Video: Rocket Customer Webinar: Rocket® PASSPORT® Lifecycle | Duration: 3240s | Summary: Rocket Customer Webinar: Rocket® PASSPORT® Lifecycle | Chapters: Introduction and Housekeeping (32.3s), Agenda and Disclaimer (101.99s), Historical Acquisition Background (172.82s), Rocket's Customer Focus (243.415s), Secure Host Access (355.845s), Product Tiers and Security (556.005s), Secure Host Access (1392.91s), Product Lifecycle Management (1957.555s), Zero Footprint Client (2666.73s), Web-Based Solution Benefits (2730.025s), Scaling and Deployment (2852.985s), Self-Healing Enterprise Solutions (2965.125s), Evaluation and Roadmap (3040.025s), Future Product Roadmap (3090.23s), Concluding Remarks (3188.81s)
Transcript for "Rocket Customer Webinar: Rocket® PASSPORT® Lifecycle": Think we've got a lot of good stuff to show you, and I'm excited for the conversation that we'll have. But a little housekeeping, we want this to be an engaging and insightful session. If you have questions, please go ahead and drop them into the chat, into the q and a panel. I'll be keeping an eye on it so we can bring them to Chris and Barbara so we can get answers during the session. Wanna make sure they're brought up when it's it's relevant to to what you're asking. But otherwise, there is a email address a little bit later in the in the session, rocketconnectivity@rocketsoftware.com. It is basically Chris and Barbara on the back end, but it is another way for if you have a question that you don't necessarily wanna bring up here or maybe just think about something that you wanna pass along. So it's a way that you can reach us quickly and and get your your questions answered. So with that, I think I'll go ahead and hand things off to Chris to to kick us off. Sounds great, Evan. Thank you very much for that introduction and also thanks everybody for joining today. Quick overview of the agenda. So we're gonna talk about some historical background in the terminal emulation market first, how we got to where we are. The path forward is going to be a product called secure host access. That's why we're convening today. We'll talk about that a bit. And then the product life cycle. So customers can plan on, you know, how and when to upgrade to future releases of secure host access. And then talk about our commitment to you, how we're gonna support you in this going forward, in this journey going forward. And we'll take questions during and after the session. So with that, let's talk a little bit about oh yes, the disclaimer. The disclaimer. So basically, we're gonna talk today a lot about kinda some, you know, go forward plans with regards to our rocket products. And some of this information could change in the future. Not sure. We're doing everything we can to make sure what we tell you today is accurate. If you'd like to read the full presentation disclaimer later, this will be recorded and you will be able to take a closer look at everything in this presentation. Alright. So the historical background, kind of fun to look back. You know, I've been involved in this industry for I don't know how many years now, thirty plus years. And never a dull moment, probably similar to, you know, if you look at the merger acquisition activity of many companies, probably the companies you work for, you probably could draw a similar road map or map or journey, if you will. But you you see yourself here probably if you're a Passport customer that was developed by a company called Zephyr. And that is in that second company down just below Seagull, as you can see, acquired by Rocket in the 2020, 2021 time frame. And then all these other corporate acquisitions. Right? Very interesting sort of history here with some of the other companies, heritage companies. So Barbara and I have been around for a while. Like I said, we started with a company called Attachmate back in the early nineteen nineties. So we've seen a lot of change in the industry. We've seen a lot of great stuff happen, and we're excited to share what the go forward plan is today. Alright. Let's let's throw it over to Barbara and talk about some of our values. Can we do that, Barbara? We can obviously. Yes, Chris. Chris and I came over as he said from the attachment days thirty some odd years ago. I was only 10 so we'll make sure we get that out there. With the transition to Rocket, Chris and I have been through a lot of companies as you saw on the historical slide and I just wanted to share a little bit about my journey. I know that you're Passport customers, so I know you've been with Rocket for a while, but you know there was an acquisition and so you moved vendors from Zephyr, if you will, to Rocket Software. I just wanted to say that I am thrilled to be a part of Rocket, and I really feel like Rocket is very customer focused. That's part of why we're talking here today. We want to share with you a journey that we're going on. We think there's going to be a lot of value here for you, but we also understand that change is hard. Our values say that we want to be transparent with you, but we also want to do the right thing. Throughout this presentation, that's exactly what we're going to do. And with that said, we're also gonna give you a way to communicate with us. So Rocket is a very customer focused company and so are Chris and I from a product management perspective. The closer that product management is to their customers, the better products that they turn out. So so that's why we wanted to share that little bit with you that we're we're happy to be with Rocket. We're happy that you're Rocket customers, And now we're going to share our journey of where we're going and how it affects you as a Passport customer. With that said, let's chat a little bit about the path ahead. So what we've done with a product called Secure Host Access that we're going to dig into a little bit is lifted terminal