NEW SOFTWARE RELEASE ==================== Products involved: AXIS Device Manager Release date: November 7, 2024 Release type: Release Software version: 5.30 Build 125 Protocol Version: 5.0.56 File name: AXISDeviceManagerSetup.exe Required: 64-bit Operating System Microsoft .NET version 4.8 Supported OS: Windows 8.1 Pro, Windows 10 Pro, Windows 11 Pro, Windows Server 2016, Windows Server 2019, Windows Server 2022 Recommendations: Latest OS Service Packs. Observe the hardware requirements for running AXIS Device Manager Server. * Minimum (#devices<500): Intel core i5 or equivalent, 4GB RAM, 100 Mbits/s across the network infrastructure * Recommended (500<#devices<2000): Intel core i7 or equivalent, 8GB RAM, 1000 Mbits/s across the network infrastructure * More than 2000 devices per server is not recommended. * Make sure Axis devices run the latest available AXIS OS. Supported Devices: AXIS products with AXIS OS versions 4.40 or higher. (Note that the exact functionality supported varies depending on a particular product model and firmware) Virus Scanner: Cortex XDR. Languages: (UI + help files) English, French, German, Italian (UI only) Arabic, Czech, Chinese (Simplified), Chinese (Traditional), Dutch, Finnish, Japanese, Korean, Persian, Polish, Portuguese (Brazil), Russian, Spanish , Swedish, Thai, Turkish and Vietnamese. Last 2 preceding supported releases: * 5.29 Build 120 * 5.27 Build 108 -------------------------------------------------------------------------------- Contact Information =================== Please contact Axis Communications for product information, updates and support at: https://www.axis.com Solutions to new problems and FAQ's are listed at: https://www.axis.com/products/axis-device-manager Installation ============ - Run AXISDeviceManagerSetup.exe and follow the instructions. - If not already installed, Microsoft .NET 4.8 framework will be installed (included in installation file). This will take a few minutes. Microsoft .NET 4.8 framework can also be installed via Windows Update prior to installation of AXIS Device Manager. - Make sure you have full administrator rights on the computer you install on. Uninstallation ============== - Click 'Uninstall' for AXIS Device Manager under Start > Control Panel > Programs and Features -------------------------------------------------------------------------------- Changes made in 5.30.125 ============================== * Resolved CVE-2024-43485 * Fixed a bug that caused SAN extension to be missing in certificates signed for devices with AXIS OS 11.11 or later. * Fixed a bug that prevented the correct reminder and warning when a certificate is close to expiration date or expired. * General improvements of cybersecurity. * General improvements of performance and stability. Known Limitations in 5.30.125 ============================== * Because of Windows Server 2016 lack of support for some encryption algorithms we observed a failure to import CA certificates archives (pfx/p12) using strong encryption if the client is used in the Windows Server machine. New features in 5.29.120 ============================== * Added support of elliptic curves algorithms in the TLS communication from server to devices. * Added support of elliptic curves algorithms when installing and signing TLS certificates for devices that support ECC. Changes made in 5.29.120 ============================== * Resolved: CVE-2024-30105 * Fixed some problems with dialogs showing UTC time when configuring NTP server. * Fixed UTC time calculation which caused wrong validity time for IEE802.1x certificates * Fixed some unnecessary restart of devices when configuring date and time. * Fixed the correct order of suggested default AXIS OS (Firmware) when upgrading multiple devices. * Improved stability of the function that installs certificates in bulk. * General improvements of cybersecurity. * General improvements of performance and stability. Changes made in 5.28.116 ============================== * Fixed incorrect handling of some .CFG files. * Fixed crash caused by corrupted communication with AXIS A8004. * General improvements of cybersecurity. * General improvements of performance and stability. Known Limitations in 5.28.116 ============================== * Elliptic curves algorithms are not yet supported when performing certificates management operations. * IEEE802.1X certificates may have wrong start validity time due to wrong calculations based on UTC time Changes made in 5.27.108 ============================== * From this version we provide customers with a SBOM (software bill of materials) in the software download page. * Introduced official compatibility with Windows 11 Pro and Server 2022. * Client-Server TLS 1.2 communication is now supporting EC cipher suites. * Corrected a bug that in rare occasions prevented to install some device software (ACAPs). * Corrected a bug that allowed the deletion of the last User/Group from the user list. * Corrected