================================================================================ = = = Replify Accelerator 8.4.0-32853 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 8.4.0-32853. The previous GA release of Replify Accelerator was version 8.3.0. ================================================================================ Release Highlights ================================================================================ - Moved to Erlang OTP 28. (TLS performance improvements) - Moved to Debian Trixie. - Connection handling performance improvements. - ARM64 support. ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.4.0: = 8.3.0 = 8.2.1 = 8.2.0 = 8.1.1 = 8.1.0 = 8.0.0 = 7.3.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that a warning relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. Note that this is the final Replify Accelerator release that will support Windows 10. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-7057] Version attribute has been removed from Docker container YML files. These are obsolete for recent Docker versions. [ACC-7224] Deprecated API functions in peered_accelerators handler have been removed. These are 'set_cache_size' 'purge_client_cache' and 'get_cache_size. [ACC-7159] Certificate handler API functionality that allows the path of a TLS certificate to be used is no longer available. [ACC-7195] Replify server and GUI certificates are now renewed every 24 hours by default. Command line function `replify-ctl generate-new-gui-certificate` has been added. Non-Replify GUI certs will not be renewed automatically. [ACC-7196] Debian v10 (Buster) is no longer supported. This will affect any Accelerator installations that were created before August 2022 and have not received a Linux OS upgrade. [ACC-7205] macOS client is now built natively on Silicon and is no longer supported on Intel platforms. ================================================================================ New Features and Improvements ================================================================================ [ACC-7195, ACC-7217] TLS certificates used for securing connections between Accelerator nodes are re-generated daily. [ACC-7196] Virtual machines and Docker containers now use Debian Trixie. [ACC-7207, ACC-7218] REM and VA are now supported on ARM64. Debian packages and Docker containers are available for this architecture. [ACC-7140] Support for AES-256-CBC TLS certificates. [ACC-7221] Peered Accelerators API now supports multiple peers that have the same IP address. [ACC-7149, ACC-7185, ACC-7187, ACC-7188, ACC-7189] Performance improvements when creating new connections between Accelerator nodes. [ACC-7191] Windows client now uses .NET v4.8. [ACC-7193, ACC-7213] Logging improvements. [ACC-7194] ZStandard v1.5.7 is now used for compression. [ACC-7208] OpenSSL v3.5.0 is now used. [ACC-7210] MacOS alternative interception capability is available. Contact Replify Support for more information. [ACC-7220] Product is built on OTP 28. This contains several TLS performance improvements. ================================================================================ Fixes ================================================================================ [ACC-7182] Issue where VA didn't automatically pick up available licenses from the REM has been resolved. [ACC-7183] Fixed issue where the REM "Unlicense" button sometimes failed. [ACC-7198] Issue where errors could occur during shutdown have been resolved. [ACC-7200] Deadlock issue resolved on Linux/Mac client [ACC-7209] Redirect URLs sometimes had "//" instead of "/". [ACC-7211] Local Client IP reported on the VA UI is now always that of the NIC used to connect to the VA. [ACC-7212] Fix for incorrect application server address validation issue. [ACC-7215] Fix for incorrect service port validation issue. [ACC-7222] Issue where Peered_accelerators API call returned a 'badmatch' error has been resolved. [ACC-7223] UI issue with REM licensing dialog has been fixed. [ACC-7226] Issue where REM UI doesn't show alert when no licenses are available to give a connecting VA. ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client [ACC-7145] Docker users who currently use a REM will encounter an issue when upgrading their VA where their REM will recognise the VA as a new appliance after the upgrade is complete. Users should note that they should delete the "old" VA from the REM to prevent extra licenses being used. Users should also note that this will result in the loss of VA statistics from before the upgrade. [ACC-7167] Users who are using a Client -> Local VA -> Remote VA deployment will not be able to use the new "Automatic VA CA installation" feature. Users in this scenario will have to install VA certificates manually, or through group policy. [ACC-7112] On MacOS, CA's sent by the VA will not be trusted by Chrome unless the user explicitly changes the trust settings for the CA certificates to 'Don't trust' and then back to 'Always Trust' ================================================================================ = = = = Release Notes for Previous Releases = = = ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.3.0: = 8.2.1 = 8.2.0 = 8.1.1 = 8.1.0 = 8.0.0 = 7.3.0 = 7.2.0 = 7.1.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that a warning relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-4686] Adding a new v8.3 REM to an existing deployment with Virtual Appliances requires that the VAs are upgraded to v8.3 before connecting to the new REM. Note that an older REM can be upgraded to v8.3 and will work with Virtual Appliances that are using an older release. This is due to licensing changes for the 8.3 release. [ACC-7047] TLS v1.1 and TLS v1.0 are now disabled by default for application servers ================================================================================ New Features and Improvements ================================================================================ [ACC-4686, ACC-7114, ACC-7115, ACC-7174] Licensing improvements [ACC-6998] The impair-network tool is now supported in LXC and Docker containers [ACC-7014, ACC-7038, ACC-7059, ACC-7077, ACC-7083] Improved Accelerator logging [ACC-7023] Removed unnecessary information in VA configd log [ACC-7024] Tidied up some errors in the Linux systemd logs [ACC-7025, ACC-7148] Ability to modify GUI SSL cert via GUI and API [ACC-7031] Admin user on Replify supplied VMs has more OS privileges [ACC-7032] SSL performance improvements [ACC-7041] replify-ctl upgrade now accepts the release code as an argument [ACC-7052, ACC-7070, ACC-7071] Multiple application servers can now be added at once on the UI [ACC-7053] Multiple SNIs can now be added at once on the UI [ACC-7060] Replace spinning icon on reboot screen of VA/REM with new version [ACC-7061, ACC-7092, ACC-7094, ACC-7103, ACC-7105, ACC-7109] Upgraded to OTP 27.1 [ACC-7076] VAs now only use a license when they are connected to a REM [ACC-7098] Users can now permanently unlicensed a VA from the REM [ACC-7099] New REM mode which allows users to manually approve licenses being given to a connected REM [ACC-7104, ACC-7112, ACC-7116, ACC-7119, ACC-7147, ACC-7163, ACC-7165] Added ability to automatically install VA's CA certificate on client upon connection [ACC-7108] Diagnostic reports now contain extra information. [ACC-7131] GUI certificate is now included in backup when "Include SSL Certificates" option is used [ACC-7138] Multiple application servers can now have matching aliases [ACC-7162] Reboot no longer required after changing network configuration on VA and REM by using configure-network command ================================================================================ Fixes ================================================================================ [ACC-5782] Fixed issue with RAM Defragmentation [ACC-6940, ACC-7095] replify-ctl bug fixes [ACC-7002] Memory leak fixed [ACC-7048] Corrected GUI issue with the help functionality on the HTTP settings page [ACC-7050] Extended timeout on VA rebooting screen [ACC-7051] Fixed problem with Appliance exclusion rules [ACC-7056] Active FTP performance fix [ACC-7110] Fixed possible crash on client when upgrading from 7.0 [ACC-7124] Setting disable_replify_data_encryption via API now works [ACC-7133] Fixed issue with Bitcask merges [ACC-7141, ACC-7152, ACC-7153, ACC-7154] Fixed various issues with adding certificates [ACC-7142] Fixed issue where individual cache size could not be changed on VA UI [ACC-7144] Fixed error when shutting down Linux client [ACC-7156] Fixed error when generating diagnostic report from shell [ACC-7161] Fixed command issue with replify-ctl ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client [ACC-7145] Docker users who currently use a REM will encounter an issue when upgrading their VA where their REM will recognise the VA as a new appliance after the upgrade is complete. Users should note that they should delete the "old" VA from the REM to prevent extra licenses being used. Users should also note that this will result in the loss of VA statistics from before the upgrade. [ACC-7167] Users who are using a Client -> Local VA -> Remote VA deployment will not be able to use the new "Automatic VA CA installation" feature. Users in this scenario will have to install VA certificates manually, or through group policy. [ACC-7112] On MacOS, CA's sent by the VA will not be trusted by Chrome unless the user explicitly changes the trust settings for the CA certificates to 'Don't trust' and then back to 'Always Trust' ================================================================================ = = = = Release Notes for Previous Releases = = = ================================================================================ ================================================================================ = = = Replify Accelerator 8.2.1-32679 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 8.2.1-32679. This is a hotfix release, containing a hotfix for the Replify Accelerator Client on macOS Sequoia. The release also contains some other minor macOS fixes. The previous GA release of Replify Accelerator was version 8.2.0. ================================================================================ Release Highlights ================================================================================ - Hotfix: Fix Replify Accelerator Client Start Failure on macOS 15 ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.2.1: = 8.2.0 = 8.1.1 = 8.1.0 = 8.0.0 = 7.3.0 = 7.2.0 = 7.1.0 = 7.0.0 = 6.5.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that a warning relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-7081] SOCKS Bypass Proxy Mechanism Added It is possible to add exceptions for certain IPs, domains or subnets to a file /Library/Replify/proxy-bypass-domains.list. By default, this contains domains for applications that don't work well with SOCKS proxies. Microsoft Teams is One example, and is present by default. When interception is enabled for an interface, entries in this file will be added to the operating system's 'bypass proxy' list and will not be directed towards the Replify Accelerator Client for acceleration. ================================================================================ New Features and Improvements ================================================================================ None ================================================================================ Fixes ================================================================================ [ACC-7079] Fix Accelerator Client Start Failure on macOS 15 [ACC-7081] SOCKS proxy bypass mechanism added for macOS with Teams bypassed by default [ACC-7082] Ensure app server exclusions are honoured on macOS [ACC-7084] Process to add current username on macOS now exits gracefully ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client ================================================================================ = = = Replify Accelerator 8.2.0-32655 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 8.2.0-32655. This release contains features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 8.1.1. ================================================================================ Release Highlights ================================================================================ - Improvements to HTTP2 optimization, increasing offload and throughput - Internal Erlang runtime updated to OTP 26.2.4 - The REM now allows a specific address to be used for a VA when addresses are given to clients - Reduction of memory usage for accelerated TLS connections - Many other improvements and fixes ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.2.0: = 8.1.1 = 8.1.0 = 8.0.0 = 7.3.0 = 7.2.0 = 7.1.0 = 7.0.0 = 6.5.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that a warning relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ - The 'ip_address_exposed_to_clients' configuration value is has been renamed to 'address_exposed_to_clients' and now allows hostnames as well as IP addresses. ================================================================================ New Features and Improvements ================================================================================ [ACC-6860, ACC-6975, ACC-6976] Upgrade to OpenSSL 3.3 [ACC-6964] Upgrade version of ZStandard to 1.5.6 [ACC-6828, ACC-6829] HTTP2 security improvements. [ACC-6943, ACC-6944, ACC-6947ACC-6957, ACC-6962, ACC-6711] VA/REM UI improvements. [ACC-6981] Upgrade to OTP 26.2.4 [ACC-7006] Allow hostnames in ip_address_exposed_to_clients [ACC-7007] GUI option provided to configure VA hostname override. [ACC-6979] HTTP2 performance improvements. [ACC-6972] Allow multiple application servers to use the same WAN port. [ACC-6919] Client block store encryption can be enabled on the server [ACC-6744, ACC-6746, ACC-6995] WAN Connection Pool improvements. [ACC-7008] Management connection stability improvements. [ACC-6969] writer_service logging improvements [ACC-6970] Cache performance improvements [ACC-6772, ACC-6889] Resource checker improvements. [ACC-7026] Debian packages dependency updates. [ACC-7012, ACC-7016] replify-ctl status improvements. [ACC-7001] Reduced memory usage for accelerated TLS Connections. ================================================================================ Fixes ================================================================================ [ACC-6951, ACC-6901] Fixed HTTP2 Stream Timeout issue. [ACC-7004, ACC-7005] WAN Connection pooling bug fixes. [ACC-6987, ACC-6999, ACC-7021, ACC-7022, ACC-7027] Port Mapping Bug Fixes. [ACC-7017] Fixed GUI bug when adding a REM to a VA. [ACC-7011] Restoring a backup no longer causes service to stop. [ACC-6921, ACC-6990, ACC-6992] Mac networking bug fixes. ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client ================================================================================ = = = Replify Accelerator 8.1.1-32606 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 8.1.1-32606. This release contains features and improvements along with bug fixes. It also contains a hotfix for v8.1.0. The previous GA release of Replify Accelerator was version 8.1.0. ================================================================================ Release Highlights ================================================================================ - Improved HTTP/2 Optimization. - Application Server Port Mapping. - WAN Connection Pooling Hotfix for v8.1.0 when using TLS Application Servers ================================================================================ Hotfix details ================================================================================ [ACC-6994] WAN Connection Pooling TLS for Accelerated Application Servers ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.1.1: = 8.1.0 = 8.0.0 = 7.3.0 = 7.2.0 = 7.1.0 = 7.0.0 = 6.5.