Fixes for SG3.2.3.3 Build 21579

Report created September 10, 2004
IssueService RequestDescription
423151-6150626Transparent FTP users whose credentials were already cached would be prompted for proxy authentication.
42555NONEThe sc-bytes access log field could contain an abnornally large byte count when an exception page was sent.
426091-5020299, 1-6644514An issue with host affinity existed where the DNS server did not maintain the order of the IP addresses.
42610NONEThe HTTP proxy now ignores the Content-Length header with CONNECT request, and forwards all bytes followed by the request header to upstream (the proxy or origin server). Previously, it issued a "400 Bad Request" error when it received a CONNECT request with non-zero content length.
42619NONEConfiguration files uploaded through HTTPS failed when an upstream proxy was used.
42622NONEFor units upgraded from SGOS 2.x: If the administrative authentication policy used an NTLM realm and an administrator was successfully logged in from an IP address, subsequent administrative challenges to that IP address accepted and event logged the invalid credentials until the IP surrogate credential for the initial administrator expired.
42628NONEWhen the authentication mode was "auto": After a valid user was in the credential cache, transparent FTP proxy users from the same IP were allowed access until the IP surrogate expired, even when entering invalid proxy credentials.
42631NONEThe optional realm display string in authenticate() is deprecated in SGOS 3.2 and will not be supported in SGOS 4.x
42677NONEThe number of maxium workers for a 645/6 with 3 disks has been set to be the equivalent of a 625/6.
42763NONEProvide ability for setting or deleting the Host: header from CPL.
42774NONELDAP "referral following" supported only one level of referrals.
428451-6564553, 1-6673445, 1-6699938Feature: Support IP spoofing on FTP data connections.
42881NONEPatience pages did not operate correctly if both response modification and request modification were used. The ProxySG continuously restarted the download from origin server and did not deliver the requested page.
42883NONEVirus scanning of FTP PUT is now supported
42887NONERead-only administrators got Java null pointer exceptions when using the Management Console's Configuration>Access Logging>Logs applet.
42894NONEMSN-IM: File transfer occasionally did not complete correctly when using an HTTP Proxy.
42920NONENetegrity Siteminder agent creation: Event log messages referred to Server 0 instead of "primary agent" and Server 1 instead of "alternate agent".
42922NONECPL substitutions: next_date() and $(http_date) gave parse errors when the argument contained a colon (':'). This affected only those customers who used this function to implement splash or coaching page policy to establish absolute expiry times that include a specific hour.
429351-7288380The ProxySG did not support the HelixDNAClient on Linux platforms.
429511-6419806, 1-6442088VPM generated incorrect policy for Combined Destination Object.
42958NONEBridging: You could change the IP address of an interface after it was attached to a bridge.
42964NONEYahoo-IM: Access log output '%20' instead of spaces in the x-im-chat-room-id field.
429891-6293491, 1-6614690, 1-6633371, 1-6645024URL Path and query strings: If there is a "#" character in the path of a URL received by the ProxySG, the ProxySG doesn't parse the url any further. Instead, the URL is truncated at the "#" before passing it upstream. Otherwise, if the path does not contain "#" but the query string does, the "#" is treated as an ordinary character, and the full URL is passed upstream.
42992NONEUrl rewrites were not being performed on embedded ARCHIVE tags.
429951-6119174, 1-6191551, 1-6295484Support HTTP request headers exceeding 8K in size.
43182NONEPAC Files: Even when the Management Console port 8081 is not enabled, you can enable the HTTP proxy on port 80 to allow the browser to get PAC file using <http://<ip>/<pac_file_path>>. You can also download the PAC file over HTTPS.
43207NONEPrivate keys had the possibility of being insecure when imported through the Management Console..
43302NONESupport Cerberian content filtering list.
43371NONEAdd accesslog field (rs-time-taken) to measure time between request and response (in ms).
435151-6439395, 1-6575316Pagefault in process "Agent-Admin-" in "" at .text+0x0 when using bcaaa (NTLM) agent.
436141-6517658, 1-6608411, 1-6609411, 1-6610457, 1-6610481, 1-6610822, 1-6611528, 1-6614490, 1-6629601, 1-6632461, 1-6632548, 1-6633627Websense incremental downloads could cause high CPU utilization.
436721-6632566You can now spoof proxy-authentication.
436951-6547721Patience Page: If you used the "Always_verify" policy in addition to a patience-page enabled resp-mod service, a download loop occured if the content on the origin server has changed or if the origin server returned HTTP 200 OK.
437161-7013739, 1-7029884, 1-7215771Director: Doing profile execution on the ProxySG from a Director connected via SSH (SSH RSA) could cause the SSH on ProxySG to hang.
437441-6575193, 1-6629547Websense: After initial category load failure, you could not load Websense Off-box categories.
437551-6575193Websense: The ProxySG would not connect to Websense off-box if the initial connection upon system boot/policy installation failed open irrespective of fail close policy.
43870NONEDirector: A race condition ocasionally prevented backups from being restored onto the ProxySG from Director.