a bug that prevented to use Axis Camera Station Server and Axis Device Manager Server together on the same machine. * Replaced some old DLLs to improve general level of cyber security of the solution * General improvements of performance and stability. Known Limitations in 5.27.108 ============================== * Elliptic curves algorithms are not yet supported when performing certificates management operations. * Dropped support of Windows Server 2012 R2 and lower Windows Server versions. Changes made in 5.26.103 ============================== * Solved a bug that prevented some users from adding multiple devices of the same model in bulk if they were all reset to factory defaults. * The IP address assignment function will now also provides more insight when an assignment is not possible. * Fixed some wrong icon displayed when working with AXIS Network Speakers. * General improvements of stability and speed. Changes made in 5.25.101 ============================== * Solved an issue that caused crash when restore points operations were performed with units not entirely supporting our API. * Solved a bug which caused a crash of the server when some not supported cryptographic protocols are used inside a certificate. * Improved the description in the server's logs that are created when a certificate error occurs. * Improved some terminology used in the user interface when installing a device application (ACAP). * Added support for the installation of ACAPs following the latest SDK recommendations. * Corrected erroneous strings in the help user interface and copyright information. * Assigning IP addresses in a range when not enough IP addresses are available generates a warning dialog before aborting the operation. * Changed classification of "Unknown product type" log from ERROR to INFO. * General improvements of stability and speed. Known Limitations in 5.25.101 ============================== * Elliptic curves algorythms are not supported when performing certificates management operations. Changes made in 5.24.100 ============================== * Fixed a bug that prevented the installation of own certificate file * General performance and stability improvements Changes made in 5.23.098 ============================== * Fixed some incorrect bhavior in the CSV Column Interpretation Wizard * Non valid characters cannot be used anymore in the CSV file to keep compatibility with AXIS OS * Improved stability of Set Password and User Management functionality * Iproved stability of the nightly restore points creation * Iproved stability of import device function * Fixed some uncommon issues with setting date and time Changes made in 5.22.092 ============================== * Fixed a 12hour error when syncing time with ADM server * Fixed an issue with handling tags when importing devices from file * Improved stability of the SSDP protocol * Improved the import function to handle incorrectly formatted data * General stability improvements * Updated UI help texts and help file to reflect the latest changes New features in 5.21.087 ============================== * Added the possibility to use a CSV-file, to add/edit/remove device user credentials * Added the possibility to use a CSV-file, set device credentials used by ADM Changes made in 5.21.087 ============================== * Moved firmware downloads source from FTP to PubAPI * Addressed a vulnerability in ZLib1.dll used by Firebird * Addressed an unquoted path vulnerability * Corrected encoding for UPnP user friendly names for new firmware revisions * Corrected encoding in Set configuration to handle parameters at URI in case of http-post * fixed 'Scrollbar missing' at certificate wizard when showing list of devices * Corrected sorting of Firmware such that firmware versions are sorted in the expected sequence * Corrected a client crash when replacing Q7406 with Q7436 * Wrong translation to French when installing ACAP New features in 5.20.082 ============================== * Now possible to add devices with credetnials via CSV file * Change default device connection protocol from http to https when adding new devices Changes made in 5.20.082 ============================== * T8705 firmware update timeout extended to allow successful completion * Excluded T8705 from restore point functionality to avoid ADM Server crash every night * Add port to device report also when port is 80 for clairty New features in 5.19.078 ============================== * Added LTS year to firmware options displayed * Introduced functionality for export and import devices Changes made in 5.19.078 ============================== * Fixed https so renew certificate does not switch to http * Fixed a crash when renewing client (802.1X) certificates * Fixed html error in one of the Help pages * Fixed a crash in set config * Fixed Server failure that occurred if Windows was not setup such that IP address 127.255.255.255 is a working loopback address * Fixed