IBM Support

Deprecated and removed features in IBM DataPower Gateway products

Question & Answer


Question

What features are deprecated or removed in versions 10.5 and earlier IBM® DataPower firmware? This document lists features that are deprecated in versions 10.5 and earlier of DataPower firmware. Features deprecated or removed in one release continue to be deprecated or removed in the current and later releases. Alternatives are provided, if available.

Cause

Due to evolving technology, the DataPower firmware is updated, which can change the required configuration of objects.

Answer


If a feature is listed as deprecated, IBM reserves the right to remove this capability in a later product release. A feature is generally not removed after announcement of deprecation until at least two major releases or one full year, whichever time period is longer. IBM reserves the right to remove a feature immediately when warranted. Migrate your existing configuration to use the alternative.


10.5 deprecated and removed features


10.5 deprecated features

Feature Alternative Additional information
10.5.1: Objects that integrate with IBM MQ servers that are not running version 9 or later. Use objects that integrate with IBM MQ servers that are running version 9 or later.
10.5.1: Conformance validator utility None
10.5.0.6 (10.5.1): WebGUI Use the new UI
10.5.0.3: The following gateway-peering properties.
  • The field to define the primary count, which determines whether peer mode or cluster mode.
  • The field to define peers in a peer group.
  • The field to define nodes in a cluster
  • The control to indicate whether to auto manage the nodes in a cluster.
  • The control to indicate whether to use TLS to secure connections among peers in the peer group or nodes in the cluster.
  • When TLS is enabled, the fields to define the identification credentials and validation credentials.
Where applicable, the property is moved to the gateway-peering group.
10.5.0.3: Send a test message tool Use a third-party application like Postman.

10.5 removed features

Feature Alternative Deprecated since version
10.5.4: WebGUI Use the new UI 10.5.0.6 (10.5.1)
10.5.2: Secure Gateway Client. None. 10.0.0.0
10.5.0.0: Blueprint Console. WebGUI or the new UI. 2018.4.1.18
10.5.0.0: XC10 appliance as a document cache. WebSphere eXtreme Scale as a document cache. 7.7
10.5.0.0: The b2bp-archive-purge-now command. The purge-b2bp-all and purge-b2bp-gateway commands. 10.5
10.5.0.0: The Archive-purge transactions action. Purge B2B Transaction Data action. 10.5
10.5.0.0: Microsoft Internet Explorer to access the DataPower GUI. Another supported browser. 10.5
10.5.0.0: Restrict a privileged user to specific domains. None. 10.5

10.0 deprecated and removed features


10.0 deprecated features

Feature Alternative Additional information
10.0.4: Rate limit API action Add a rate limit assembly action where rate limits use the limits defined in the API plan.
10.0.4: Extension Functions in XML manager None
10.0.2: Allow WebSocket upgrade in invoke assembly action Add a WebSocket upgrade assembly action to the assembly.
10.0.1.1: Restrict to HTTP/1.0 in invoke assembly action Use the HTTP version to server property to set the protocol version. When set to HTTP/2, whether to require HTTP/2.
10.0.1.1: Restrict to HTTP/1.0 Policy in User Agent HTTP version policy
10.0.0.0: Suppress identical events for a defined duration in a log target. None
10.0.0.0: Secure Gateway Client None
10.0.0.0: Cloud Gateway Service None
10.0.0.0: Cloud Connector Service None

10.0 removed features

Feature Alternative Deprecated since version
10.0.4: Extension Functions in XML manager None 10.0.4
10.0.0.0: Set syslog-ng as the log target type. Use syslog-tcp. 5.0
10.0.0.0: Debian firmware images for DataPower for Linux. None 10.0.0.0

