Article ID: 2230978 - Last Review: August 13, 2010 - Revision: 3.0 Description of Update 4 for Intelligent Application Gateway 2007 Service Pack 2
On This PageSUMMARYMicrosoft has released Update 4 for Intelligent Application Gateway (IAG) 2007 Service Pack 2 (SP2). This article contains the following information about this update:
INTRODUCTIONCollapse this table
For more information about IAG 2007 SP2, click the following article numbers to view the articles in the Microsoft Knowledge Base: 962977
(http://support.microsoft.com/kb/962977/
)
Description of Intelligent Application Gateway (IAG) 2007 Service Pack 2
968384
(http://support.microsoft.com/kb/968384/
)
Description of Update 1 for Intelligent Application Gateway 2007 Service Pack 2
975491
(http://support.microsoft.com/kb/975491/
)
Description of Update 2 for Intelligent Application Gateway 2007 Service Pack 2
979097
(http://support.microsoft.com/kb/979097 /
)
Description of Update 3 for Intelligent Application Gateway 2007 Service Pack 2 New features and improvements that are included in this update
Details of the ADFS improvementsThis update fixes various issues that occur when you publish applications that use ADFS in a holistic way. Changes to configuration files no longer have to be made manually. They are now made automatically when you run the IAG ADFS configuration script. All fixes to the IAG infrastructure that are required to support ADFS v1 publishing have now been made. ADFS v2 publishing is not supported by IAG.Limitations of the ADFS improvementsYou must run the ADFS script after you install and enable the update. Additionally, you must run this script after each configuration change. For example, you must run this script when you add an application to an existing trunk. The script can be found under \utils\ADFS.Updates for Client ComponentsUpdate 4 for IAG Service Pack 2 contains new Client Components (version 4.0.1152.100) that are aligned with UAG Update 1. Users are required to upgrade previously installed versions of Client Components when they first access an IAG Service Pack 2 Update 4 server. Users may be required to restart their computer after they complete the Client Components installation.Limitations to the Client Components updateThe Network Connector feature is not implemented for Windows 7. Therefore, full remote network connectivity is not available for Windows 7 with IAG. Customers who require full network connectivity for Windows 7 clients must upgrade from IAG 2007 to Microsoft Forefront Unified Access Gateway (UAG) 2010. Forefront UAG 2010 provides support for SSTP and Direct Access for Windows 7.Client OS compatibility with Update 4 for IAG 2007 Service Pack 2Collapse this table
General information about the IAG client endpoint system requirements
(http://technet.microsoft.com/en-us/library/dd277998.aspx)
Issues that are fixed by this updateThis update fixes the following issues that were not previously documented in a Microsoft Knowledge Base article:Issue 1SymptomsWhen you use SAP instead of the Whale portal as the default application in IAG, you receive the following HTTP 500 error:Server Error in '/adfs' Application. Request is sent to the wrong port (whale portal port, instead of directly to the Default application CauseThis issue occurs because the configurator does not recognize that ADFS is enforced. When you set an initial application that enforces ADFS, the initial port in the configuration files is set to 6002.ResolutionThe code in the configurator is now ADFS-aware. Therefore, the port is set correctly.When you set an application as the initial application, you must change the cookie domain to the actual domain. If you publish SharePoint applications, you must enter the domain that corresponds to your Forefront UAG host name and the AAM host name in the cookie domain field. For example, if the Forefront UAG portal uses the host name portal.example.com and the SharePoint AAM host name is sp.example.com, enter .example.com. For more information about how to configure SharePoint AAM applications, visit the following Microsoft website: Configuring SharePoint AAM applications with AD FS
(http://technet.microsoft.com/en-us/library/ee939390.aspx)
Issue 2SymptomsWhen you use an ADFS trunk that directly links to an internal page, you receive the following error message:You are not authorized to access this application. unrecognized application CauseThis issue occurs because of an error in the ADFS authentication process. This process involves changing the orig_url attribute and the host attribute. However, during this process these parameters are malformed. Therefore, bookmarks cannot be used in ADFS.ResolutionThe internal site files and the filter mechanism now support the scenario in which ADFS is enforced.When you set an application as the initial application, you must change the cookie domain to the actual domain. If you publish SharePoint applications, you must enter the domain that corresponds to your Forefront UAG host name and the AAM host name in the cookie domain field. For example, if the Forefront UAG portal uses the host name portal.example.com and the SharePoint AAM host name is sp.example.com, enter .example.com. For more information about how to configure SharePoint AAM applications, visit the following Microsoft website: Configuring SharePoint AAM applications with AD FS
(http://technet.microsoft.com/en-us/library/ee939390.aspx)