emulation out of its core green screen access space and moved it into a security solution that makes sure that you can have secure access to those host applications. What do I mean by that? Well, if you look at these statistics on the slide, and I'm not going to bore you with statistics, it's all about how many breaches and how are they getting in and what it's going to cost you. But what I really want to draw your eye to is that middle black 71%. About thirteen years ago, I think it was, it was in 2013, so yep thirteen years ago, one of the very first breaches was the OPM breach. That was in The US. OPM is a large federal government agency, stands for the Office of Personnel Management. That was one of the first breaches that really brought about the fact that compromised credentials, users' credentials are being used in a nefarious way. They are being used to access data that the organization that has the data doesn't want them to. It's really that simple. In the OPM breach, I'm a veteran and my information was shared. This was personal to me, but it was also professional because out of the OPM breach, that's when we started seeing the mandates change. And in respect to that breach, a US federal mandate came out fairly fast after that breach that said if you're doing business in the federal government in The US, you cannot use usernames and passwords anymore. That was called HSPD twelve. And my customer who is in the federal government, this was back when we were AttachMate, they came to us and they said, you know, Barbara, we have this new mandate and know usernames and passwords pretty easy to handle out there in the enterprise, but it's not so easy to handle on the mainframe. What are we going to do? And that's where this product was born and that's where the journey started and I'm going to show you where we are today about helping you add layers of defense in-depth between who we hope is an authenticated and authorized user but may not be and your crown jewels that sit on your host system. Rather that be a Z mainframe or an I series, even a Lennox box you're attaching to with VT, could be a Unisys host, we got a few of those out there, airlines host, could even be an HP nonstop host. So we've been at this for a while. It has really gone to where it's not just a terminal emulator anymore. It really is about security and it really is about fitting that terminal emulation solution, your host access solution, into the ecosystem of security that we're living in now. I've kind of set the stage. Chris is going to talk a little bit about how the product is tiered and what you get with that, and then he's going to come back and I'm going to show you what it would look like in your organization. Chris, we cannot hear you. We still cannot hear you. Just got a lot of technical difficulties when you're live, and we'll see if he can pick back up but if not I can cover his slide. Okay you just muted so that's good. You are now muted in the platform Chris if that helps. Okay so now you are unmuted in the platform and we can still not hear you. While Chris works on that, let me cover this slide for him just a little bit. Chris, you're free to interrupt me when you have a voice. So Chris said goodbye. He'll be back, I'm sure. This product, unlike your terminal emulator today, is one product that comes in three tiers. What do I mean by a tier? So the basis tier, the, the professional tier, the secure host access pro is really the desktop client that you're used to. You use Passport today. Now I will tell you, I am familiar with Passport. I actually own Passport as a product manager, but I'm not necessarily sure what all of you have. So there was a thick client and there was a thin client, and then you could have both. So so I'm gonna speak to all of that. So this would be comparable to your thick client of Passport. Chris is back. We're going to see if he has a voice. You're muted on the system. That would be your thick client that that pro tier is equal to. So then the next tier up so again, one product, three tiers. Middle tier is going to add some security to that thick client. It's gonna allow you to manage it. It's gonna allow you to hook into your IAM. I'm gonna show you that in a little bit so you can use enterprise credentials and your authorization schema in your enterprise to make sure that that end user is who they say they are and they're authorized. That's what we give you in the enterprise. In Anywhere, the difference there is we also add a thin client, a web based client that is the zero footprint, so no dependencies on the desktop. Now what I want to follow-up here really quick is those top two tiers have centralized management. So you can manage either of those on the anywhere. You can manage both thick and thin, and on enterprise you can manage thick. In both of those also, and I'm going show you how this works in your environment here in just a second, but you also get the single sign on capabilities. So we have some single sign on capabilities for any host based system, and both of those tiers include that as well. So, obviously, if you're in the enterprise tier, you wouldn't have a thin client, so that would only be for thick. If you're in the anywhere clear, that single sign on would be for both thick and thin. So Alright. And I think we're gonna go back and look at a market texture diagram here. Nope. Before the market texture diagram, we're gonna tell you a little bit about the product. So we're aiming really there's this product a lot to this product. Right? And I could talk about it all the day long, but Evan won't let me. I'm really trying to hit sweet spots here. It is aimed to help you in two ways or solve two problems at the same time, if you will. The left hand column is really talking about integrating your enterprise IAM. Think about how you log into your Windows system