Attachmate Worldwide  |   Contact Us  |   NetIQ.com
Home » Support » Solution Library

Technical Notes

Readme: Features Introduced in Reflection for Secure IT Windows Client 6.1
Technical Note 1897
Last Reviewed 31-May-2006
Applies To
Reflection for Secure IT Windows Client version 6.1
Summary

This document lists the features introduced in Reflection for Secure IT Windows Client version 6.1 and provides information for obtaining this Reflection SSH product.

Note: Reflection for Secure IT version 7.0 is available beginning in February 2008. For a list of new features in 7.0, see Technical Note 2281. For information about purchasing Reflection for Secure IT, please e-mail us: SalesRecept@attachmate.com.

Features Introduced in Version 6.1

The following new features are available in Reflection for Secure IT Windows Client version 6.1.

Public Key Infrastructure (PKI) Certificates

  • Reflection certificate store.

Certificates in the new Reflection store can be used for host and user authentication during Reflection SSH and SSL/TLS sessions. Use the new Reflection Certificate Manager to manage these certificates. (Reflection continues to support authentication using certificates in the Windows certificate store.)

  • Key Agent authentication using imported certificates.

You can now import certificates into the Reflection Key Agent and have them available for user authentication for Secure Shell connections.

  • LDAP support for CRL checking and storing intermediate certificates.

You can configure Reflection to use an LDAP server both for external CRL (Certificate Revocation List) checking and to store intermediate certificates. See the LDAP tab in the Reflection Certificate Manager.

  • Smart card support.

Reflection now supports authentication using smart cards that conform to PKCS#11 specifications. See the PKCS #11 tab in the Reflection Certificate Manager.

Secure Shell connections

  • Drop-down list for selecting SSH config schemes.

If you have already created an SSH Config scheme, or configured settings for a particular host, you can easily use this configuration again. All configured hosts and schemes are now available for selection from a convenient drop-down list.

  • Automatically launch local applications.

Use the Local Port Forwarding dialog box to configure Reflection to launch an application automatically after the Secure Shell connection has been established. This feature makes it easier to send data securely through the SSH Tunnel from any application installed on the local computer.

  • Configure Multi-hop SSH connections.

Use multi-hop connections when you need to establish secure connections through a series of SSH servers. This is useful if your network configuration doesn't allow direct access to a remote server, but does allow access via intermediate servers.

  • Reuse established SSH connections.

You can reuse an established SSH connection when you open multiple sessions to the same host—additional sessions don’t require re-authentication. To change this setting use the General tab of the Secure Shell Settings dialog box.

  • Forward FTP communications.

Reflection can now forward all FTP communications—including the FTP command channel and data channel(s)—through an existing secure SSH tunnel.

  • Configure FIPS mode for specific sessions.

FIPS mode can now be configured on a per-session basis. Reflection also continues to support use of group policy to enforce FIPS mode for all sessions.

  • VT220 emulation for Secure Shell command line sessions.

New keywords are available for configuring VT220 emulation for command line ssh and ssh2 sessions. These can be configured in the Secure Shell configuration file, or by using the -o command line switch. To see a list of these new terminal settings, see "Secure Shell, configuration file keywords (terminal settings)" in the Reflection application Help index.

  • Full support for both OpenSSH and F-Secure style command line switches.

The ssh, scp, and sftp command line utilities now support the full range of command line switches provided by equivalent OpenSSH-style utilities. New ssh2, scp2, and sftp2 utilities have been added for customers who are migrating from F-Secure and need to maintain scripts written for the F-Secure command line utilities.

  • Scp transfers use the sftp subsystem.

The scp and scp2 command line utilities now use the sftp subsystem to transfer files securely. (Backwards compatibility for OpenSSH-style scp transfer, which uses rcp through the SSH tunnel, is available using the -1 switch.)

Supported Platforms in Version 6.1

For information about platform support in Reflection for Secure IT, see Technical Note 1944.

Obtaining Your Product Upgrade

If you already obtained your product upgrade, disregard this section.

Maintained customers are eligible to download the latest product releases from the Attachmate Download Library web site: https://download.attachmate.com/Upgrades/.

You will be prompted to login and accept the Software License Agreement before you can select and download a file. For more information on using the Download Library web site, see Technical Note 0200.

Related Technical Notes
0200 Using the Attachmate Download Library (FAQ)
1905 Features Introduced in Reflection for Secure IT Windows Client 6.0
1944 Supported Platforms in Reflection for Secure IT Client and Server
1947 Recommendations When Upgrading to Reflection for Secure IT Windows Client 6.1
1999 Reflection for Secure IT Technical Notes
2128 Reflection for Secure IT Windows Client 6.1 Service Pack 3 (SP3): Fixes, Features, and File Download
2281 New Features in Reflection for Secure IT Windows Client 7.0 and Release Notes

Did this technical note answer your question?

Yes    No    Somewhat     Not sure yet

Additional comments about this tech note:

Need further help? For technical support, please contact Support.