INTRODUCTION: GOVERNANCE, PERFORMANCE, AND MODERNIZATION
OpenText Application Security 25.2.0 (Fortify) focuses on strengthening cryptography, modernizing APIs and deployments, reducing operational noise, and nudging enterprises off fragile legacy integrations. For CIOs, CISOs, and SDLC leaders, this release is about improving risk posture, CI/CD efficiency, and long-term platform strategy.
Stronger License & Infrastructure Security with Sha256
What it is
LIM now supports SHA1 and SHA256 (offline activation needed). From 26.4.0, only SHA256 will be supported.
Enterprise impact
Reduces cryptographic risk and future-proofs license/infrastructure communications.
Supports staged upgrades of mixed Fortify environments without downtime.
Day-to-day team value
Platform owners can upgrade LIM once, preserving backward compatibility.
Offline customers have clear activation procedures without ad-hoc hacks.
Kubernetes Deployment Modernization for SSC
What it is
Helm charts and values files removed from SSC ZIP; deployment now requires Tomcat 10.1 with clear documentation.
Enterprise impact
Standardized, supportable cloud/container deployments.
Easier alignment with platform engineering and audit policies.
Day-to-day team value
DevOps follows documented deployment steps.
Avoids trial-and-error migration issues, reducing downtime.
REST API PERFORMANCE WITH withoutCount PARAMETER
What it is
Paginated endpoints (e.g., /api/v1/activityFeedEvents) can skip computing total counts for faster responses.
Enterprise impact
Supports scalable automation in large environments.
Predictable API behavior for CI/CD pipelines and dashboards.
Day-to-day team value
Faster polling for activity feeds and issue lists.
Dashboards prioritize responsiveness over exact totals.
Stronger Governance Around Report Libraries
What it is
PUT updates to internal fields (fileDocId, guid, templateDocId) are blocked; use POST for replacements.
Enterprise impact
Preserves report integrity and improves auditability.
Reduces fragile integrations that could corrupt report metadata.
Day-to-day team value
Fewer mysterious report breakages.
Clear guidance for automation scripts: PUT for metadata, POST for files.
Clearer Authentication Events and Logging
What it is
Dedicated events for API token usage; bulk request logging consolidated.
Enterprise impact
Improved security monitoring and incident response.
Reduced noise in SIEM/audit logs.
Day-to-day team value
Easier troubleshooting for failed automations.
Analysts focus on meaningful events, not repetitive logs.
Log Rotation and Plugin Log Improvements
What it is
Logs rotate at ~10MB into logs/archive; plugin logs consolidated in ssc_plugins.log.
Enterprise impact
Predictable logging footprint simplifies SIEM/log shipper setup.
Easier retention policy compliance.
Day-to-day team value
Simplified debugging and incident response.
Fewer directories and logs to monitor.
OPENAPI 3 REST SPEC AND UPDATED fortifyclient
What it is
SSC REST API now uses OpenAPI 3; fortifyclient uses Apache HttpClient.
Enterprise impact
Standardized SDK generation and API governance.
Migration away from legacy Swagger 2 integrations.
Day-to-day team value
Auto-generate clients in multiple languages.
Modern HTTP client with consistent bindings.
ARM Support for SSC Server on Linux
What it is
SSC now runs on Linux ARM architecture.
Enterprise impact
Flexible, cost-effective, energy-efficient infrastructure planning.
Supports long-term modernization strategies.
Day-to-day team value
Deploy SSC on ARM nodes without exceptions.
Test performance and scalability across x86/ARM.
ScanCentral SAST Queue Control
What it is
replace_duplicate_scans=true by default; only one scan per application version in queue.
Enterprise impact
Reduces redundant compute and queue congestion.
Predictable SLAs for security analysis.
Day-to-day team value
Pipelines rerunning same version process latest scan request.
Retain control via -dr flag when needed.
Noise Reduction in Default SAST Policies
What it is
Low probability issues treated as low risk; filter clarity will improve in future releases.
Enterprise impact
Focus on high-impact issues for executive reporting.
Reduces overload of low-value findings.
Day-to-day team value
Developers/security engineers triage less noise.
Backlog grooming and sprints focus on actionable items.
ScanCentral DAST: New Composite Settings Format
What it is
DAST settings now packaged as ZIP; XML format deprecated.
Enterprise impact
Easier version control and artifact promotion.
Simplifies standardization across applications.
Day-to-day team value
UI-based import/export of single ZIP.
Automation developers use consistent, hardened reference files.
Strategic De-Support and Deprecations
What it is
Bugzilla plugin removed, CAS/Kerberos SSO removed, ALM/WIE deprecations, SHA1 phased out, Windows Docker images ending post-25.4.
Enterprise impact
Reduces integration risk and technical debt.
Encourages platform unification on Linux and modern protocols.
Day-to-day team value
Signals to stop building new flows on deprecated systems.
Supports preemptive retirement of unsupported components.
Conclusion: Strategic Impact
Risk management: SHA256, cleaner auth logs, deprecated plugin removal, supported SSO/containerization improve systemic security.
Operational efficiency: SAST queue control, lighter REST responses, modern API spec, predictable logging save time and reduce triage effort.
Strategic modernization: ARM support, Linux Docker images, Tomcat 10.1, OpenAPI 3 enable future-proof, governable SDLC.
MERITO VALUE-ADD:
Assess Fortify usage, gaps, and deprecations.
Design target-state architecture for SAST/DAST/SSC.
Implement and operationalize changes without disrupting delivery pipelines.
Next steps:
Platform Health Check: assess versions, integrations, deployments.
Modernize Integration Layer: adopt OpenAPI 3, DAST/SAST policies, SSC logging/auth.
Plan/Execute Legacy Migrations: retire ALM, WIE, Bugzilla, CAS/Kerberos, Windows components.



