Layer7 API Security

 View Only

Layer7 Work in Progress Update - PI24

By Gregory Thompson posted Dec 17, 2020 09:35 AM

  

As part of our effort to keep our customers up to date and get continuous feedback, we will begin providing updates on our development work in progress for each Program Increment (known as a "PI") here in the Layer7 Community. We invite you to provide feedback by commenting on this post below. The key capabilities currently being worked on in this PI (PI24) are:

API Gateway

  • MySQL 8.0 backport for SSG DB for GW 9.4 (Only Software GW and Container) - allows customers to continue to use the software and container versions of API Gateway 9.4 with MySQL 8.0 to ensure a fully supported DB is available.
  • Support kerberos authentication with compressed kerberos ticket - allows support for compression of kerberos tickets to improve bandwidth usage
  • Upgrade to CCJ 3.x - upgrades the API Gateway's Crypto Comply Java library to version 3 to provide up to date encryption support.
  • Upgrade to Java 11, Spring 5.3+ and Hibernate 5.x - updates key platform libraries within the API Gateway to move away from older versions that will be end of service in near future.


API Portal

  • MySQL 8.0 Support for Portal DB - allows the API Portal to support MySQL 8.0 to ensure a fully supported DB is available.
  • API Hub: OKTA integration - provides the ability for API Hub users to support an SSO experience as part of the SaaS Layer7 API Portal offering
  • Differentiate Consumer Org from Publisher Org - securing the access of organization users by restricting API management activities (e.g. managing organization of the API, attaining the Org Publisher role) to Publisher organizations only
  • Filter Users by Organization - allows admins and organization admins to filter the list of users by organization
  • Improve automatic API sync  - optimizes the sync of APIs between the portal and gateway to provide a more reliable & robust sync 
  • Improve Gateway published API sync - optimizes the sync of APIs to the API portal for gateway-published APIs
  • API for querying deployment status - a new API as part of the Portal API (PAPI) to provide details on the deployment status of APIs to improve troubleshooting of API sync inconsistencies

Note that some larger capabilities may span multiple PIs and, as always, plans are subject to change based on a number of different factors.

Candidates for PI25
While the capabilities to be included in PI25 are not yet set, please see below for a list of candidates being considered. Of course, not all of these will fit and we will select a subset of these based on your feedback. We'd love to know if there is a capability in the list you are eagerly awaiting and/or plan to use. We also would love to know if there is something missing from the list that is important to you. Please comment in the comments section below with your feedback.

API Gateway

  • JDK 11, Spring and hibernate 5 updates for remaining APIM components like OTK, portal assertions, integration testing.
  • Headless Install Updates for Siteminder and Precision API Monitoring
  • Policy plugin updates
  • Policy Manager on Popular OS (Ubuntu, MacOS, Windows)
  • Oracle Access Manager 12c
  • IBM Access Manager 9
  • Headless Install Updates for Siteminder and Precision API Monitoring
  • Websockets support for HTTP using same port
  • Ephemeral Gateway
  • Custom Assertion SDK Updates
  • Common Criteria Certification

API Portal

  • API Hub Page Enhancements for viewing apps with multiple keys
  • Workflow for API key creation/edit
  • API Portal support for Environmental Gateway Bundles
  • API Portal for “service” type gateway bundles
  • Optimize API sync for SOAP services
  • Support for multiple-level organization to improve API manageability from parent organizations
  • Portal Doc Improvements for HA/DR
0 comments
24 views

Permalink