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that an error relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-6883] replify-ctl generate-new-ca-certificate also generates new server certificate. [ACC-6959] SSL errors are now output to data-connection-warnings.log. ================================================================================ New Features and Improvements ================================================================================ [ACC-6072, ACC-4707, ACC-6898] HTTP2 optimization improvement. [ACC-6862, ACC-6861, ACC-6658, ACC-6942] UI Improvements. [ACC-6887] Upgraded zlib-ng to 2.1.5. [ACC-6888] Upgraded hpack to 0.3. [ACC-6890] Option provided on login page for user to see password in plain text. [ACC-6905] Upgraded openssl to v3.0.13. [ACC-6912] Application Server Port Mapping. [ACC-6925] VA GUI can be configured to use a different SSL certificate to the one used for data connections going through the VA. ================================================================================ Fixes ================================================================================ [ACC-6872, ACC-6699, ACC-6899, ACC-6933] UI bugs fixed. [ACC-6881] Removal of network interface no longer causes crash. [ACC-6900] Certificate Caching no longer occurs under load. [ACC-6910] Block store encryption now works on client. [ACC-6945] REM Management interface setting is no longer ignored. ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client ================================================================================ = = = Replify Accelerator 8.1.0-32575 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 8.1.0-32575. This release contains features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 8.0.0. ================================================================================ Release Highlights ================================================================================ - Improved HTTP/2 Optimization. - Application Server Port Mapping. ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.1.0: = 8.0.0 = 7.3.0 = 7.2.0 = 7.1.0 = 7.0.0 = 6.5.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that an error relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-6883] replify-ctl generate-new-ca-certificate also generates new server certificate. [ACC-6959] SSL errors are now output to data-connection-warnings.log. ================================================================================ New Features and Improvements ================================================================================ [ACC-6072, ACC-4707, ACC-6898] HTTP2 optimization improvement. [ACC-6862, ACC-6861, ACC-6658, ACC-6942] UI Improvements. [ACC-6887] Upgraded zlib-ng to 2.1.5. [ACC-6888] Upgraded hpack to 0.3. [ACC-6890] Option provided on login page for user to see password in plain text. [ACC-6905] Upgraded openssl to v3.0.13. [ACC-6912] Application Server Port Mapping. [ACC-6925] VA GUI can be configured to use a different SSL certificate to the one used for data connections going through the VA. ================================================================================ Fixes ================================================================================ [ACC-6872, ACC-6699, ACC-6899, ACC-6933] UI bugs fixed. [ACC-6881] Removal of network interface no longer causes crash. [ACC-6900] Certificate Caching no longer occurs under load. [ACC-6910] Block store encryption now works on client. [ACC-6945] REM Management interface setting is no longer ignored. ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client ================================================================================ = = = Replify Accelerator 8.0.0-32491 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 8.0.0-32491. This release contains features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 7.3.0. ================================================================================ Release Highlights ================================================================================ GUI - Live updating via websockets added to many GUI pages on VA - MacOS Client UI improvements Protocol and Performance - Read-only caching when system is under load, resulting in higher performance - Read-only caching can now be set from the settings page to ensure the content of the cache doesn't change - Default client cache size is now configurable independently of VA cache size - HTTP/2 protocol handling improvements for a wider variety of implementations - TLS Certificate Caching to reduce bytes on the wire for TLS connections Security - Secure peering verify hostname functionality - Product upgraded to use OpenSSL 3 Other - API documentation now in HTML format and included with VA - Moved to latest version of Erlang (26.1.2) - Moved to Debian Bookworm - Hyper-V VMs now have multiple vCPUs by default - TCP keep-alives used to monitor management connection ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 8.0.0: = 7.3.0 = 7.2.0 = 7.1.0 = 7.0.0 = 6.5.0 = 6.4.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that an error relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ - New VAs will default to a 1 gigabyte cache size while clients remain at 256 megabytes - Muxing functionality removed - Removed ability to generate self-signed certificates from the GUI - It is no longer possible to use a proxy connection between a client and VA using a proxy server ================================================================================ New Features and Improvements ================================================================================ [ACC-5463] TLS Certificate Caching [ACC-5772, ACC-6701] Added hostname validation configuration option for secure peering [ACC-5915] Removed ability to manual create TLS certificates via the GUI [ACC-5931] Migrated API Documentation to HTML [ACC-6115] Management Connection Establishment Improvements [ACC-6413] Allow default client size to be changed from the GUI and API [ACC-6618] Management Link is monitored using TCP keep-alives [ACC-6636, ACC-6635, ACC-6668] Live updates added for RAM/CPU usage, Clients and Cache page [ACC-6656] Tail Logs feature on VA/REM UI now includes extra VA logs [ACC-6659] Provide visual feedback if VA failed to license to REM initially [ACC-6663] Move to new version of Debian (Bookworm) [ACC-6673] Hyper-V VM is be deployed with multiple vCPUs [ACC-6675] Direct-to-server fallback behaviour when VA is not available is now configurable [ACC-6677, ACC-6819] Move to Erlang OTP 26.1.2 [ACC-6688] Update dockerhub readme to use 'docker compose' [ACC-6689] ZStandard 1.5.5 is used for compression [ACC-6700] The VA/REM web UI now uses gzip compression [ACC-6710] VA GUI now displays build number of connected clients [ACC-6718, ACC-6727, ACC-6729] Upgraded to OpenSSL 3 [ACC-6731] Verify Receiver Cert by Default [ACC-6734] Remove muxing [ACC-6740] HTTP 500 errors are returned in a nicer manner to API calls [ACC-6742] Improvements to cache loading error reporting and resilience [ACC-6747] Create read-only cache [ACC-6753] Add secure peering to get_clients