-for-soft-and-hard-deletes"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-rest-api-request-controls-for-soft-and-hard-deletes"></a>Added REST API request controls for soft and hard deletes</h3>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_ticket">DS-49530</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We added support for the following HTTP request controls in the Directory REST API:</p>
</div>
<div class="dlist">
<dl>
<dt class="hdlist1">Soft delete</dt>
<dd>
<p>Used to soft-delete entries</p>
</dd>
<dt class="hdlist1">Hard delete</dt>
<dd>
<p>Overrides automatic soft-delete policies and performs a full hard delete</p>
</dd>
<dt class="hdlist1">Soft-deleted entry access</dt>
<dd>
<p>Used to read or search soft-deleted entries</p>
</dd>
<dt class="hdlist1">Undelete</dt>
<dd>
<p>Restores soft-deleted entries to their normal state</p>
</dd>
</dl>
</div>
<div class="paragraph">
<p>Learn more in the <a href="https://developer.pingidentity.com/pingdirectory/directory/controls.html" target="_blank" rel="noopener">Directory REST API documentation</a>.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-support-for-the-haproxy-proxy-protocol"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-support-for-the-haproxy-proxy-protocol"></a>Added support for the HAProxy PROXY protocol</h3>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_ticket">DS-43335</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We added support for LDAP and LDAPS clients accessing the server through a software load balancer using the PROXY protocol, which allows the server to see the actual address and port of the end client system rather than just the address of the load balancer.</p>
</div>
<div class="paragraph">
<p>The server supports LDAP clients using TCP over IPv4 or IPv6 with header versions 1 and 2. It also accepts valid PROXY protocol headers with other protocols and address families, but it only updates the client address and port for TCP-based clients.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingdirectory/10.3/pingdirectory_server_administration_guide/pd_ds_proxy_protocol.html" class="xref page">Using the HAProxy PROXY protocol</a>.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-support-for-thales-luna-hsm-extensions"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-support-for-thales-luna-hsm-extensions"></a>Added support for Thales Luna HSM extensions</h3>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_ticket">DS-48531</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We added support for two Thales Luna HSM Server SDK extensions, which are available as separate downloads. To get the extensions, contact your Ping Identity account representative.</p>
</div>
</div>
<div class="sect2">
<h3 id="more-efficient-server-handling-of-failed-authentication-attempts"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#more-efficient-server-handling-of-failed-authentication-attempts"></a>More efficient server handling of failed authentication attempts</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49418</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We changed the default server behavior for failed authentication attempts to unavailable user accounts.
If a user’s account becomes unavailable (for example, because the account is locked, disabled, or the password has expired), the server won’t update the user’s recent login history for failed authentication attempts.</p>
</div>
<div class="paragraph">
<p>This change can prevent excessive write operations to a user entry in cases where the user can’t possibly authenticate, including when accounts could be subject to password guessing or denial-of-service attacks.</p>
</div>
</div>
<div class="sect2">
<h3 id="encoded-password-caching-improved-for-frequently-used-passwords"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#encoded-password-caching-improved-for-frequently-used-passwords"></a>Encoded password caching improved for frequently used passwords</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49516</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We improved the eviction logic for <a href="https://docs.pingidentity.com/pingdirectory/10.3/pingdirectory_security_guide/pd_sec_encoded_pw_caching.html" class="xref page">encoded password caches</a> to help ensure
that frequently used passwords remain cached. When a cache becomes full
and needs to add a record, the server evicts the least-recently-used record
to make room. Previously, the server evicted the oldest record from the cache.</p>
</div>
</div>
<div class="sect2">
<h3 id="smarter-dsreplication-initialize-failure-behavior"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#smarter-dsreplication-initialize-failure-behavior"></a>Smarter <code class="cmdname">dsreplication initialize</code> failure behavior</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-48158</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We improved the <code class="cmdname">dsreplication initialize</code> failure behavior for source backends supplied in a JSON topology file.