and then did all your other applications other than your green screen application today. So you probably do that through it could be like Okta. It could be Intra ID. It could be Ping Identity. Those are all vendors that have IAM solutions. And we don't support specific vendor. We support specifications. So we can integrate via SAML OIDC. We support Kerberos. So the whole plethora of authentication types. And it's good that we're specifications based because that means as you move, we'll move with you. On the right hand side of this screen, it is talking about regulatory compliance. We're kind of, and I'm sure you know this, in a new era of mandates. They've really been just coming across like crazy here in this last twelve months. They've been adding new ones to what we're used to. An example of that is NYCRR regulatory requirement. That is for if you're doing business with the state of New York, you have to use multi factor authentication. DORA is now requiring multi factor authentication. PCI DSS is now requiring multi factor authentication. So, either we're getting new mandates, which there are several, but we're also seeing the mandates that we've always been used to move from a best practices to a mandate. One of those, by the way, looks like HIPAA is going to flip by the end of the year. That's what we're seeing on the horizon, if you will. The other thing I want to mention along security lines, just so that we're all on the same page, is we have some new threats that we're needing to understand as organizations on how to mitigate, how to thwart, how to make sure that they don't impact you. These are a little bit larger than the normal user ID and password. And there's still plenty of those. I think if you saw on that one slide, just year over year from '23 to '24 there was an 81% increase or 71% increase so it's still happening all the time. But we have this new fake workers. That's kind of a new concept not talked about a lot because a lot of people don't want to admit that they've been subject to that, if you will. What it ends up being is this farm of laptops or servers that are making themselves look like employee candidates for organizations to hire and they aren't who you think they are. Can be done in a lot of ways. It could be somebody impersonating somebody, but it also can just be that you hire somebody and then they sell their credentials off to somebody else. It's quite in-depth. It's really kind of an interesting threat. And then AI. We all love AI. Everybody's asking to develop an AI. Everybody's asking me, Gosh, what are your products doing with AI? AI is going make us all better at our job. And I completely agree. AI is already making me better at my job, but it's also going to make those threat actors better at their job. Tomorrow's going to bring on new things for us because the threat actors that are out there today are going to be better. I will tell you, I am sure we're going to get more threat actors because now they have to know how to code the solution. They can get that through AI. Just putting this out there for mainframe organizations who think nobody could hack a mainframe because they don't know what to do when they get in there, AI is a game changer. There's new threats upon us and so that's really why we're introducing secure host access. So now let's take a look at how it would fit in one's organization. And I'm talking to you as Passport customers so that you kind of get an understanding of what the benefits you would get by using Secure Host Access and also what is similar to what you have today. So again, one product, three tiers. So the pro tier or the baseline includes a terminal emulator like you're used to today with Passport desktop, Passport PC to host, I think is what they call it. That's a thick client that you install on Windows, so we certainly have one of those. But we also have that HTML zero footprint client. You launch your emulator like you always do, like you do today, but in Secure Host Access we can configure it to integrate with your IAM. What do I mean by that? What I mean by that is when I launch my emulator I have to go through my IAM. I have to be authenticated rather that is through challenging for credentials or through single sign on. I am validated as an authenticated user in my IAM, and then we go off to the user directory to make sure that you're authorized to get a green screen connection. And if you cannot pass both of those steps, you will not connect to the mainframe. So there's more security right there, and that's what I'm talking about with these layers of defense in-depth. I'm adding two things there, two more things in addition to what you already have on the mainframe. So I'm checking you with your authentication and your authorization in the enterprise. Now, we do much more than that. And by the way, when we go back to mandates, when we think about that, if you're still using a user ID and a password on the host, and I know you don't want to admit that, but a lot of people are and that's just the way it is because it's hard to change, Right? So I get it. We we don't think it's secure. That's not what it is at all. But it's it's hard to change things, and it's hard to change things especially in the mainframe organization with end users needing that critical data. So and I'm gonna speak to that in a minute. But that would mean you have no multifactor authentication in your path to the host. So by adding this IAM checking and if you use multi or two factor authentication in your organization in the front, in the enterprise, then you are adding that. You'll be able to prove to an auditor that you are requiring two factor authentication prior to getting to the host. So I'm moving on. Here's the real secret sauce. There's two places that secret sauce here is this IAM integration. That's really important. But the other thing