2018.4 deprecated and removed features


2018.4 deprecated features

Feature Alternative Additional information
2018.4.1.18: Blueprint Console WebGUI Although Blueprint Console is the only GUI where you can create and manage service patterns, pattern-management is not available in the WebGUI. When Blueprint Console is removed, removal includes pattern management.
2018.4.1.8: Integration with Federated Identity Manager. None End of support for IBM Security Federated Identity Manager is 30 September 2019.
2018.4.1.8: Set the WebSphere Service Registry and Repository (WSRR) server version in the GUI or with the WSRR Server server-version command. Based on the supported version of WSRR, this property no longer has a purpose.
2018.4.1.7: All public certificates that DataPower provides in the pubcert: directory. Request and upload any public certificates that you require.
2018.4.1.7: GatewayScript fibers module None You can use a generator to manage asynchronous processes in a synchronous manner. However, the use of a generator is not an alternative.
2018.4.1.5: Authentication for incoming API requests in the API basic authentication security definition or in the user security assembly action. Configure an API basic authentication security definition or a user security assembly action to use an existing user registry configuration for authentication. The supported registries are API LDAP and API authentication URL. If you encounter problems, you must reconfigure one of the following objects to use a supported registry configuration.
  • Any API basic authentication security definition.
  • Any user security assembly action.
2018.4.1.4: The compatibility mode property for the API Connect Gateway Service. Migrate your API Connect integration to use the API Gateway service instead of the Multi-Protocol Gateway service. For more information, see the API Porting Notes wiki. When the compatibility mode is set to V5, the DataPower service used is the Multi-Protocol Gateway. When not set to V5, the DataPower service used is the API Gateway.
2018.4.1.1: Key and certificate aliases for a gateway-peering instance. Edit the configuration for each gateway-peering instance to assign identification credentials that reference the required key and certificate aliases.
Support for IBM Security Access Manager 8.0.x Upgrade to a supported version of IBM Security Access Manager. End of support for IBM Security Access manager 8.x is 30 September 2019.

2018.4 removed features

Feature Alternative Deprecated since version
2018.4.1.9: The common ntp that identifies an NTP server. Use the ntp-service command to enter NTP Service mode to identify an NTP server and set the interval between clock synchronization. 7.2
2018.4.1.8: Set the WebSphere Service Registry and Repository (WSRR) server version in the GUI or with the WSRR Server server-version command. None. 2018.4.1.8
2018.4.1.7: All public certificates that DataPower provides in the pubcert: directory. Request and upload any public certificates that you require. 2018.4.1.7
2018.4.1.5: Authentication for incoming API requests in the API basic authentication security definition or in the user security assembly action. Configure an API basic authentication security definition or a user security assembly action to use an existing user registry configuration for authentication. The supported registries are API LDAP and API authentication URL. 2018.4.1.4
The user option from the Access Level property of the User Account configuration. To restrict user accounts to specific domains, create the users as group-defined. Then, modify the access profile of the group to restrict domain access. 6.0.0
Configurations that associated with the IBM Security Access Manager Proxy Module None 7.7 - End of support for IBM Security Access Manager for DataPower Appliances was 30 September 2018.

7.7 deprecated and removed features


7.7 deprecated features

Feature Alternative Additional information
Delete quota enforcement keys with the Global ratelimit delete command. Use the appropriate command in Quota Enforcement mode.
  • The delete concurrent command
  • The delete count command
  • The delete rate command
  • The delete tokenbucket command
Generate SNMP Engine ID in SNMP Settings None A unique engine ID is created automatically on all platform except DataPower Gateway for Docker. For this platform, define the seed text to generate the engine ID.
IBM Cloud™ Product Insights None End of support for IBM Cloud™ Product Insights is 13 May 2018.
Support for IBM Security Access Manager 7.0.x Upgrade to a supported version of IBM Security Access Manager. End of support for IBM Security Access manager 7.0 is 30 September 2018.
IBM Security Access Manager Proxy Module None End of support for IBM Security Access Manager for DataPower Appliances is 30 September 2018.
XC10 appliance as document cache WebSphere eXtreme Scale The end of support for the XC10 appliance is 30 June 2019.