missing binding that caused exception under some circumstances when device configuration was chosen New features in 5.18.077 ============================== * Improved certificate handling with a new certificate wizard Changes made in 5.18.077 ============================== * Fixed an issue when all configuration parameters to be applied were not selected automatically * Allow multiple certificates to be installed by ADM on a device * Ensure a unique common name for the CA generated by ADM by appending the ADM Server hostname to the certificate common name Changes made in 5.17.071 ============================== * Fix of device password input to support white space and "paste". * Improved handling of adding newly factory reset device Changes made in 5.17.066 ============================== * Fix of import function using IP address instead of hostname, if IP address is intended * Fix failure of ’Set password’ for new or factory reset devices New features in 5.17.065 ============================== * Encrypt (RSA) device passwords in client RAM Changes made in 5.17.065 ============================== * Fixed an unhandled exception which delayed devices loading in the client * Fixed erroneous translation when starting certificate dialog * Changed default ports text in 'Add devices from IP range or from file with IP addresses' dialog from 80 to 80,443. New features in 5.16.063 ============================== * Added possibility to use username and password with both client and server proxy * Added handling of combined certificates Changes made in 5.16.063 ============================== * Fixed a crash when removing firmware that has been revoked by Axis * Removed the 'select all' option when selecting parameters to modify New features in 5.15.061 ============================== * Added possibility for user to disable 3DES cipher in ADM 5 installer * Updated text for promoting ADM Extend, Beta tag is removed New features in 5.14.059 ============================== * Added possibility to encrypt configuration file * On importing devices via a file, added support for finding devices via Hostname and importing tag information Changes made in 5.14.059 ============================== * PTZ Presets are now added in the same order as initially created * Display a warning dialog when downgrading AXIS OS (firmware) on a device * Added certificate status to exported device report * Fixed an issue which showed older devices IP as 0.0.0.0 * Fixed a broken link to ACAP information on Help page New features in 5.13.055 ============================== * Added 'Set Config' advanced configuration function Changes made in 5.13.055 ============================== * Improved new firmware notification * Closed port 55766 (not used by ADM) * Improved 'Warranty information' sign-in account credential handling * Security improvements implemented in client & server protocol Changes made in 5.12.053 ============================== * Upgraded to use .NET 4.8 * Device warranty info stuck in "pending" state * Fixed a crash in resource monitor (.Net & PerfLib error) * Fixed a crash when browsing for local firmware files * Fixed an issue with unexpected MAC/Serial numbers * Updated User Interface and Help file language support New features in 5.11.050 ============================== * Added support for Warranty information functionality Changes made in 5.11.050 ============================== * Addressed a scenario where ADM was unable to start due to port being locked Changes made in 5.10.045 ============================== * Fixed Server failure that occurred if no route to IP address 127.255.255.255 was available New features in 5.10.044 ============================== * Promotion of “ADM Extend” in “ADM 5” Changes made in 5.10.044 ============================== * Removed old bundled ACAPs New features in 5.09.042 ============================== * Added device model to Audit logs when removing revoked firmware. * Added support for firmware rollback functionality Changes made in 5.09.042 ============================== * Fixed selected device count that increased after a logout/login * Factory default of target device required for certain firmware downgrades New features in 5.08.039 ============================== * Added possibility to remove administrator group * Updated EULA * Added device port to address column in list users dialog * Added option to set serial number in lower case when configuring a device Changes made in 5.08.039 ============================== * Fix for FW revocation New features in 5.07.037 ============================== * Added IP List import functionality Changes made in 5.07.037 ============================== * Fixed a crash that occurred when the ADM server came out from power save mode * Fixed failure when adding thousands of devices * Improved robustness to firmware short comings regarding device parameter settings (M2025 etc) * Closed unused port 55766 Changes made in 5.06.032 ============================== * Fix