PingID integration for Mac login 1.2 (February 14, 2023)
Use of OAEP padding for offline authentication
Info PingID
OAEP padding is now used by default in the encryption for offline authentication. If you do not want to use OAEP padding for offline authentication, use the --rsa_padding
option when running the command-line installation. For details, see Mac login command line reference.
Installation verifies PingID properties file
Security PingID
Beginning with version 1.2 of the integration, you must use the restricted-permissions properties file that is generated when you click the Generate button in the Integrate with Windows and Mac login section. You can no longer use the properties file that is generated when you click the Generate button in the Integrate with PingFederate and other clients section. This resolves issues related to CVE-2022-23717.