7.7 removed features

Feature Alternative Deprecated since version
Delete quota enforcement keys with the Global ratelimit delete command. Use the appropriate command in Quota Enforcement mode.
  • The delete concurrent command
  • The delete count command
  • The delete rate command
  • The delete tokenbucket command
7.7
Firmware images for DataPower Gateway for Citrix XenServer None 7.7
Generate SNMP Engine ID in SNMP Settings None 7.7
IBM Cloud Product Insights None 7.7

7.6 deprecated and removed features


7.6 deprecated features

Feature Alternative Additional information
Predefined DataPower service patterns None

7.6 removed features

Feature Alternative Deprecated since version
Restart the default domain. Reload the firmware on the DataPower Gateway. If you attempt to restart the default domain, a notice is displayed. 5.0
Predefined DataPower service patterns None 7.6
The scrypt4 firmware images on IBM Fix Central to upgrade a virtual XG or XI to version 7.6. To upgrade a virtual XG45 or XI52 to version 7.6, you must first use a migration tool from Fix Central to convert the virtual XG45 or XI52 to a virtual DataPower Gateway. Refer to Migration of a virtual DataPower SOA appliance to a virtual DataPower Gateway 7.6

7.5 deprecated and removed features


7.5 deprecated features

Feature Alternative Additional information
The Halt system mode for the Shutdown action and the halt parameter with the shutdown command. Use the Power off system mode or the poweroff parameter with the shutdown command.
The smtp protocol identifier to connect to remote SMTP servers. Use the dpsmtp or dpsmtps protocol identifier.
Support for Tivoli Access Manager (TAM) 6.0, 6.1, 6.1.1. Upgrade to a supported Access Manager version. IBM no longer supports the cited versions.
The Verify property and the verify command in the configuration of a Signature Identifier. None. When removed, the action always runs as expected. When disabled, it always bypasses signature verification. In other words, you always want this property to be enabled.
Sysplex Distributor Target Control Service None.

7.5 removed features

Feature Alternative Deprecated since version
Support for Tivoli Access Manager (TAM) 6.0, 6.1, 6.1.1. Upgrade to a supported Access Manager version. Deprecated in 7.5.0, and removed in 7.5.2.

7.2 deprecated and removed features


7.2 deprecated features

Feature Alternative Additional information
GatewayScript methods for context variables:
  • The getVar() method
  • The setVar() method
GatewayScript methods for context variables:
  • The getVariable() method
  • The setVariable() method
For service variables, use the getVar() and setVar() methods.
The alias command
Load balancer groups LDAP and IMS Connect health checks Load balancer group TCP health check The TCP health check has all of the same capabilities of the LDAP and IMS Connect health checks.
File names: The ability to create and upload files that begin with a period "."
SSL Proxy Profile and Crypto Profile Use SSL Client Profile, SSL Server Profile, and SSL SNI Server Profile For more information, see Migration from SSL Proxy Profile.
Password Password Alias For more information, see Migration from passwords to password aliases.
Support for UDDI Registry and UDDI Subscription Use WebSphere Service Registry and Repository (WSRR) Use WSRR Server and WSRR Subscription objects as the alternatives for UDDI Registry and UDDI Subscription
On the System Control page, the Generate Device Certificate action Use the Crypto keygen command to create key and cert for the device. Then, create an SSL Server Profile, which can be configured in the management interfaces. Refer to the documentation on how to change the security settings on web management interface and the XML management interface.
The ntp command that identifies an NTP server. The ntp-service commands Use the commands in the ntp-service command mode to identify an NTP server and set the interval between clock synchronization.
Support for 1 K (1024 bit) or smaller RSA private keys within the HSM Do not store any 1 K or smaller RSA keys within HSM. Delete existing 1K or smaller keys and replace them with larger keys, for example with keys that are 2048 bits or greater. You might need to replace the associated certificates. Deprecation of 1 K or smaller RSA private keys is in accordance with the NIST recommendation.
Integration with IBM License Metric Tool Manually track subcapacity licensing.

7.2 removed features

Feature Alternative Deprecated since version
WSRR server versions
  • 6.0
  • 6.1
  • 6.2 - 7.0
WSRR supported server versions 6.0.0
The icon for the XSL Accelerator services was removed from the Control Panel. Migrate to a Multi-Protocol Gateway. 7.0.0
Integration with IBM License Metric Tool Manually track subcapacity licensing. 7.2.0 fix pack 11

[{"Type":"MASTER","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"ARM Category":[{"code":"a8m50000000L0rqAAC","label":"DataPower"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
17 April 2024

UID

swg21634531