to handle configuration function of certain devices without PTZ support (e.g. Audio devices). * Improved performance when creating the firmware list for the first time Changes made in 5.06.030 ============================== * Removing locally stored firmware files after they have been revoked by Axis. * Added PTZ Presets to both configuration file and replace device. Available in the additional settings tab. * User permission window does no longer pop up when double click on user. * Fixed a client crash that occurred when browsing for firmware files, after the previous folder location was removed. * A new information dialog is shown at startup when there is a new ADM 5 version available on Axis.com * Fixed firmware upgrade that sometimes failed when running on multiple servers. * Fixed a client restart issue when no network access to axis.com is available. Changes made in 5.05.021 ============================== Support for initial device access changes implemented in device firmware, starting on track versions 8.40.3 LTS, 6.50.4 LTS and 9.40.1 and progressing to as follows: * Firmware 1.65.x * Firmware 1.8x.x * Firmware 5.xx.x * Firmware 5.41.x * Firmware 5.51.x * Firmware 5.60.x * Firmware 5.70.x * Firmware 5.75.x * Firmware 6.50.x LTS * Firmware 6.53.x * Firmware 6.55.x * Firmware 7.15.x * Firmware 7.35.x * Firmware 8.35.x * Firmware 8.40.x LTS * Firmware 9.xx ACTIVE Track See also FAQ: https://www.axis.com/support/faq//FAQ116429 Changes made in 5.04.015 ============================== * Fixed a problem adding a device using “Add device using IP address” when the device communicated using http and using Basic authentication. * Fixed the help so it is shown properly in different non-English languages. * Fixed so it is possible to minimize and maximize Alarms & Tasks. * Fixed a bug affecting adding of devices with “https only” using discovery. * Fixed a bug affecting “Add device using IP address” and “Add devices using IP range” where devices are communicating with https and using Digest authentication. * Fixed a problem where http and https ports were overwritten in the database when using “Add device using address” or “Add devices using IP range”. New features in 5.04.010 ============================== * Improved support for installing combined Server/Client certificates Changes made in 5.04.010 ============================== * Updated the version of Firebird that is used for AXIS Device Manager’s databases, from version 2.5.7 to version 3.0.4. * Backups of the Firebird 2.5 database files are put in timestamped folder in the backup folder before upgrading the databases to Firebird 3.0 during upgrade from a previous version of AXIS Device Manager to version 5.04.010. * Firebird logs are now included in the System Report * Fixed a problem with “use hostname when possible” function when adding new devices to ADM. * Improved performance for tabs resulting in the faster opening and navigating between tabs. * Solved an issue where the server could crash during ACAP installation if the connection with the installation file is interrupted. This now shows an error. * Reduced server load when connecting a remote client. * Other corrections and stability improvements. * Validated support for Windows Server 2019. New features in 5.03.002 ============================== * Ability to configure IEEE 802.1X certificates to be renewed periodically by AXIS Device Manager: IEEE 802.1X can now use the Certificate Authority (CA) on the ADM server, i.e. it now behaves in a similar way to HTTPS. When a CA has been set up, enabling/updating IEEE 802.1X will result in new client certificates being created and signed by the CA, so it's no longer required to manually install client certificates before enabling IEEE 802.1X. The client certificates can also be automatically renewed in the same way as HTTPS server certificates. * Firmware API with LTS tracks: Now uses new firmware API for fetching the firmware list, and downloading of new firmware. In an online installation, it has an indication if it is LTS or active firmware track. * Collect Device Data: Presets have been added to the collect device data feature. This lets the user quickly gather data from commonly use sources. Changes made in 5.03.002 ============================== * Application version: The version number of ADM is now shown in the title bar of the service control. It is also shown when right-clicking the icon in the system tray. The notification popup now also contains the version number. * Fixed an issue where Client would stay minimized in Windows * Client and Server stability improvement * Windows Server 2008 R2 is no longer tested and no longer recommended. Upgrading to a more recent Operating System is advised. New features in 5.02.003 ============================== * Ability to configure Zipstream parameters in "Configure Devices" menu. * Ability to backup/restore Zipstream parameters. * Added support for