that we can do for you to boost your security as well as alleviate some pain points is we can automatically sign you in to your mainframe. And we can do that for any of the host types. I'm going to stick with mainframe here because it's easier to just stick with one host type. We need a trusted component on the mainframe. The one I would recommend on Z is ZMFA sold by IBM And in that case, we can have a trusted relationship with ZMFA, and ZMFA will trust our server so that we can map an ID from the enterprise to the user ID in, let's say, RACF, but it could be ACF two or Top Secret. And we will map that and sorry. On behalf of that end user, we'll go to the host and we'll say, I'd like to authenticate Bob at RACF, and the mainframe will look them up in all the same ways they typically would because this is mainframe security, not us. And he's cleared all the hurdles there, so we're gonna let him in. But this time, instead of using a username and a password or being diverted to a web page to copy a token, we will actually pass that token back in an automated fashion, and the user will be automatically signed in. I'm hoping you're painting a picture in your head. This is the picture I want you to see. Yesterday, you opened your bra your, emulator. You supplied an IP address and a port and probably some encryption and you got to the host and then you had to log in. And yes, it was probably with a user ID and a password. With Secure Host Access, all of those promptings for credentials go away. We're able to check you at the enterprise credential level. You may be single sign on into that if it fits in your organization, and we're gonna single sign on you into the mainframe as well. So now we have a user with a great user experience, and we have far more security because we have ups the game. We have added layers of defense in-depth. We have authenticated them in two different fashions, and we have issued, most likely, two different one time codes to get in. Doesn't really get much better than that. There's no silver bullet, but this is pretty impenetrable for today until AI takes over and makes me do something else. Is the solution that is really about Secure Host Access. So now let's talk a little bit about what does this mean for you. The first thing I'm going to say is as my Passport customers, you have not had updates to your emulator, rather it's thick or thin, for quite some time. I believe the last passport release was somewhere in the neighborhood of 2018, 2019, maybe as far as 2020, but it's been a long time. With the new desktop client, if that's what you're interested in and most of this is in the thin client as well. You get TLS 1.3. You don't have that today with Passport. You get data redaction. This is really cool and privacy filters. This is our way of redacting on the screen because let's talk about a credit card number. Not everybody in your organization should see the credit card number. Not everybody in your organization should see all the fields that are customer PII some form of PII. We have ways not only to redact that information, but we also have ways to roll that out to specific groups or users so that it's done based on their role in the organization. Because we constantly ship, we are on an agile framework. We ship every three months. Security vulnerabilities are always addressed on third party components. Can you hear me now, by the way? Okay. Great. Yeah. Okay. Thank. We have a regular cadence of security patches, and we're always there to have your back. So should a log four j happen, we're right there for you. Productivity. So I don't believe you have this in Passport either. We have Office compatibility and that's really kind of cool because you actually have a spell checker and you have autocomplete. But what's really, for me, I think is really beneficial is you have a screen history and a scratch pad so that you can easily use things for training and understand where you've been without necessarily navigating the screens on the host. From an automation perspective, we support VBA. That's very, very powerful. Dot net API, very powerful. I'm sure you had Halopi in Passport, so we have some great tools there. And of course, unlike Passport today, you have a robust go forward roadmap. So let's go ahead and go to the next slide and I'm going to talk a little bit about the enterprise and anywhere level. In those tiers, we offer you this SSO to host based applications. Remember, I talked about the mainframe here but we can really do it to any host. We have an MFA for the I Series right here at Rocket. We can connect to that. We can do a lot of things there. We support OIDC as well as SAML. A lot of people are using that today. That's kind of the new foundation of intra ID. We're always adding specific protocols so that we can integrate with any IAM out there. That's really important. We're keeping up with what all the IAMs are doing so that we're vendor agnostic. We also, for authorization, just added claims based authorization. So if you're using SAML or OIDC, we can actually figure out your authorization. Are you allowed to connect through your claims in that token that you pass around with SAML and OIDC. From an administrative perspective, we have multiple deployment models. We have a software appliance that you just load up into your virtual process, whether that be VMware or anything else. We have a standard Linux install, and then we are containerized. So we are containerized and orchestrated inside of our black box, but we also have a version of the product that you can deploy in your own orchestration tool. So think cloud. Right? Think if you're gonna deploy in a in an you already have an orchestration tool and you would like it to just co manage this application, we can absolutely support that as well. With containers and orchestration, I don't know if that's