A backend must be enabled before it can be initialized. If <code class="cmdname">dsreplication initialize</code> doesn’t successfully initialize the target backend from one source, the command re-enables the target backend before attempting to initialize it from the next source in the JSON file.</p>
</div>
</div>
<div class="sect2">
<h3 id="exclude-virtual-attributes-to-streamline-reversible-delete-audit-logging"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#exclude-virtual-attributes-to-streamline-reversible-delete-audit-logging"></a>Exclude virtual attributes to streamline reversible delete audit logging</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49377</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We added a configuration property for the file-based audit log publisher that can exclude virtual attributes from delete audit log records that use the reversible form of logging.</p>
</div>
<div class="paragraph">
<p>Excluding virtual attributes reduces the size of these log messages and can eliminate the potential performance impact of computing their values. Virtual attributes are still included by default in delete audit log messages generated by the regular file-based audit logger, but they are now suppressed by default in the data recovery log.</p>
</div>
</div>
<div class="sect2">
<h3 id="made-it-easier-to-update-fips-compliance-levels"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#made-it-easier-to-update-fips-compliance-levels"></a>Made it easier to update FIPS compliance levels</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49550</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We updated <code class="cmdname">manage-profile replace-profile</code> to allow changing the value of the <code class="codeph">--fips-provider</code> argument in <code class="filepath">setup-arguments.txt</code> from <code class="codeph">BCFIPS</code> to <code class="codeph">BCFIPS2</code>. This makes it possible to update an existing instance running in FIPS 140-2 compliance mode to use FIPS 140-3 compliance mode.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-fips-compliance-information-to-monitor-entries"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-fips-compliance-information-to-monitor-entries"></a>Added FIPS-compliance information to monitor entries</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49731</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We updated the Version and SSL Context monitor entries to always include the <code class="codeph">fips-compliant-mode</code>,
<code class="codeph">fips-140-2-compliant-mode</code>, and <code class="codeph">fips-140-3-compliant-mode</code> attributes, even when the server is running in non-FIPS-compliant mode. We also exposed those attributes in the <strong class="uicontrol">Version</strong> monitor entry in the admin console’s <strong class="uicontrol">Status</strong> section.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-on-demand-ldap-connection-pool-creation"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-on-demand-ldap-connection-pool-creation"></a>Added on-demand LDAP connection pool creation</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49944</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We added an option to allow LDAP external servers to create connection pools without any initial connections so that all connections for use in the pool are created on demand. This can help make it faster to initialize components that use one or more LDAP external servers, but initial attempts to communicate with those servers could take longer as a result of needing to establish new connections.</p>
</div>
</div>
<div class="sect2">
<h3 id="clearer-attribute-parsing-for-the-processing-time-histogram-plugin"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#clearer-attribute-parsing-for-the-processing-time-histogram-plugin"></a>Clearer attribute parsing for the Processing Time Histogram plugin</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-49558</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We added the <code class="codeph">include-parseable-attribute-names</code> option to the Processing Time Histogram plugin to output
entries in a format that’s easier to parse. These reformatted entries are duplicates and still exist in their original
format. Changing this option requires a server restart to take effect.</p>
</div>
</div>
<div class="sect2">
<h3 id="improved-server-setup-when-using-a-profile"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#improved-server-setup-when-using-a-profile"></a>Improved server setup when using a profile</h3>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_ticket">DS-50069</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We added the <code class="codeph">--skipImportLdif</code> argument to <code class="cmdname">manage-profile setup</code>. You can supply this argument
to set up a server without importing any LDIF files contained in the profile directory structure.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-server-installation-issue-with-java-17-and-red-hat"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-server-installation-issue-with-java-17-and-red-hat"></a>Fixed a server installation issue with Java 17 and Red Hat</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49716</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue that could prevent installing or running servers using Java 17
or later on Red Hat Enterprise Linux (RHEL) systems when the operating system
itself is configured to run in FIPS-compliant mode.</p>
</div>
<div class="paragraph">
<p>This operating system setting is unrelated to whether the PingDirectory server has been set
up to run in FIPS-compliant mode.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-replication-behavior-for-listen-on-all-addresses"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-replication-behavior-for-listen-on-all-addresses"></a>Fixed replication behavior for <code class="codeph">listen-on-all-addresses</code></h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49547</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed the replication server configuration property <code class="codeph">listen-on-all-addresses</code> so that when the property is set to <code class="codeph">false</code>, replication servers only listen to the replication port on the interface that corresponds to the hostname of the server instance for that replication server.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-replication-assurance-for-some-password-updates"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-replication-assurance-for-some-password-updates"></a>Fixed an issue with replication assurance for some password updates</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49851</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where replication assurance wasn’t applied to the internal operation performed by the password modify extended operation.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-dsreplication-enable"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-dsreplication-enable"></a>Fixed an issue with <code class="cmdname">dsreplication enable</code></h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-35915</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed a bug where <code class="cmdname">dsreplication enable</code> ignored the <code class="codeph">--noPropertiesFile</code> option and incorrectly applied options from the <code class="filepath">tools.property</code> file.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-the-failure-behavior-for-dsreplication-initialize"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-the-failure-behavior-for-dsreplication-initialize"></a>Fixed the failure behavior for <code class="cmdname">dsreplication initialize</code></h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49890</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where a PingDirectory server would continue sending binary data
to the destination server after a failed attempt to initialize using <code class="cmdname">dsreplication initialize</code>.
