Dear Valued Partners,
BioStar 2 version 2.9.12 is now available at the Suprema Download Center.
This release replaces BioStar 2 CLOUD with the new Remote Access feature and strengthens system security.
It also adds support for BioStation 3 Max and XPass Q2, and supports deleting device event logs.
[Important] BioStar 2 CLOUD Support Discontinued End-of-Life Notice: BioStar 2 Cloud Feature and FAQs BioStar 2 v2.9.12 discontinues support for BioStar 2 CLOUD. To access the BioStar 2 server from an external network, use Remote Access. See 1. Remote Access.
[Note] FaceStation F2 v1.x.x Firmware Support Discontinued BioStar 2 v2.9.7 and later do not support FaceStation F2 firmware v1.x.x. If you use FaceStation F2 v1.x.x, upgrade the device to the latest firmware. The latest firmware is available at the Suprema Download Center.
1. Remote Access
Remote Access replaces the BioStar 2 CLOUD feature. It lets you access the BioStar 2 server from an external network through the ngrok tunneling service. No firewall settings or port forwarding are required.
When to use Remote Access
- You need to connect to the BioStar 2 server from an external network.
- Firewalls or NAT prevent a direct connection.
- You want to set up remote access without complex network configuration.
- You need to provide temporary outside access.
License
- Remote Access requires a BioStar 2 Remote Access license. This is an annual subscription license.
- When you purchase the license, Suprema creates a bot account, an endpoint, and a license document on the ngrok Suprema site.
Before You Start
Enable the Unified Gateway setting. [BioStar 2 > Settings > Security]
The services available through Remote Access depend on the Unified Gateway setting.
Unified Gateway | Accessible services |
|---|---|
Active | All services |
Inactive | Access Control service |
Setup
- Activate the license: [BioStar 2 > Settings > License] Enter the admin name and Remote Access license key in Remote Access, and then click Activate.
- Enable Remote Access: [BioStar 2 > Settings > Remote Access] Set Remote Access to Use in the Remote Access with ngrok section.
- Enter the ngrok informationprovided by Suprema:
- Authtoken: The authentication token.
- URL: The endpoint URL, in the format
https://desire-subdomain.bs.ngrok.app.
- Click Apply. If a warning message appears, review it and click Agree.
- From an external network, open the endpoint URL and confirm that you can access the BioStar 2 server.
[Note] The subdomain can contain only English letters (A–Z, a–z), numbers (0–9), and hyphens (-). Special characters and spaces are not allowed.
[Important]
- The BioStar 2 API does not support Remote Access.
- Remote Access uses ngrok, a third-party tunneling service. The security and continuity of the connection depend on the ngrok service. Before using this feature, review the Remote Access Feature Agreement.
- If you cannot access the endpoint URL from an external network, contact the sales point or distributor that issued your license.
For details, see Setting Remote Access in Suprema Docs.
2. Security Improvements
BioStar 2 v2.9.12 addresses security vulnerabilities in the system and in Time & Attendance (T&A).
System
- Applied HTTP security headers to the web server.
- Enhanced the encryption method for database connection passwords.
- Updated internal libraries to address Java server security vulnerabilities.
- Enhanced password security on the Directory Integration page.
- Improved access permissions on the User List page.
- Improved SQL Injection vulnerabilities.
- Updated the Open JDK version.
Time & Attendance
- Fixed a vulnerability related to URL exposure and unauthorized access during PDF export.
- Updated the Minimist library to address security vulnerabilities.
- Enhanced the database password encryption method.
[Note] When upgrading to v2.9.8 or later, BioStar 2 shows a popup message that recommends deleting unnecessary Redis for enhanced security.
3. Other New Features and Improvements
New Device Support
BioStar 2 v2.9.12 supports the following new devices:
Device Event Log Deletion
Administrators can delete device event logs in BioStar 2.
Event Logs from BioStar X Firmware
BioStar 2 correctly displays new event logs from devices that use BioStar X supported firmware.
Exclude from Synchronization on Upgrade
When you upgrade from v2.9.8 or earlier, BioStar 2 automatically applies the Exclude from Synchronization setting to existing users during the first synchronization.
Bug Fixes
BioStar 2 v2.9.12 includes the following main fixes:
- Fixed Time & Attendance reports not generating correctly because of an authentication log synchronization failure.
- Fixed an issue where non-admin users could access other users' report filters through the API.
- Fixed anti-passback not working when the same device was configured for both a Muster zone and Global Hard APB.
- Fixed the server failing to start because of a database out-of-memory error when many Audit Logs exist.
- Fixed server memory usage that kept increasing after transferring many users with Transfer To Device.
- Fixed all users being synchronized from Microsoft Entra ID when only specific user groups were selected.
- Fixed user profile photos not displaying after enabling Encrypt Personal Data on Database.
For the full list, see BioStar 2 v2.9.12 Revision Notes.