your thing, right? But there's just so much value in that because that's where we get the high availability with less administration. Because it gives you seamless scalability. It gives you a lot of automation that comes from this orchestration tool. You can set it up to where always have to have, say, five nodes live, and if one gets lost, orchestration spins up another one. It really does provide a lot of value to the product. And then the other thing that you don't have today from a centralized console, you can manage both thick and thin together. And so what do I mean by that? If you're using Passport on the desktop today, you know that anytime you have to change something like, let's say, when you went from SSL to TLS, you had to do that in the session document. A lot of my customers don't even know where all their session documents are. That's a really hardship. Right? And then you got to go find them and then you got to change every one of Well, in Secure Host Access, from that server, you can actually tweak those from the server, and only that change will be picked up the next time the user logs in. So lots of value here. Hope you're seeing the journey. Now we're gonna move to some upgrade advice. So, again, because we have not delivered you a release in quite some time, my suggestion to you is to take a look at this sooner than later. I'm not in sales, and I'm not going to ask you to buy it. What I'm asking you to do is look at this as a future journey that we can partner on. Trials are available today. You you would contact your rep to get that. If you don't know who your rep is, I can get you one, so that's not a problem. I can work the eval for you as well. So I just think you need to start looking at this, and then let us know how we can assist you. You might feel a little overwhelmed right now. I don't want you to. This is how we're communicating to all our customers. This particular webinar is about Passport but we're having the same webinar for all of our I think it's fourteen-fifteen emulators. Every customer is being suggested to start looking at this now because of the state of security and because of the value that this solution provides you. On the slide, you see an email address. Take a picture of that. It'll also be in the deck when Evan sends it to you. That's how you actually get to Chris and I. We put this out there so that Chris and I can share an inbox and we can get back. We're the only ones in there. If if we if we don't reply fast enough, just send another one in there. You know, it is just Chris and I, but we promise to get back to you. And there are no questions you can't ask us. K? We'll tell you if it's not our job, and we'll bring somebody in that it is, but no questions you can ask so make sure you keep that inbox. I think Chris planted that whole mic thing going out just so he could see me go. Alright. So the reason why you're here today is because you received an announcement on or around January 17, and that told you that Passport, both thick and thin, are going into maturity in January 2027. Now you might ask, since I haven't given you a release since 2018, why is it? What are the dates? Well, the reason why we wanted to give you a lot of time is because I think we, a couple of years ago, suggested that you move to RTE. We don't want you to do that anymore. And I am talking to my RTE customers, but we don't want you to upgrade twice and RTE customers are being asked to look at Secure Host Access as well because what we're doing here is focusing all our innovation into Secure Host Access so that we can give you the best product to address all the security needs that you have with all of our development efforts. That's why we're doing this. We're saying this to RTE customers as well, so we don't wanna make you we don't wanna ask you to move to RTV and then ask you to move to secure host access as well. So we're asking you today to consider the move to secure host access. And with that, we will put Passport into mature status in January 2027. Now what does maturity mean? It does not mean end of life, folks. Rocket is a great company, very customer focused, and we don't end of life products. It's as simple as that. We will support you tomorrow the same way we're supporting you today. Now with that said, I will tell you, I worry about security vulnerabilities because we haven't released the product for several years. But we will do our best and we will evaluate any bug that you turn in and any vulnerability against the product and and do our best to resolve it for you and deliver an answer to that. So but if you ask me to enhance the product, I'm gonna have to tell you no because all of our innovations, including new features, are gonna be developed against Rocket Secure Host Access. And I'm sure you probably have questions about that, and that's okay. You can either bring them into the chat, and we'll answer them right here in front of everybody because I don't mind those things, or you can send me an email because what I don't want you to do is being up all night worrying about these things. We got your back. We'll do the right thing, and Securus Access really has a lot to offer you. Chris, don't tell me your mic's not working, buddy. Can Alright. you read lips? Yeah. It's all good. That was the next move there. So thanks, Barbara, for covering for me. I'm back now, it sounds like. So that's great. So let's talk a little bit about the product life cycle for secure host access. So we recently published a product life cycle and really that's put in place because we wanna help you plan for your upgrades, whether it's from a heritage emulator or within the secure host access, you know, product and the releases associated with secure host access. So we recently published a product life cycle to show folks where their emulators are in their life cycle. A lot of the