This behavior interfered with further initialization attempts from any other server.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-replace-certificate-trust-store-issue"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-replace-certificate-trust-store-issue"></a>Fixed a <code class="cmdname">replace-certificate</code> trust store issue</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-44645</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue that prevented the <code class="cmdname">replace-certificate</code> tool from using the JVM-default trust store when replacing the listener certificate in interactive mode.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-replace-certificate-argument-issue"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-replace-certificate-argument-issue"></a>Fixed a <code class="cmdname">replace-certificate</code> argument issue</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49769</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where <code class="cmdname">replace-certificate replace-listener-certificate</code> didn’t obey the
<code class="codeph">--trust-store-update-type</code> argument.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-some-password-resets"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-some-password-resets"></a>Fixed an issue with some password resets</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50108</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where password resets done with the <code class="codeph">bypass-pw-policy</code> privilege would circumvent the
<code class="codeph">force-change-on-reset</code> property of password policies.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-the-modifiable-password-policy-state-plugin"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-the-modifiable-password-policy-state-plugin"></a>Fixed an issue with the Modifiable Password Policy State plugin</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49878</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the Modifiable Password Policy State plugin didn’t obey the value of the <code class="codeph">filter</code> property.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-the-entry-counter-plugin"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-the-entry-counter-plugin"></a>Fixed an issue with the Entry Counter plugin</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49872</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the Entry Counter plugin couldn’t evaluate criteria filters against virtual attributes with
<code class="codeph">require-explicit-request-by-name</code> set to <code class="codeph">true</code>.</p>
</div>
</div>
<div class="sect2">
<h3 id="restored-the-ability-to-modify-an-enabled-entry-counter-plugin"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#restored-the-ability-to-modify-an-enabled-entry-counter-plugin"></a>Restored the ability to modify an enabled Entry Counter plugin</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49816</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue with the Entry Counter plugin where an enabled plugin couldn’t be modified.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-the-monitor-history-plugin-preserving-files"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-the-monitor-history-plugin-preserving-files"></a>Fixed an issue with the Monitor History plugin preserving files</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-46253</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the Monitor History plugin wouldn’t preserve files for longer than 14 days when
<code class="codeph">retain-files-sparsely-by-age</code> was set to <code class="codeph">true</code>.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-scim-issue-with-modifying-ds-pwp-modifiable-state-json"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-scim-issue-with-modifying-ds-pwp-modifiable-state-json"></a>Fixed a SCIM issue with modifying <code class="codeph">ds-pwp-modifiable-state-json</code></h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49781</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where SCIM requests that attempted to modify the <code class="codeph">ds-pwp-modifiable-state-json</code> attribute would fail.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-scim-response-errors"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-scim-response-errors"></a>Fixed SCIM response errors</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-48511</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue with inconsistencies in <code class="codeph">id-attribute</code> values returned in SCIM operation responses.