438931-6747067Websense Reporter: It was possible for Websense Reporter to show malformed log entries as the ProxySG was sending Application Type and Keywords. Reporter no longer requires Application Type and Keywords.
438951-6227107Add support for serving PAC files over HTTPS.
439051-6638451Under some circumstances, the VPM would lose policy layers during installation.
439091-6713192Known Issue: iChat users are unable to transfer files.
439101-6709821IM: page fault: at 0x0 in MSN IM Worker in in "im.dll" at .text+0x2A00A.
439121-6699601The ProxySG was incorrectly removing the host affinity cookie when passing the request to an upstream proxy.
439541-6686441Known Issue Cannot serve the /proxy_pac_file over a VIP.
439611-6693521, 1-7052431, 1-7177674Snapshots appeared to be disabled in the Management Console when they were actually enabled.
439811-6086239WebFTP: For webFTP requests that incorporate user credentials in the URL, no patience page splashes occurre between the initial and final patience page splash, resulting in a download/patience-page loop.
440071-6759704Logging: "Logging disabled per overflow policy" was logged erroneously when log overflow policy was set to delete.
44009NONEVPM policy: It was possible for an installation attempt of policy from the VPM to experience significant slowness.
440361-6568753, 1-6647279, 1-6869932, 1-7058869, 1-7120180, 1-7188074If an HTTP request URL containedan IP address and there was a policy rule on an URL domain/host, the ProxySG did an unnecessary forward DNS lookup.
440481-6620469Users could not authenticate to the HTTPSvirtual authentication host when HTTPS termination was not licensed.
440971-6545851, 1-6743481SNMP trap for CPU utilization will be sent only if the CPU continues to stay up for 32 or more seconds. This is different behavior and needs to be documented
441111-6782630Host affinity did not work when multiple forwarding groups were defined.
441131-6688689, 1-6783155, 1-6933522, 1-6973210, 1-6988034Websense regex handling: Discrepancies for regex handling for Websense content filtering have been resolved. Note that a new database needs to be downloaded (incremental or full) to completely resolve the problem. If your database is current, you can either wait for the next update from Websense, or force a complete full download.
441171-6804411HTTP hex encoded characters were being sent to upstream FTP servers.
44155NONEResolve a potential restart in ICAP (SWE=0x30 in "Kernel.dll" at .text+0x8693) when scanning infinite objects.
441581-6885420Extended cookie host affinity functionality for SSL connections.
441991-6986673Host affinity state is not set or reset promptly when host affinity was first assigned before the connection was made, or after a successful connection when the affinity needed to be changed.
442051-6863641The ProxySG could not handle DNS requests that contained multiple records. This caused EDNS queries to be mishandled.
442151-6879773Local user database: Page fault at 0x0 in CAG_Worker 0" in "authenticator.dll" at .text+0x1ABF0 when installing a local user database.
442351-6885595The ProxySG was logging empty HTTP requests.
442511-6810390, 1-7085519Websense Off-box: Provide protocol schemes for URLs that arrive schemeless.
443411-6763029The ProxySG returned an HTTP 401 for upstream connection failures when attempting to play HTTP Windows Media streams.
443491-7022007It wasn't possible to import chained certificates through the ProxySG's Management Console.
443511-6685822The ProxySG displayed the bridge config twice if a pass through card was installed.
443801-6972423Blue Coat had a URL categorization mis-match with Websense's testdatabase urls.
443831-6772491Comment characters such as "!" and ";" were not allowed in configurations when using the CLI.
444331-7061836Yahoo IM: There were compatibility issues when using a HTTP Proxy with Version 6.x of the Yahoo IM Client.
444911-7077321Content Filter Database downloads could not be retried after the previous download had timed out.
445861-7088735, 1-7444404, 1-7501113VPM cannot install policy if SG was restarted during prior policy load.
446141-7108826, 1-7322126Transparent cookie authentication did not work for IP hostnames.
446401-7165691, 1-7403867The "disabled" attribute of a policy rule did not propagate with the rule as additional rules were added
447501-7085416The doc errata in the previous release notes incorrectly stated the policy evaluation order.
447981-7297783The ProxySG was incorrectly adding the "Front-end-https: on" for non-HTTPS requests.
448051-7321967, 1-7347969The "policy poll-interval" CLI command did not work properly.
448211-7200836Resolve a page fault in "SMTP_Admin" in "smtp.dll" at .text+0xDE4.
448291-7149651Users were unable to play some MMS streams over HTTP because older versions of the media server performed case sensitive header evalutaions.
448901-7356077, 1-7465658Some Windows 2000 users are unable to authenticate when using telnet proxy.
450041-7052603, 1-7494573, 1-7628159HTTPS Post request that contained more than 128KB of entity data caused the ProxySG to return an "HTTP 500 Internal Error."
450181-7620945SG-ME would sometimes lose RDNS policies when they were pulled from the ProxySG.
438761-11209136Prevent HDW=0x2 SFW=0x19 PF=0x0 "Cache Administrator" in "Kernel.dll" at .text+0xFDC3