call [ACC-6758] Cache can now store blocks less than 4KB [ACC-6759] Ensure full logging capability is available from startup [ACC-6769] Review and Update Help Text on Cache Page [ACC-6776] Increase Default Cache Size for VAs [ACC-6786, ACC-6792, ACC-6804, ACC-6805, ACC-6806] Minor API Changes [ACC-6796] Add ability to enable read only cache to settings page [ACC-6799] Reduce logging for erroneous REM connections [ACC-6820] Move to OpenSSL 3.0.11 [ACC-6822, ACC-6823] Upgrade to rocksdb-1.8.0-1 [ACC-6854] Logging SNI as part of conn.log is now configurable [ACC-6857] Improvement to wording on HTTPS first time setup UI ================================================================================ Fixes ================================================================================ [ACC-3884] macOS: Escaped connections UI not refreshing [ACC-6344] Client is connected but VA reporting it as disconnected [ACC-6698] Corrected value of Cache Data Size in Per Cache UI when downloading the same file multiple times. [ACC-6657] Fix help text for replify-ctl get-dynamic-snis command [ACC-6660] Connected Caches Listed as Disconnected when they are connected [ACC-6670] Fix configure-network script errors when running as non-sudo user [ACC-6671] Keyring configuration value is not being read correctly. [ACC-6685, ACC-6686, ACC-6850, ACC-6852] Minor UI Fixes [ACC-6690] macOS: Connection spy doesn't show process info of accelerated connections [ACC-6715] macOS: Enabling interception requires two clicks to take effect [ACC-6719] Reduced size of installers [ACC-6760] Single cache stats for nodes with a '+' in their GUID are now displayed correctly [ACC-6763] Cache sizes now applied correctly if they change when a node is disconnected [ACC-6764] Cache Size Settings on GUI Use Incorrect Units [ACC-6780] macOS: DNS errors regularly occur on macos. [ACC-6856] Error message in REM systemd log on installation [ACC-6864] TLS middle-box mode can now be configured [ACC-6871] Crash when changing GUI interface on settings page [ACC-6875] Unnecessary warnings on REM [ACC-6877] Accessing the VA UI without a user agent causes a crash ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. SNI Filters should be used in these cases to apply only TCP optimizations. [ACC-5083] macOS: SMB Connections are not optimized by the Mac client ================================================================================ = = = Replify Accelerator 7.3.0-32314 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 7.3.0. This release contains features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 7.2.0. ================================================================================ Release Highlights ================================================================================ - HTTP Settings now apply to HTTP/2 traffic - New interception mechanism for Windows connecting to local peered VAs - Peers can now be added via hostname as well as IP address ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 7.3.0: = 7.2.0 = 7.1.0 = 7.0.0 = 6.5.0 = 6.4.0 = 6.3.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that an error relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-6608] If TLS connection to application server fails certificate validation, TLS optimization no longer occurs and the original TLS payload is sent to the client. Previous behaviour was to terminate the connection. [ACC-6626] If a peered appliance cannot establish a data connection to its peer, it will now attempt to establish a connection directly to the application server instead of terminating the connection ================================================================================ New Features and Improvements ================================================================================ [ACC-4459] New and more efficient interception/forwarding mechanism now used when connecting to a local appliance [ACC-5892] Android client service starts more quickly on phone restart [ACC-6193] New REM UI functionality to update statistics on request [ACC-6286] Minor performance improvement with caching [ACC-6450] Minor performance improvement when resizing caches [ACC-6478] Users now prompted to change default password on first time setup [ACC-6497] HTTP/2 and HTTP traffic settings now covered under HTTP settings page [ACC-6501] Offload Stats now shown on VA terminal after SSH login [ACC-6515] Performance improvement when using large caches [ACC-6541] Better use of disk space on systems with limited storage [ACC-6543] HTTP protocol handler improvements [ACC-6569] Release notes on client upgrade link now uses TLS [ACC-6575] Improvements to validation on peered appliances UI [ACC-6582] Improved UI validation on REM Filters UI [ACC-6589] More stats detail added to Deployment Summary on REM UI [ACC-6591, ACC-6649] Connection errors are now logged to separate log files [ACC-6597, ACC-6648, ACC-6565, ACC-6609] REM logging improvements [ACC-6598] New VA API call exposing client information for an appliance has been introduced [ACC-6599] REM appliances page updates information in real time [ACC-6615] WFP Driver information has been updated [ACC-6628] robots.txt has been added to web application to prevent indexing on internet facing VAs and REMs [ACC-6631] peered_accelerators API now has support for peer addresses being specified as hostnames [ACC-6633, ACC-6638] Improvements to Services GUI ================================================================================ Fixes ================================================================================ [ACC-5741] Android UI issue when an appliance/REM with a long hostname was used has been corrected [ACC-6135] Minor issues with Web UIs displaying incorrectly on large screens have been corrected [ACC-6453] Crash condition when VA is under high load has been resolved [ACC-6524] Condition where updated configuration was not sent to clients has been resolved [ACC-6531] Crash condition when system under load has been resolved [ACC-6535] Cache is no longer cleared unnecessarily when block store encryption key is not available [ACC-6556] Service account is deleted when Mac client is uninstalled [ACC-6561] Corrected issue where get_cache_stats API call sometimes didn't return results [ACC-6579] REM can be specified using a hostname on VA GUI [ACC-6580] Issue with upgrading a VA/REM via the UI has been resolved [ACC-6595] 'active_clients' field in API get_system_info call has been renamed to 'active_data_sessions' [ACC-6603] API now returns value of NULL when relevant instead of a string "undefined" [ACC-6612] numberOfActiveClients field in MIB now returns correct information [ACC-6629] GUI crash when deleting service has been resolved [ACC-6639, ACC-6647] Resolved high load crash due to race condition [ACC-6650] Issue with scan resistance and the HTTP protocol handler resolved [ACC-6653] Typo on Android client diagnostic report page corrected [ACC-6654] Error when saving SSL settings on a Muxed VA has been resolved ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. [ACC-5083] SMB Connections are not optimized by the Mac client [ACC-6352] It is no longer possible to use a proxy connection between a client and VA using a proxy server [ACC-6646] Sometimes there is a mismatch between the number of clients reported to be connected to an appliance and the clients that are actually connected ================================================================================ = = = Replify Accelerator 7.2.0-32213 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 7.2.0. This release contains several features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 7.1.0. ================================================================================ Release Highlights ================================================================================ - Improved Cache Throughput - HTTP/3 traffic acceleration ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 7.1.0: = 7.1.0 = 7.0.0 = 6.5.0 = 6.4.0 = 6.3.0 = 6.2.1 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. Note that an error relating to the /replify/packages directory may be observed when upgrading the REM. This can safely be ignored. ================================================================================ Android client ================================================================================ There are no changes to the Android version for v7.2, so this release includes the v7.1 Android client. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for releases prior to v7.1.0 assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-6480] Logging in via the root user is disabled over SSH. A new 'admin' user has been created for this purpose. ================================================================================ New Features and Improvements ================================================================================ [ACC-5852] HTTP/3 traffic can now be accelerated [ACC-5966] Product is built with Erlang/OTP v25.2.3 [ACC-6270, ACC-6509] Cache throughput improvements [ACC-6449, ACC-6530] Informational log messages regarding connection handling are logged to a new log file: mgmt-activity.log [ACC-6461] Virtual Appliance Debian packages are no longer downloaded to a REM during upgrade [ACC-6466, ACC-6492, ACC-6538, ACC-6551, ACC-6363, ACC-6462, ACC-6475] Logging improvements [ACC-6482] The VA and REM web UIs now use TLS 1.3 when accessed via HTTPS [ACC-6484] Lager 3.9.1 is now used for logging framework [ACC-6490] When accessing the REM/VA UI for the first time, the user is asked if they wish to use HTTPS for all future access attempts [ACC-6494] Peered VAs can now be added using a hostname as well as an IP address [ACC-6514] When accessing a VA/REM Virtual Machine for the first time, users will be prompted to change the hostname of the VM [ACC-6518] Yaws 2.1.1 is now used for web UIs [ACC-6525] Ranch 2.1.0 is now used for connection handling [ACC-6526] Some older deprecated libraries have been removed from installers [ACC-6527] Erlang/OTP is now built using Openssl 1.1.1t [ACC-6539] TLS requests with a trailing "." at the end of the SNI are now treated as if the "." was not present ================================================================================ Fixes ================================================================================ [ACC-6460] Broken link in Per Tag statistics page on REM has been corrected [ACC-6467] replify-ctl commands now give useful error if run when the service is unavailable [ACC-6470] Broken Syslog functionality is now working [ACC-6473] Syslog configuration can now be enabled/disabled via the API [ACC-6474, ACC-6479, ACC-6452, ACC-6485, ACC-6496] Corrected issues with nft interception rules [ACC-6481] When a server certificate expires and is renewed, any subject alternative name records present are copied across [ACC-6491] HTTP upgrade headers with h2c value are now processed correctly [ACC-6502] Warnings relating to the fd0 device not being present on virtual machines are no longer generated [ACC-6506] Changing cache directive via API no longer requires a restart to take effect [ACC-6510] CA certificates provided on Docker images are the same as on VMs [ACC-6511] Deadlock condition when adding peers with a specified cache size via the API has been corrected. [ACC-6516] ICMP pings from a client to an appliance can now be disabled [ACC-6533] When adding a certificate via the API with both a filename and ID specified no longer causes an error to occur [ACC-6534] Condition where cache size was sometimes incorrectly calculated has been resolved [ACC-6546] When static caching was enabled, a condition where data wasn't retrieved from the cache was corrected [ACC-6553] ICMP traffic no longer sent from clients to VA after the client disconnects from the VA [ACC-6577] Error where a failed data connection could sometimes crash the client when WAN Connection pooling was in use has been corrected ================================================================================ Errata or Known Issues ================================================================================ [ACC-3825] Un-rooted Android devices can only accelerate HTTP(S) traffic [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. [ACC-4719] STARTTLS and HTTP CONNECT content is not cached in client to local VA scenarios [ACC-5083] SMB Connections are not optimized by the Mac client [ACC-6145] Adding a new CA to a VA may require a service restart to occur before this is used when validating application server connections [ACC-6351] Windows client can only check for updates when "run as administrator" [ACC-6352] It is no longer possible to use a proxy connection between a client and VA using a proxy server [ACC-6497] HTTP Settings functionality only applies to HTTP/1 and HTTP1/1 traffic [ACC-6571] Service needs to be restarted when mac client is upgraded [ACC-6580] Upgrades via the VA/REM UI may not always work ================================================================================ = = = Replify Accelerator 7.1.0-32109 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 7.1.0. This release contains several features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 7.0.0. ================================================================================ Release Highlights ================================================================================ - Improved Cache Throughput - Many other fixes and improvements (see below for details) ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 7.1.0: = 7.0.0 = 6.5.0 = 6.4.0 = 6.3.0 = 6.2.1 = 6.2.0 = 6.1.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. If upgrading the REM or VA from a release that is older than v7.0, please run the following command: apt-get update --allow-releaseinfo-change The following command should be used to upgrade the VA/REM for all releases. replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. ================================================================================ Extra steps for QEMU/Proxmox users ================================================================================ The QCOW2 image supplied for previous releases assumed that the image was attached using a standard SCSI device. If it was attached using VirtIO SCSI, the upgrade may result in errors. To resolve these, run dpkg --configure grub-pc and choose the correct device. This will usually be '/dev/vda'. If unsure, please contact Replify Support. ================================================================================ Changes in Behaviour this Release ================================================================================ [ACC-6399] Due to changes on how cache information is stored on disk, the cache will be cleared after upgrading to v7.1. [ACC-6353] Bandwidth Savings tool has been removed from the Bandwidth savings page [ACC-6400] The Linux client is no longer supported on Ubuntu 18-04. ================================================================================ New Features and Improvements ================================================================================ [ACC-5950] Improved peering logic when peers have different block size configurations [ACC-6183, ACC-6209, ACC-6430, ACC-6456] Logging improvements [ACC-6313] Improved cache