Starting with version 1.2.1, the logic for processing user groups from an external data source of the ACTIVE_DIRECTORY type has been revised. After the update, synchronize the SIDs of the groups added to the source on the Groups page in the identity source settings:

Click the
button.
Until synchronization is performed, group processing in authorization policy conditions will not work. If NAICE login using Active Directory credentials was configured previously, make sure before the update that you can log in using a local account that will allow you to synchronize the groups. If it is necessary to restore the default local administrator account (admin), follow the instructions: v1.2_2.4 Restoring the administrator account. |
Groups of the If such groups are used in authorization policy conditions, reconfigure the policies and discontinue their use. |
This section provides a list of changes introduced in version 1.2.X that will require reconfiguration after the update if values other than the default values were previously used. This is due to the fact that these settings have been moved to the Configuration Manager and will subsequently be stored in the database. Reconfiguration of these settings will not be required after future updates. |
Starting with version 1.2, security certificates (for the web interface and portal) and RADIUS certificates (EAP-PEAP and EAP-TLS) can be managed through the system GUI (see System Settings → Certificate Store → Server Certificates).
If custom certificates were configured using environment variables in version 1.1 or earlier, they must be reinstalled through the NAICE GUI after upgrading to version 1.2.X: v1.2_3.8 Using security certificates and v1.2_3.12 Updating/replacing RADIUS certificates for EAP-PEAP/TLS.
These actions only need to be performed once. The installed certificates will be preserved during subsequent upgrades.
Starting with version 1.2, it is possible to configure two computer credentials associated with a NAICE node in a high-availability configuration. These settings will not be migrated to the database during the upgrade. After the upgrade, manually add the computer credential information in Users and Devices → Identity Management → External Identity Sources.
Starting with version 1.2, the CAPTCHA difficulty level setting has been moved from the .env environment variables to the portal builder. For existing portals where the SMS Login authentication method was enabled, the CAPTCHA difficulty level is automatically set to medium during the upgrade. If you need to change the difficulty level or disable CAPTCHA, make the appropriate changes in the portal builder.
For a stand-alone installation, the PostgreSQL database image has been changed to match the one used in a high-availability installation (using Replication Manager), which requires database migration.
Attempting to perform the upgrade by installing the new version of NAICE over the existing version will cause NAICE to become inoperable. |
Starting with version 1.2, it is possible to change Docker subnets using Ansible playbook variables. For more information, see v1.2_3.13 Changing Docker networks.
Before the upgrade, specify the current subnet addresses in the playbook, matching those configured previously. Otherwise, the upgrade will fail with an error. |
In version 1.1 and earlier, access to the web management interface was provided through the host machine address specified during installation.
Starting with version 1.2, this restriction has been removed, and NAICE management can be accessed by default through any IPv4 address or the host's domain name on port 443. A mechanism has also been added to restrict the list of management addresses. This setting is available in System Settings → Security and Access → Login → Management Addresses.