heritage products are, you know, very well along in their life cycles. But anyways, it's published now. We're we're gonna do an update to it. We're constantly evolving, you know, our approach just to make sure that we're addressing all the needs of customers and and so forth. But the the new product life cycle policies are are new and improved. You can more easily understand them than maybe the way they were in the past. In a lot of cases, we weren't even publishing policies for certain products. So, you know, you're potentially getting a lot more information than you were in the past. We have, you know, frequent communications from the marketing team and the product management teams, whether it's through email or on the forum, which is kinda new, probably a good place for you to plug into if you have any questions about passport or secure host access. You can go to the forum and ask questions there. And that's one one channel to get communications or to exchange feedback. And then, the documentation portal is also very useful. That's where all the product online documentation is, and I use that every day release notes for every release of the product and so forth. So if you wanted to see what the new features were in the latest release of the secure host access product, you could find that there. And then the RCC platform Rocket customer community is where you download the software media. And I'm sure you you're familiar with that. There's also a lot of information on ours available on RCC. So again, you know, the the product life cycles were bringing, you know, together a bunch of different heritage companies and products and there was not a consistent policy. Now we've kinda made a consistent policy. If you look at the screenshot at the bottom of the screen, kinda going forward with secure host access, the product life cycle policies are gonna be at a very high level from general availability, which is the first date of release for about three years. We're gonna be doing, you know, full support, tech support, phone support, dev support, fixing vulnerabilities, adding new features, so forth. And then years four and five, limited support, and then couple years of doing restricted support. So that's kind of the plan for, you know, releases of secure host access. I mean, we can also answer questions regarding, you know, the legacy emulators and and what their product life cycles look like. And and that information, again, is published on the product life cycle page. And again, you know, we have some updates coming to that page as well to better define what the policies are going forward. So you should check that out. It's available on the public Rocket website right now. And with that, let's talk a little bit about our commitment to you. So Barbara, I think, has expressed this very well. We're committed to our customers. She mentioned that we're gonna be, you know, evaluating issues with Passport. So we're obviously taking phone calls and responding to, you know, bug fix requests and and any problems that are occurring with Passport that you might be having with Passport. We talk we're talking about secure host access is a really important product for us going forward because it really addresses the market requirement right now, which is security, and it's gonna be this way for a long time. You can move at your own pace. We think you'll find moving to secure host access compelling. We're happy to have road map, you know, conversations and show you kinda what's what's happening going forward. We're gonna support you on and and we put this at, you know, our your modernization journey is really, you know, ours as well collectively. We're gonna do this together, and and we want you to be successful. I'm gonna turn it over to Barb Barbara now to talk a little bit about the other bullets here. You bet. So, we do believe wholeheartedly that Secure Host Access provides a really innovative roadmap. I will tell you the one thing I didn't mention in my previous slides and I should have is we also have a discovery tool. I mentioned sometimes that customers don't know where all their sessions documents are. Right? Because you you you get it going and when it works, you just keep using it and and it just the user data like macros, sessions, those kind of things kind of just grow on their own and it easily gets out of control. So we have discovery tools that can go out and look in your organization for you to use, not for us to use. We'll show you how and it can go out and tell you where all of that stuff is so that you can kind of start thinking about how big is the lift to Secure Host Access because we get it. Although I sound really enthusiastic and I and I am, change is hard and nobody wants to change out their terminal emulator. And frankly, nobody should be changing out their terminal emulator unless there is real value and that's what we believe is in Securos Access. So and we also believe that today, when you compare the two solutions and the security landscape, there's just no doubt. Even just the thick client, you need to have TLS one dot three. You need to have those redaction capabilities. You need to have current versions of SSH. So there's just a lot packed in this. The other thing that we're doing as well is we're working very hard to understand all of our terminal emulator customers and what they will need in Secure Host Access. So we have ways. It's not intuitive in Secure Host Access, but we have ways to get your data from Passport over to Secure Host Access. We won't make you jump through the hoops, but we can partner with you and we can get that data over. Right? We knew you were gonna go to RTE, so we'll run it through the RTE process because that had migration tools. And then we have migration tools from RTE to Secure Host Access. So we can do all that for you or with you or however you see