SafeNet Agent for TokenValidator Proxy release notes
SafeNet Agent for TokenValidator Proxy (TVP) relays proxy authentication requests from other agents to the SafeNet server.
When used with other agents, such as SafeNet Agent for Windows Logon, only the SafeNet Agent for TVP is required to register its IP address with the SafeNet server. Alternately, without SafeNet Agent for TVP, the IP address of each workstation must be registered with the SafeNet server.
When using the SafeNet server API with a cloud application (such as MS Azure), you cannot be sure of the IP address of the cloud server, nor are you entitled to claim the IP address as your own. To solve this problem, you can point your cloud applications at the SafeNet Agent for TVP and register the agent as their Auth Node.
Release description
SafeNet Agent for TVP v3.1.0
This release introduces the following features and resolves the issues listed below:
-
MobilePASS+ numeric push: Users enter the number shown on the sign-in page into the push notification, helping prevent MFA fatigue and push-based attacks. For more information, see MobilePASS+ push number matching.
-
TLS 1.3: Support for the TLS 1.3 protocol to strengthen transport security.
-
.NET upgrade: Upgraded .NET Framework from 4.5 to 4.8 to improve platform compatibility and security.
-
Enhanced operating system support: Compatible with Windows Server 2022 and 2025.
| Issue | Synopsis |
|---|---|
| SASNOI-22563 | Previously, number matching failed in WLA 4.1.2 on Windows 11. SafeNet Agent for TVP now fully supports Numeric Push authentication. |
| SASNOI-21416 | Push authentication did not work in PAM agent v1.2 with SafeNet Agent for TVP, whereas OTP authentication functioned as expected. Now push authentication functions correctly in the PAM Agent with the SafeNet Agent for TVP acting as a proxy. |
| SASNOI-15657 | Previously, Windows Server 2022 and 2025 were not supported. With the latest update, SafeNet Agent for TVP fully supports both Windows Server 2022 and 2025. |
SafeNet Agent for TVP v3.0.1
This release introduces the following features and resolves the issue listed below:
-
Thales rebranding
-
Reduced operating system support: Since Microsoft has deprecated the support of Windows Server 2008 R2, SafeNet Agent for TVP 3.0.1 no longer supports Windows Server 2008 R2.
| Issue | Synopsis |
|---|---|
| SASNOI-15284 | Summary: For failover scenarios, the TVP agent took several seconds before redirecting the authentication requests to the secondary SafeNet server, thereby causing time out of authentication requests. This is now fixed. When the primary server is not available, the TVP agent redirects the authentication requests to the secondary SafeNet server within two seconds. |
SafeNet Agent for TVP v3.0.0
This release introduces the following features:
-
FIPS support: Support for the FIPS mode within the operating system with AES-GCM and RSA key standards.
-
Enhanced security: The AES-GCM encryption algorithm is now used to provide faster and a more secure way to protect data exchange between the SafeNet Agent for TokenValidator Proxy and the SafeNet server.
Extended operating system support: Support for Windows Server 2019 (64-bit).
SafeNet Agent for TVP v2.1.0
This release introduces the following features and resolves the issue listed below:
-
Extended operating system support: Support for Windows 2016 (64-bit).
-
Security enhancements: Security enhancements at infrastructure and agent level to better secure the communication between channels.
-
Support for Transport Layer Security 1.1/1.2 protocols
| Issue | Synopsis |
|---|---|
| SASNOI-3436 | Support for Transport Layer TLS 1.1 and TLS 1.2 protocols has now been added. As a result, authentication is now possible when connection is set to any of TLS/SSL versions. |
SafeNet Agent for TVP v2.0.0
This release introduces the following features:
- Push authentication: Transfers Push Authentication requests from all SafeNet agents that support Push Authentication.
Note
Push Authentication is supported only with MobilePASS+ tokens.
-
Performance improvements: The speed of authentication through SafeNet Agent for TVP against failover servers has been greatly increased.
-
Logging function
-
Security enhancements: Ability to activate or deactivate a certificate check.
-
Rebranding: The installation wizard has been updated with Gemalto branding.
Advisory notes
Installation
When installing SafeNet Agent for TVP, note the following:
-
If changing the default destination folder, do not locate on a root drive. This will cause the agent to malfunction.
-
If a non-default destination folder is selected, the SAS Connectivity Test in connected agents will not work.
Push authentication
SafeNet Agent for TVP v2.1.0 (and above) supports Push Authentication seamlessly, and does not require configuration.
Compatibility and upgrade information
System requirements
Supported platforms
- Windows Server 2025
- Windows Server 2022
- Windows Server 2019
- Windows Server 2016
Supported architecture
- 64-bit
Additional software components
- IIS 10
- IIS 7.5
- .NET Framework 4.5 or above
SafeNet Authentication Service versions
SafeNet Agent for TVP supports the following SAS releases:
- SafeNet Authentication Service Cloud Edition
- SafeNet Authentication Service PCE 3.9.1 and later
Upgrade
SafeNet Agent for TVP 3.0.1 supports upgrade from v1.02 (or later versions).
To replace a version of SafeNet Agent for TVP earlier than v1.02, uninstall the previous installed version before installing version 3.0.1.