throughput on systems where cache is full [ACC-6366] Clearer descriptions added to REM Client Report UI [ACC-6399] Alternative index and block store modules are now available that use rocksdb for storage [ACC-6400] The VA, REM and Linux clients are now built against glibc-2.28 [ACC-6416] Ability to edit filters has been added to the REM UI [ACC-6422] QCOW2 images are configured with Virtio SCSI [ACC-6426] Batch deletion of tags functionality added to REM UI [ACC-6433] Cache efficiency improvements [ACC-6440] VA, REM and clients now use OpenSSL 1.1.1s [ACC-6442] VA and clients now use ZStandard 1.5.2 compression library ================================================================================ Fixes ================================================================================ [ACC-6078] The Linux client uses same interception hook mechanism as the VA [ACC-6256] Improved logic when available disk space on a VA is low [ACC-6364] REM client report UI no longer has an erroneous delete button in the active clients tab [ACC-6365] Condition where connecting a client to a REM sometimes sent out incorrect VA list has been resolved [ACC-6374] Stats collection module uses fewer CPU resources [ACC-6381 Deactivating an application server when a VA is under load no longer causes a crash [ACC-6395] Validation of peered IP address is improved on VAs with multiple interfaces [ACC-6402, ACC-6451] Logic for resizing caches when disk space is low has been improved [ACC-6404] Error handling when adding peer with invalid IP has been improved [ACC-6417] Error handling with adding a duplicate filter has been improved [ACC-6415, ACC-6437] Some race conditions removed from cache logic when under multiple connections are processing the same content under high load [ACC-6423] Capability filters are saved to a file with a user friendly filename [ACC-6432] Maximum number of open files is now configured correctly on Docker images [ACC-6350, ACC-6431, ACC-6368, ACC-6398] Efficiencies made in how cache index is stored on disk [ACC-6367] Added more detail to help text of replify-ctl command [ACC-6389] Accelerator Start menu entries in Windows have more user friendly names [ACC-6447] Parameter validation added to replify-ctl ================================================================================ Errata or Known Issues ================================================================================ [ACC-6470] Syslog functionality is broken [ACC-6352] It is no longer possible to use a proxy connection between a client and VA using a proxy server [ACC-6145] Adding a new CA to a VA may require a service restart to occur before this is used when validating application server connections [ACC-5083] SMB Connections are not optimized by the Mac client [ACC-4719] STARTTLS and HTTP CONNECT content is not cached in client to local VA scenarios [ACC-4648] Mac client service stops when it connects to a VA that is using a non-standard block size [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. [ACC-3825] Un-rooted Android devices can only accelerate HTTP(s) traffic ================================================================================ = = = Replify Accelerator 7.0.0-32043 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 7.0.0. This release contains several features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 6.5. ================================================================================ Release Highlights ================================================================================ - Faster cache engine, meaning higher throughput caching, better performance, and support for higher bandwidth links - Reduced RAM usage, both on VA and REM - Reduced bandwidth usage between VA and REM ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 7.0.0: = 6.5.0 = 6.4.0 = 6.3.0 = 6.2.1 = 6.2.0 = 6.1.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. To upgrade the REM or VA please run the following commands at the console: apt-get update --allow-releaseinfo-change replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. ================================================================================ Changes in Behaviour this Release ================================================================================ -------------------------------------------------------------------------------- [ACC-6188] Hostname exclusion functionality has been removed -------------------------------------------------------------------------------- Any customers using this should contact Replify Support for assistance on how to reconfigure their system to use SNI filters. -------------------------------------------------------------------------------- [ACC-6306] Windows 32 bit client has been deprecated -------------------------------------------------------------------------------- Any customers using this should contact Replify Support. -------------------------------------------------------------------------------- [ACC-6232] "flushed_bytes" renamed "send_raw_bytes" in API -------------------------------------------------------------------------------- API calls that return cache stats now refer to "send_raw_bytes" to refer to the amount of data that is processed by Replify Accelerator, but not cached. -------------------------------------------------------------------------------- [ACC-6227] Windows installer no longer asks for IP address of REM -------------------------------------------------------------------------------- This can be configured instead using an installer parameter, modified installer or group policy. -------------------------------------------------------------------------------- [ACC-6216] SSL certificate API change -------------------------------------------------------------------------------- SSL certificate information returned from the 'certificate' API handler no longer returns the 'dynamic' field. This was previously always set to 'false'. -------------------------------------------------------------------------------- [ACC-6190] Stats are sent from VA to REM less frequently -------------------------------------------------------------------------------- Statistics are now sent to the REM from VAs every five minutes instead of every minute. The previous behaviour can be restored if necessary. Please contact Replify Support. ================================================================================ New Features and Improvements ================================================================================ [ACC-6329, ACC-6323, ACC-6322, ACC-6276, ACC-6275, ACC-6264, ACC-6259, ACC-6250, ACC-6226, ACC-6210, ACC-6314. ACC-6341, ACC-6361] Diagnostic logging improvements [ACC-6320] Client is now supported on Ubuntu 22-04 [ACC-6303, ACC-6284, ACC-6279, ACC-6278, ACC-6268, ACC-6161, ACC-6262, ACC-6258, ACC-6257, ACC-6254, ACC-6244, ACC-6225, ACC-6219, ACC-6214, ACC-6375, ACC-6376] Cache throughput improvements [ACC-6298] Erlang VM allocated memory information is now available from API [ACC-6265] Use of a single cache block size is now supported [ACC-6253] Improved flow control for cache messages between VAs and between client and VA [ACC-6251] Process ulimits are no longer configured in limits.conf [ACC-6247, ACC-6197] Improved flow control for cache messages between VAs [ACC-6243, ACC-6231, ACC-6291] VA uses less RAM than before, especially for large caches [ACC-6240] VA_ADDRESS parameter for Windows installers now accepts hostnames in addition to IP addresses [ACC-6237, ACC-6228] New Static File Caching mode available to provide increased throughput for static HTTP content [ACC-6206] REM Virtual Images are now supplied with 2GB of RAM