fit. I just want you to know that we're thinking ahead because we understand that you can't just swap these out even if there is value. So and like Chris said, the life cycle is out there. You should be able to look up passport today. That's where I got the 2018 date. And it's nice because now you can see exactly what our relationship is from a product lifecycle perspective between you and Rocket. There's always work to do when you make this big of a change, so we don't take that lightly either. We're asking you to tell us what you like and what you don't like. And you can be quite frank with me, I got pretty thick skin. Use that email address. Use it for anything you need in order to get help from Rocket. If you don't know who your rep is, I can help you there. If your renewal is coming up and that's stressing you out because you don't see the value in Passport, I can help you out there too. It may not be me or Chris that actually do what you need done, but we have resources in the back that we can get you in touch with. So we're always in that inbox. Don't hesitate to reach out to us. And with that, I think we're opening up to q and a. Excellent, Barbara. So a lot of questions come up. I think for the Passport customers, did you say, Barbara, that there's both web based and desktop? is. Yep. Right? Yep. That's true. So one of the questions that's come up is you've got with Secure Host Access, the new solution, you've got both thick and thin in the Secure Host Access Anywhere tier. That's correct. And a lot in a lot of cases, when you go to a web based solution, you don't you're not you get the ability to manage web based sessions and so forth and users configurations, but not the not the thick client. With secure host access, can you can you do both, or are they separate, you know, consoles or something to manage. One console thick and thin? you can manage both thick and thin. You can actually kind of the uniqueness and Passport customers wouldn't know this because this came out of customer need, you can actually manage the thick client just like you manage the thin. So you can create the client, you can create that session on the administrative console and then push it out to users, you can update it. Users can keep their own changes. You can make surgical changes to it. There's a lot of value in that management of that thick client that is very similar to what you would get with a thin client, but it's still thick because you still need thick client in most organizations. You have business logic wrapped around it, Halopy and maybe macros that connect via Excel spreadsheets and all of this business logic that we wrap around these terminals that has worked for years and years and years. And you can't do that with a browser based session because there's rules, there's security sandboxing in the browser that won't let you do some of those things. So that's, in my opinion, that's why almost every organization I talk to has to have some thick. Even if they want to go all thin, they still have to keep some thick. Thank you. And then there have been a lot of questions around, I think when you hear web based or browser based solutions, people think a lot about the kind of the prior generation of solutions that included the JRE, the Java runtime, and so forth in the browser that was required to get a terminal emulation session going and so forth. How does that fit into the whole secure host access picture? Java on the client side required at all. This is a zero footprint client. So the server in the middle has all the thirty two seventy traffic and goes thirty two seventy or or fifty two fifty from the server to the host, and then it's HTML out to a browser through HTTPS. No requirements on the desktop at all. So no. Java. on the desktop or any other desktop requirement. Great. Great. We do have another question in the queue Yep. asking about do I need to go to the Anywhere tier to get the thin client? And yes, that is where the thin client is And then you get all of the rest with it. Right? You get the single sign on. You get the integration into IAM. And and you will have the thick client rather you use it. That is certainly your decision. But, yes, it is the anywhere tier that would give you that zero footprint client. And as folks, you know, move in that direction, right, a lot of the customers we talked to are using a thick client today. They're gonna move to a web based solution. You just answered a question anywhere is web. Web means a server, the secure access server. And then with that, some of the benefits you can get are, related to, you know, kind of business continuity, with things like, scalability, high availability availability, and so forth. Can you comment a little bit about all those things related to, you know, implementing the web based. side of things? Yep. And even if you're gonna use the FIC client, if you're in the Enterprise or Anywhere tier, remember you're still in a server because that's what manages that thick client. Right. High availability, for example, I can't just tell you how to do high availability because it matters how your organization looks at high availability. It could be across servers. It could be across data centers. It could be across geographical locations. It could be across zones in AWS or or Google Cloud. So but what we do have is a really great deployment model that shows you how to deploy, how to get high availability, and how to scale. And the other thing that's really nice about this, because I think licensing and pricing is always in somebody's mind, is we price by the, named user or concurrent user. We that's how we license the product. What and what do I bring in that up for is because we don't license by the server. So if you need x amount of servers because you span 20 nodes or 20 geos or 20 zones in the cloud, then you can deploy 20 servers at