We also fixed an issue with SCIM GET operations where a filter used to search for an entry would result in a 404 error.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-scim-2-0-put-issue-with-attribute-values"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-scim-2-0-put-issue-with-attribute-values"></a>Fixed a SCIM 2.0 PUT issue with attribute values</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49619</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where SCIM 2.0 PUT operations involving multivalued complex attributes would incorrectly remove some of the values.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-rest-api-issue-with-failed-put-requests"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-rest-api-issue-with-failed-put-requests"></a>Fixed a REST API issue with failed PUT requests</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49912</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue in the REST API where PUT requests would return a 500 response when attempting to replace the value of a virtual attribute.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-allowed-rest-api-syntax-violations"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-allowed-rest-api-syntax-violations"></a>Fixed an issue with allowed REST API syntax violations</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-46314</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where REST API calls failed due to attribute syntax violations, even though the server had been configured to allow syntax violations for those attributes.</p>
</div>
</div>
<div class="sect2">
<h3 id="added-a-missing-debug-type-to-ldap-sdk-logging"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#added-a-missing-debug-type-to-ldap-sdk-logging"></a>Added a missing debug type to LDAP SDK logging</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-43814</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy</span></p>
</div>
<div class="paragraph">
<p>We added the missing <code class="codeph">connection-pool</code> debug type to the server’s support for LDAP SDK debug logging.</p>
</div>
</div>
<div class="sect2">
<h3 id="suppressed-inaccurate-server-startup-warnings"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#suppressed-inaccurate-server-startup-warnings"></a>Suppressed inaccurate server startup warnings</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49991</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We suppressed inaccurate server startup warning messages about some Apache <code class="codeph">commons-logging</code> classes being scanned
from multiple locations. The scan detected older versions of those classes packaged inside a Spring JCL <code class="filepath">.jar</code> file
needed by the admin console, but the older versions aren’t loaded at runtime.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-internal-error-logged-at-server-restart"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-internal-error-logged-at-server-restart"></a>Fixed an internal error logged at server restart</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49551</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed a null pointer exception error logged when restarting a PingDirectory server configured with Delegated Admin.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-delegated-admin-memory-leak"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-delegated-admin-memory-leak"></a>Fixed a Delegated Admin memory leak</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49409</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where Delegated Admin could leak memory due to unfinalized memory consumers.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-a-topology-issue-related-to-removing-defunct-servers"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-a-topology-issue-related-to-removing-defunct-servers"></a>Fixed a topology issue related to removing defunct servers</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49700</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where the <code class="cmdname">remove-defunct-server</code> tool could leave a PingDataSync topology in a state where new servers couldn’t be added.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-password-sync-from-active-directory"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-password-sync-from-active-directory"></a>Fixed an issue with password sync from Active Directory</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-50043</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where password synchronization from multiple Active Directory subdomains through multiple sync pipes could fail abruptly.</p>
</div>
</div>
<div class="sect2">
<h3 id="excluded-some-password-attributes-from-sync-sources"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#excluded-some-password-attributes-from-sync-sources"></a>Excluded some password attributes from sync sources</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49212</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We changed the <code class="cmdname">resync</code> tool to exclude <code class="codeph">unicodePwd</code> automatically from
AD sync sources and <code class="codeph">password</code> from PingOne sync sources.</p>
</div>
<div class="paragraph">
<p>By design, the <code class="cmdname">resync</code> tool updates the existing values for included
attributes at the destination to match what’s found at the source.
If <code class="cmdname">resync</code> can’t retrieve an attribute value at the source, it removes
any existing values at the destination. Because <code class="cmdname">resync</code> can’t retrieve
these password attributes from their sources, we’ve excluded them from
the attributes for <code class="cmdname">resync</code> consideration to avoid disrupting the values
at the destination.</p>
</div>
<div class="paragraph">
<p>You can still include these attributes manually in a <code class="cmdname">resync</code> operation by
providing the <code class="codeph">--includeSourceAttr</code> argument.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-logging-changes-to-some-attributes"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-logging-changes-to-some-attributes"></a>Fixed an issue with logging changes to some attributes</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49917</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where PingDataSync would log an operation as not applied if the only changes applied
were to password policy state attributes.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-third-party-change-detectors"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-third-party-change-detectors"></a>Fixed an issue with third-party change detectors</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49035</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue where third-party change detectors didn’t properly persist the state of processing at the sync source.