upgrading to firmware 8.25 and above. Changes made in 5.02.003 ============================== * General stability improvements and corrections. New features in 5.01.005 ============================== * Added support for 21 languages: - UI + help files: English, French, German, Italian - UI only: Arabic, Czech, Chinese (Simplified), Chinese (Traditional), Dutch, Finnish, Japanese, Korean, Persian, Polish, Portuguese (Brazil), Russian, Spanish, Swedish, Thai, Turkish and Vietnamese. Changes made in 5.01.005 ============================== * Corrected an issue with CPU load increasing to 100% when network changed state. * General stability improvements and corrections. New features in 5.00.010 ============================== * AXIS Camera Management is now renamed AXIS Device Manager. * HTTPS, IEEE 802.1X & certificate management: - View information about certificates installed on devices. - Install and delete certificates from devices. - Configure and enable/disable IEEE 802.1X and HTTPS. - Use AXIS Device Manager as a Certificate Authority that signs server certificates for HTTPS. - Automatically renew HTTPS certificates when they are about to expire. - Validate the trust chain of HTTPS connections. - See full documentation at https://www.axis.com/products/axis-device-manager * Updated graphical user interface: - New Axis light theme - New tab navigation * Ability to use Hotkeys to navigate and perform actions. * Internal database split, increasing reliability and performance: - The database has been split into three files, located in the same directory: - ADM.FDB: containing the system configuration such as devices, tags, permissions... This is the main database. - ADM_RECORDINGS.FDB: Exists but not in use with AXIS Device Manager. - ADM_LOGS.FDB: containing log entries (Audit log, alarms and event logs). Changes made in 5.00.010 ============================== * Upon installation, new option to enable/disable sharing of anonymous usage data with Axis Communications to help improving the application and user experience. * Added support for AXIS T8507 Video Decoder. * General stability improvements and corrections. Know Limitations in 5.00.010 ============================== * Only English is available. More languages will be added in a service release in January 2018. * Certificate management in general: - All certificates in an install batch must have same passphrase. - Certificate operations over unencrypted channels, i.e. "Basic" are not supported. Devices should be set to "Encrypted & unencrypted" or "Encrypted only" to allow "Digest" communication. * HTTPS certificate management: - Non-default ports (other than 443) are not supported. - If a device has HTTPS active and an already-uploaded certificate only containing the hostname (i.e. not an IP address), limitations will apply. See full documentation at https://www.axis.com/products/axis-device-manager - HTTPS cannot be enabled on the AXIS T85 PoE+ Network switch series. * IEEE 802.1X certificate deployment: - AXIS Device Manager cannot generate or sign client or CA certificates. Is can only distribute client certificates to one or several devices as well as CA certificates if they have been imported beforehand. - For devices with several network adapters (such as wireless cameras), IEEE 802.1X can only be enabled for the first adapter, typically the wired connection. - Devices missing parameter "Network.Interface.I0.dot1x.Enabled" are not supported (e.g. AXIS P39 Series, T85 Series and T87 Video Decoder). - Importing a Certificate Authority (under Configuration tab > Security > Certificates) will only change the HTTPS certificate management behaviour. It has no effect on the IEEE 802.1X certificate distribution function. For more information regarding HTTPS, refer to our AXIS Device Manager HTTPS certificate management guide available at https://www.axis.com/products/axis-device-manager - Make sure the time on the Axis Devices is synchronized with other devices on the network (Video Management Software, AXIS Device Manager, other servers). Know Limitations in AXIS Device Manager ======================================= * Limitations related to Basic authentication are described in FAQ: "Is Basic Authentication supported by AXIS Device Manager?” at https://www.axis.com/support/faq/FAQ116385 * Dropped support of Windows Server 2012 R2 and lower Windows Server versions. (from v5.27 on) * Elliptic curves algorithms are not yet supported when performing certificates management operations. Upgrade considerations from AXIS Camera Management to AXIS Device Manager ======================================= * Upgrade from AXIS Camera Management 4 to AXIS Device Manager 5 is supported as a regular software upgrade. * Windows Server 2008 standard and Windows Server 2012 standard are no longer tested or validated. Windows Server 2008 standard R2 and Windows Server 2012 standard R2 SP1 are still supported. Best Regards, Axis Communications