Issue 3SymptomsWhen you sign out of IAG, you do not sign out of ADFS. This means that you can access the IAG portal again without having to sign in. This may be a security risk in scenarios where the client connects to the IAG portal from a shared public computer.CauseWhen you sign out of IAG, you do not sign out of ADFS. This means that you can access the IAG portal again without having to sign in. This may be a security risk in scenarios where the client connects to the IAG portal from a shared public computer.ResolutionThe logoff URL of ADFS is now injected into the LogOff function of the IAG portal. When you log off from the IAG portal, you are also logged off from ADFS.Issue 4SymptomsThe GetUserInformation function of the Usermgrcom module cannot retrieve an attribute value that is not part of partial attributes list of an Active Directory repository.CauseWhen you perform an Active Directory Service Interfaces (ADSI) search in the global catalog, Active Directory Service Interfaces (ADSI) will only read attributes that are part of the global catalog “partial attribute” list. However, the search results include empty values for these attributes.ResolutionIf no attribute is found in the global catalog, the function returns a false result instead of adding an empty attribute value. Additionally, the function enables a fallback search by using Lightweight Directory Access Protocol (LDAP).Note If you want to use the GetuserInformation function to retrieve several Active Directory values that includes exported and un-exported attributes, you must split the call to the function into two calls. You must create one call for all exportable attributes together and a second call for all other attributes. The second call will not receive attributes from the global catalog. Therefore, the LDAP search will be initiated. Issue 5SymptomsThe Microsoft Office Outlook Web Access 2003 SP1 template blocks calendar items after 2009.CauseThis issue occurs when the default template for Outlook Web Access 2003 SP1 has multiple rules that specify parameter values between 1999 and 2010. These values are used by various Outlook Web Access calendar functions to refer to dates, and allows for only dates between the years 2000 and 2009. Therefore, calendar events after 2009 are blocked when this template is used.Issue 6SymptomsWhen IAG tries to obtain the user principal name (UPN) of a user, the operation fails if there is a slash in the common name (CN) of the user.CauseThe issue occurs because CN strings that contain a slash are parsed incorrectly. The slash is treated as a path separator.ResolutionThis update implements an additional function that encodes CN strings that contain a slash.Issue 7SymptomsAfter you install IAG 3.7 SP2 Update 2, you cannot import a trunk export ECP file as an ECP file. You can only import the file as an EGF file. Additionally, the following error is generated:
Failed to Decrypt new configuration, Please make sure you use the correct keys.
CauseThis issue occurs when you cannot import single trunk functionality.ResolutionAfter you apply the update a single trunk can be imported successfully.Note If you want to import a trunk into a configuration that already has a trunk with the same name, we strongly recommend that you cancel the operation, delete the existing trunk, and then import the new trunk again. Issue 8SymptomsYou receive the following error message:ContentLength issue of AJAX by using IAG 2007 - the message that is received from the server could not be parsed. CauseThis issue occurs because the AJAX response from the server is parsed incorrectly. The bug (37978) was previously fixed and delivered as a private fix. However, the fix is overwritten by Update 3.ResolutionThe fix was incorporated into Update 4.Issue 9SymptomsYou have a Java-enabled web browser that is not Windows Internet Explorer installed on a computer that is running a supported version of Windows. When you connect to IAG 2007 from this computer, you receive the following warning message:Whale Client Components could not run on this computer, since the script signature could not be verified. Your user experience while using the site may vary, depending on your organization's security policies. Note This issue does not affect Windows Internet Explorer. CauseThis issue occurs because of a feature in the endpoint detection application that is implemented in Java for Windows clients that use web browsers other than Internet Explorer. Some potentially dangerous characters that might be passed to Java programs are blocked by this application. This includes the comma character (,). However, the list of client detection script files that must be executed on an endpoint computer is delivered to the client as a comma separated list. Therefore, the Java application cannot parse the list and returns the error message that is mentioned in the "Symptoms" section to the client computer.ResolutionThis update changes the delimiter to a semicolon (;).Issue 10SymptomsThe icon to download the offline client components on Windows 7-based client computers is not visible.CauseThis issue occurs because the client detection agent cannot detect windows 7 when you run IAG in a portal.ResolutionThis update adjusts an agent detection script to detect Windows 7 in the same manner as regular endpoint detection.UPDATE INFORMATIONA supported update is now available from Microsoft. However, it is intended to correct only the problems that this article describes. Apply it only to systems that are experiencing these specific problems. To resolve these problems, contact Microsoft Customer Support Services to obtain the update. For a complete list of Microsoft Customer Support Services telephone numbers and information about support costs, visit the following Microsoft website: http://support.microsoft.com/contactus/?ws=support
(http://support.microsoft.com/contactus/?ws=support)
Note In special cases, the charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question. PrerequisitesBefore you install this update, make sure that you have Intelligent Application Gateway (IAG) 2007 Service Pack 2 (SP2) installed on an appliance or on a virtual machine.For more information about the IAG client endpoint system requirements, visit the following Microsoft TechNet website: http://technet.microsoft.com/en-us/library/dd277998.aspx
(http://technet.microsoft.com/en-us/library/dd277998.aspx)
Restart requirementYou do not have to restart the computer after you apply this hotfix.Removal informationTo remove this update, follow these steps:
Hotfix replacement informationThis hotfix does not replace any other hotfix.Known IssuesSupported products notes
File informationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.Collapse this table
REFERENCES
For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684
(http://support.microsoft.com/kb/824684/
)
Description of the standard terminology that is used to describe Microsoft software updates
The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the performance or reliability of these products.
| Other Resources Other Support Sites
CommunityArticle Translations |






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top