This could’ve caused change detector malfunctions with the <code class="codeph">set-startpoint</code> task,
with saving the change detector’s state upon server shutdown, or with communicating that state to failover instances.</p>
</div>
</div>
<div class="sect2">
<h3 id="fixed-an-issue-with-the-sdk-ldap-sync-destination-plugins"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#fixed-an-issue-with-the-sdk-ldap-sync-destination-plugins"></a>Fixed an issue with the SDK LDAP sync destination plugins</h3>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">DS-49854</span>
<span class="ping_product">PingDataSync</span></p>
</div>
<div class="paragraph">
<p>We fixed an issue in the server SDK’s example LDAP sync destination plugins,
where the plugins dropped modify DN operations that didn’t affect the RDN.</p>
</div>
</div>
<div class="sect2">
<h3 id="communication-error-during-replication-prevents-initialization"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#communication-error-during-replication-prevents-initialization"></a>Communication error during replication prevents initialization</h3>
<div class="paragraph">
<p><span class="ping_changetype-issue">Issue</span>
<span class="ping_ticket">DS-50171</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>If <code class="cmdname">dsreplication initialize</code> fails because of a communication error between the source PingDirectory server and the
remote destination server, the source server continues attempts to send binary data.
This causes new initialization attempts on the destination server from any other server to fail until the
source server has finished sending all data.</p>
</div>
<div class="paragraph">
<p>To work around this issue, restart the source PingDirectory server.</p>
</div>
</div>
<div class="sect2">
<h3 id="running-an-ldif-import-as-an-administrative-task"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#running-an-ldif-import-as-an-administrative-task"></a>Running an LDIF import as an administrative task</h3>
<div class="paragraph">
<p><span class="ping_changetype-issue">Issue</span>
<span class="ping_ticket">DS-50286</span>
<span class="ping_product">PingDirectory</span></p>
</div>
<div class="paragraph">
<p>When you run an LDIF import as an administrative task, the import process doesn’t verify that the source LDIF file exists before clearing the backend.</p>
</div>
<div class="paragraph">
<p>Before running an LDIF import as an administrative task, do the following:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Ensure that the LDIF file exists.</p>
</li>
<li>
<p>Check for typos in the file path or file name.</p>
</li>
<li>
<p>Consider backing up the backend data.</p>
</li>
</ul>
</div>
</div>
<div class="sect2">
<h3 id="upgrading-to-version-10-3-with-fips-compliance-could-fail"><a class="anchor" href="https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#upgrading-to-version-10-3-with-fips-compliance-could-fail"></a>Upgrading to version 10.3 with FIPS compliance could fail</h3>
<div class="paragraph">
<p><span class="ping_changetype-issue">Issue</span>
<span class="ping_ticket">TRIAGE-28464</span>
<span class="ping_product">PingDirectory, PingDirectoryProxy, PingDataSync</span></p>
</div>
<div class="paragraph">
<p>For FIPS-compliant servers running in a Linux environment with native FIPS mode enabled, the server upgrade could fail when targeting version 10.3.
The error message for this type of upgrade failure looks similar to the following:</p>
</div>
<div class="paragraph">
<p><code class="msgph">Error initializing update: Error determining build information for the server at /opt/PingDirectory:  1.  Output from /opt/PingDirectory/bin/status -F was:  .</code></p>
</div>
<div class="paragraph">
<p>To work around this issue, do the following before attempting to upgrade the server:</p>
</div>
<div class="olist arabic">
<ol class="arabic">
<li>
<p>In the server’s <code class="filepath">java.properties</code> file, add <code class="codeph">--add-opens java.base/sun.security.provider=ALL-UNNAMED</code> to the <code class="codeph">common.java-args</code>.</p>
</li>
<li>
<p>Run <code class="cmdname">bin/dsjavaproperties</code>.</p>
</li>
<li>
<p>Restart the server.</p>
</li>
</ol>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[Previous Releases]]></title>
            <link>https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#prevrel</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingdirectory/10.3/release_notes/pd_release_notes.html#prevrel</guid>
            <pubDate>Tue, 15 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sectionbody">
<div class="paragraph">
<p>Learn more about enhancements and issues resolved in previous major and minor releases of PingDirectory products using the following links:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><a href="https://docs.pingidentity.com/pingdirectory/10.2/release_notes/pd_release_notes.html" target="_blank" rel="noopener">10.2</a></p>
</li>
<li>
<p><a href="https://cdn-docs.pingidentity.com/archive/pdf/pingdirectory/10.1/pingdirectory-10.1.pdf" target="_blank" rel="noopener">10.1</a></p>
</li>
<li>
<p><a href="https://cdn-docs.pingidentity.com/archive/pdf/pingdirectory/10.0/pingdirectory-10.0.pdf" target="_blank" rel="noopener">10.0</a></p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
    </channel>
</rss>