no additional cost. We don't charge for that. We also have plans for Doctor. We have to define that. What are we talking about? What's going down? Where's the disaster? And what do you need when that disaster happens? We have a great it's called a deployment guide and it walks you through all of that. From a scaling perspective, we scale based on concurrent sessions if you're thin and concurrent logged in end users if you are talking about thick. And again, because we are containers and we're orchestrated, it's an interesting concept if you don't know much orchestration and containers. It's just really pretty cool to look at the fundamentals of that. But we can set it up in orchestration to say that because we're using X amount of sessions, we have to have this many nodes up at any one time with this many servers inside those nodes and when one goes down another one gets scaled up right away. We have health checks that you can go in and monitor the health of any of the nodes. It is an enterprise ready solution and we have it deployed in major enterprises. I shouldn't say my favorite customer because they're all my favorite, but 65,000 users are logging in every day in one of my big U. S. Federal government sites. I got 10,000 users logging in every day over in Australia at one of my big insurance sites. I got 160,000 users logging in in a US insurance. So it it scales it scales well. It it is pretty automatic which is really nice and all based on specifications. That's important too. It's not proprietary. It's not what we made up. We're using things out there that were made to do this job. And I and I saw the term self healing, thank you. That other day as. well. Because so self healing is is the concept of when that server goes down, another one comes right back up, and the users that were on the bad server automatically get moved to the new server because they're gonna see nothing's happening anymore. So they're gonna do disconnect and reconnect and boom. They're right back on. But they're actually on a different server. They just don't even know it. So. It's it's such a new perspective. If you think about kind of the old disaster recovery. business continuity plans and so forth. Right? Sending up a whole another data center with desktop based emulation on. systems and so forth. And now this can all be orchestrated kind of from a central location. and in a distributed manner as well such that it can support these types of scenarios. If if something bad happens, it can recover pretty quickly. And just mentioning distributed, very cool. we also we support on prem as well as off prem or even hybrid. So, I mean, it really is an enterprise solution that can be spread all over wherever you need it to be. If if someone wants to see it, what are some of the options? So evals, proof of concepts, that type. of thing. So we have a we have a eval ready to go. All you gotta do is contact your account rep. And if you don't know who that is, contact us at our little email box, which is right there on the screen handy dandy, and we'll figure out who your rep is. And and those can change year over year. It just depends on how big your organization is. But but we can find them pretty darn easily. So we'll get you hooked up to the right person, and then we'll also hook you up with a technical person, you know, to help you with any technical questions that you would have. So that's not a problem at all. So we can see a proof of con they can see a proof of concept. They can see all the stuff we've talked about today. And then what about the future? So if somebody wants to see what's on the road map, what should they do? So that's a great question. I mean, we're pretty careful with our road map. Right? Because what I mean, when I say careful, yeah, there's information disclosure, which we're always careful with. Right? So NDAs are in place. But the but for me, the other thing is because you and I are product managers and we hesitate to tell people what's coming down the road and set an expectation and not meet it. So we have a pretty good roadmap. We deliver quarterly. Our roadmap generally tells what we're doing in each half of the year. I would say that is well understood twelve months forward of wherever we are and when you go out past that it gets a little bit grayer. But it also, for me, what the roadmap does is if a customer is interested in seeing that, I'm interested in why. Because you might be looking for something, and I need to know what that something is so that I can make sure I'm focusing on that era going forward. Again, my view on product management is the more I know about a customer's environment and how they use my products, the better my product is going to be, a better fit for them it's going to be as they move to the next phase. Our old boss I won't name him but he had a phrase because he used to laugh I'm the Sherpa of emulation. A Sherpa is that guide that takes you on the mountains. And if the Sherpa doesn't know where you're going, it's not gonna be a good thing. So I need to know where you're going in order to make sure my road map fits you when you're ready to get there. Don't want you to be frost bitten. Yeah. Okay. We get that. Okay. Well let's see. I think that's all the questions. Evan, are there any others? No. I I I think we've hit them all. Chris and. Barbara, thank you so much. This has been a wonderful session, and I hope we've answered a lot of questions around Passport and a potential upgrade to secure us access. But, again, if there are other questions, please reach out. You have the email address here, rocketconnectivity@rocketsoftware.com. We are here to help. We'll we'll get you answers if you have questions. So thanks again for your time today. I really appreciate you all being here, and we'll hope to hear from you soon. Thank you. Thanks, for spending some. time with us.