instead of 512MB [ACC-6200, ACC-6194, ACC-6190, ACC-6167] Reduced bandwidth usage when sending stats from a VA to a REM [ACC-6199, ACC-6186, ACC-6181] REM UI updates [ACC-6198] Reduced bandwidth used by management connection beween client and VA [ACC-6196] Reduced bandwidth used for management connection between VA and REM [ACC-6191] Using an updated version of ZStandard v1.5.1 compression library [ACC-6147] REM docker container no longer requires the NET_ADMIN capability [ACC-6107] All virtual images are now based on Debian Bullseye ================================================================================ Fixes ================================================================================ [ACC-6381] Race condition that could cause a crash when an application server was removed has been corrected. [ACC-6380] peeredApplianceConnectedEvent SNMP trap now correctly fires on both VAs in a peered VA configuration [ACC-6365] Client no longer deletes existing VAs assigned if a REM also assigns the same VAs to that client [ACC-6342] Crash when client uses a proxy server to connect to an appliance no longer occurs [ACC-6333, ACC-6287, ACC-6360] Reduction in number of cache misses that occur on a system under load [ACC-6330, ACC-6328, ACC-6304, ACC-6343, ACC-6346. ACC-6358, ACC-6377] Stability improvements when system is under load [ACC-6321, ACC-6312, ACC-6293, ACC-6229, ACC-6222, ACC-6203, ACC-6173, ACC-6153] VA GUI improvements [ACC-6319, ACC-6307] Improved offload during periods of high system load [ACC-6315, ACC-6310] Correction of minor stats discrepancy between client and VA [ACC-6311] Error that sometimes occurred when installing Ubuntu client has been fixed [ACC-6263] Handle cache version mismatches [ACC-6233] HTTP content of exactly 4096 bytes are now cached correctly [ACC-6220] SSL connections to VAs using an older version of Accelerator can fail when using certain older cipher suites [ACC-6218] Error when deleting a service using the API has been corrected [ACC-6217] SNI Filter API calls are now documented correctly [ACC-6204] Date based searches on the REM UI now search correctly from 00:00 and not from 23:00 [ACC-6187] 'replify-ctl set-group-log-level' command now works correctly [ACC-6177] Newly connected VAs sometimes showed as disconnected on the REM overview page. This no longer occurs. [ACC-6171, ACC-6166] REM now uses less memory on environment with a lot of historic statistics. [ACC-6158] Client can now be connected to multiple REMs that reference the same VA [ACC-6154] Restoring an invalid backup no longer deletes system configuration [ACC-6081] Scenario where stale user connections could result in a user's GUID and cache being regenerated has been resolved. [ACC-6032] Cache crash after attempting to clear cache following memory alarm [ACC-3967] Resizing the cache no longer requires service restart to fully take effect ================================================================================ Errata or Known Issues ================================================================================ [ACC-6154] Restoring a REM backup sometimes does not restore all settings on the UI settings page [ACC-6145] Adding a new CA to a VA may require a service restart to occur before this is used when validating application server connections [ACC-6078] Raspbian data connections may be interrupted if application servers or peering is modified while transfers are in progress. [ACC-5083] SMB Connections are not optimized by the Mac client [ACC-4719] STARTTLS and HTTP CONNECT content is not cached in client to local VA scenarios [ACC-4648] Mac client service stops when it connects to a VA that is using a non-standard block size [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. [ACC-3825] Un-rooted Android devices can only accelerate HTTP(s) traffic ================================================================================ = = = Replify Accelerator 6.5.0-31851 Release Notes = = ================================================================================ This document details the content of the Replify Accelerator release 6.5.0. This release contains several features and improvements along with bug fixes. The previous GA release of Replify Accelerator was version 6.4. ================================================================================ Release Highlights ================================================================================ - REM GUI improvements - Azure Container Support - TLS v1.3 now used for secure Replify management connections - Improved SSL certificate validation ================================================================================ Upgrade Instructions ================================================================================ The following versions of the Virtual Appliance (VA) and Enterprise Manager (REM) can be upgraded directly to 6.5.0: = 6.4.0 = 6.3.0 = 6.2.1 = 6.2.0 = 6.1.0 = 6.0.0 = 5.6.0 To upgrade your system, the REM should be updated first (if you have a REM), followed by the Virtual Appliance and then clients. To upgrade the REM or VA please run the following commands at the console: apt-get update --allow-relaseinfo-change replify-ctl upgrade You will be prompted for an activation code after running the above command. Please contact support@replify.com for this code. Windows clients can be updated by navigating to 'Tools > Options > Updates' in the Replify client user interface. To avail of updates, the client must be connected to an upgraded REM or VA. Detailed installation instructions can be found in the Replify Installation & Configuration Guide. The Accelerator Client can also be downloaded from the web interface of VAs and REMs. ================================================================================ Changes in Behaviour this Release ================================================================================ -------------------------------------------------------------------------------- [ACC-6071] The network interface that the UI listens on is now configurable -------------------------------------------------------------------------------- In previous releases, the web UI of the VA was available on the LAN interface (if configured) while there is now a new setting that can be used to specify the interface to be used. If a LAN interface is specified on the settings page of the VA, the required interface for the UI to listen on should also be manually specified on the VA settings page after upgrading. -------------------------------------------------------------------------------- [ACC-6066] Dropped writes removed from health graph -------------------------------------------------------------------------------- In previous releases, the VA heath graph had a counter "dropped writes". It does not make sense to track this counter over time as it can only ever increase. To track when the disk is under severe load, the "write queue" counter can be examined instead. -------------------------------------------------------------------------------- [ACC-6111] Duplication of statistics for application servers on REM -------------------------------------------------------------------------------- In previous releases, when a peered virtual appliance setup was being used, optimization statistics for an application server could be counted twice in the REM application servers report. This will only be corrected when both VAs and the REM are upgraded to v6.5 -------------------------------------------------------------------------------- Debian Stretch support is no longer available -------------------------------------------------------------------------------- Debian