AppGate ZTNA requires a license to run Device Claim Scripts as of the v6.6 Client. Customers using Device Claim Scripts in their SDP Collective will need to request and deploy this license on a version of AppGate ZTNA that supports it before upgrading their Clients. If this license is not deployed properly, the v6.6 Client will not run a Device Claim Script potentially impacting their end users from connecting to resources as defined in assignment criteria in Policies and Criteria Scripts, and access criteria in Conditions.
Before updating any clients to v6.6, customers running Device Claim Scripts will need to take the following steps:
Open a case with AppGate Support to request an updated license. This license is for security improvements only and there are no additional costs.
Apply the license to your AppGate ZTNA Collective. You can apply the license to any version, but the license won't be effective until you upgrade to a version that supports it.
Upgrade their AppGate Controllers to v6.6.x, 6.5.4 and later, or 6.4.13 and later. Only these versions support the v6.6. Clients running Device Claim Scripts.
Once the license is applied and the Collective is updated, customers can upgrade their AppGate ZTNA Clients to v6.6.
Here are some additional notes about the transition to this new license requirement:
Clients running v6.5 and earlier do not need this license to run a Device Claim Script.
Customers will not be able to upgrade your Collective to v6.6 without this license. If a Collective is upgraded to v6.5.4 and later, or v6.4.13 and later without deploying the new license, they will see the following warning in your admin UI:
cz-controllerd: license-verified-dns-names-profiles: Your license does not include Verified DNS Names. Device Claim Scripts will stop functioning after upgrading to 6.6. Please contact support.
AppGate will only provide this license to a validated Account Administrator for your Company. If you are receiving this email, then AppGate has identified you as an Account Administrator.
Customers can see how they are using a Device Claim Script, by going to Identity >> Identity Provider and scroll to the bottom to see if any "Commands Mapped to On-Demand Device Claims" have been added.