Stretch is no longer a supported Linux platform for the Replify Virtual Appliance or Enterprise Manager. This means that, while the system may still work without any issues, Replify Support will advise of an upgrade in the first instance of an issue on this platform. -------------------------------------------------------------------------------- [ACC-6162] generate-diagnostic-report command no longer generates a URL -------------------------------------------------------------------------------- When running generate-diagnostic-report from the command line, a URL that allows the dreport to be downloaded from the web UI is no longer available. ================================================================================ Disk Space ================================================================================ When deploying from VMWare, the default disk configuration will be a 16GB disk with 'Thin Provisioning'. We would recommend 'Thick Provisioning' which will be faster when running but slower to deploy. If resources are particularly constrained on the server, you may use 'Thin Provisioning' to ensure the disk space is only consumed when required. For many production environments, 16GB may not be sufficient to hold all cache data. Please see the Quick Start Configuration Guide for details on how to add extra disk space. ================================================================================ MAC addresses with Hyper-V ================================================================================ Once the image is deployed on the Hyper-V server the MAC address allocation will be set to 'dynamic' by default. When the machine boots Hyper-V will generate a MAC address for the connected virtual network interface. Replify recommends changing this to use a static MAC address instead. ================================================================================ New Features and Improvements ================================================================================ [ACC-6164, ACC-6157, ACC-5714] Application server management has been made more efficient [ACC-6148] SOCKS acceptor can be enabled/disabled on client through configuration [ACC-6143] Time periods on REM UI dropdowns are more descriptive [ACC-6136] VAs and REM UI webserver now includes full TLS certificate bundle [ACC-6129] NET_ADMIN capability no longer required to run VA in container (Azure container support) [ACC-6110] REM now displays statistics for remote VAs in addition to local VAs [ACC-6102] Windows installers should be signed using SHA256 [ACC-6099] REM UI now shows VA hostname in the appliances configuration page [ACC-6097, ACC-5965] Diagnostic reports are not generated with more descriptive filenames [ACC-6096] TCP keepalives are now configured for management connections to REM [ACC-6082] Activity timeouts which cause client/peer disconnection can now be configured on VA [ACC-6071] The network interface that the VA UI listens on is now configurable [ACC-6060] Improvements to client diagnostic report generation UI [ACC-6034] Connection process to REM/VAs has been made more effient [ACC-6030] Virtual Machine UI informs user if they haven't configured a network interface [ACC-6027] TLS 1.3 is now used for secure management connections [ACC-6009] VA/REM backups can now be created/restored from the shell [ACC-6126] Logging improvements [ACC-6008] Improvements to SSL certificate UI on VA ================================================================================ Fixes ================================================================================ [ACC-6185] Corrupted message no longer shown on REM UI when upgrading VA [ACC-6180] Hostname exclusions can now be removed from the HTTP settings page [ACC-6170] VA Session History Page on REM UI now shows correct history [ACC-6163] REM now recovers gracefully if the process is killed unexpectedly [ACC-6151] Erroneous SNMP error logged to systemd on REM startup no longer occurs [ACC-6144] Activity Log on REM now correctly displays usernames [ACC-6141] UI components on VA and REM UI are loaded more efficiently [ACC-6137, ACC-6098] REM backup can now be restored correctly onto an existing REM that contains statistics [ACC-6134] "Tags by Performance" table on REM overview UI is now sorted correctly [ACC-6132] HTTP 500 error no longer occurrs on REM UI in specific circumstances [ACC-6127] "Interception disabled" notification on Windows is now displayed as an information message, not an error [ACC-6125] Serial getty service now detects if serial interface not available on QCOW2 images [ACC-6120] Connections initiated from an application server destined for a client are no longer blocked [ACC-6116] Server TLS certificates generated by VA are now recognised by newer versions of macOS [ACC-6111] Application servers report on REM no longer contains duplicated statistics [ACC-6109] TCP Keep-alive socket options are being correctly applied to listening TCP sockets [ACC-6108] Reconnection logic improved when disconnecting from a secure remote peer [ACC-6092] Systemd does not log erroneous NFT error on system startup [ACC-6091] Restoring a backup to a VA or REM no longer requires a server reboot [ACC-6090] `replify-ctl renew-ca-certificate` command now allows the user to cancel gracefully [ACC-6087] Linux client no longer crashes when processing SMB traffic from a Samba server [ACC-6068] UI inconsistency on REM/VA password UI has been removed [ACC-6061] Muxing no longer requires a service restart to take effect [ACC-6054] Muxing now works when using a specified WAN interface [ACC-6048] It is no longer possible to change the hostname of VAs that are not running inside a Replify supplied VM [ACC-6025] Erroneous Epmd error logged to systemd on startup no longer occurs [ACC-6017] Race condition when accelerating connection while removing application server has been resolved [ACC-6010] Running reset-cache on docker no longer gives unexpected error [ACC-5955] Race condition when peering VAs has been resolved. [ACC-5764] Certificates with multiple certification paths are not validated correctly [ACC-5758] Deactiving an application server with SSL enabled works correctly when this is in a subnet that is also an application server [ACC-5677] Cache write rate metric is now calculated correctly when multiple cache block sizes are in use [ACC-5119] Race condition that results in cache misses has been removed ================================================================================ Errata or Known Issues ================================================================================ [ACC-6145] Adding a new CA to a VA may require a service restart to occur before this is used when validating application server connections [ACC-6078] Raspbian data connections may be interrupted if application servers or peering is modified while transfers are in progress. [ACC-5083] SMB Connections are not optimized by the Mac client [ACC-4719] STARTTLS and HTTP CONNECT content is not cached in client to local VA scenarios [ACC-4648] Mac client service stops when it connects to a VA that is using a non-standard block size [ACC-4255] AVG anti-virus software incorrectly detects a threat during Replify client uninstallation [ACC-4137, ACC-4170] applications that use SSL pinning (e.g. Skype for Business, Dropbox, some applications depending on Apple certificates etc) will have their connections blocked if configured in the VA to use SSL optimization, unless the pinned certificate is also uploaded to the VA. [ACC-3825] Un-rooted Android devices can only accelerate HTTP(s) traffic [ACC-3718] Intel based processors on Android devices not supported