Attention : support for WAPT 1.8.2 ended on June the 30th 2022.

There are known vulnerabilities in WAPT dependencies in WAPT 1.8.2 branch. Please upgrade to the latest supported version. CVE listing (non exhaustive) :
  • * python engine : python 2.7 (CVE-2020-10735, CVE-2015-20107, CVE-2022-0391, CVE-2021-23336, CVE-2021-3177, CVE-2020-27619, CVE-2020-26116, CVE-2019-20907, CVE-2020-8492, etc.)
  • * cryptography : openssl : CVE-2022-2068, CVE-2022-1292, CVE-2022-0778, CVE-2021-4160, CVE-2021-3712, CVE-2021-23841, CVE-2021-23840, CVE-2021-23839, CVE-2020-1971, CVE-2020-1968, CVE-2019-1551
  • * python dependencies : cryptography (CVE-2020-36242, CVE-2020-25659), eventlet (CVE-2021-21419), jinja2 (CVE-2020-28493), psutil (CVE-2019-18874), waitress (CVE-2022-31015), lxml (CVE-2021-4381, CVE-2021-28957, CVE-2020-27783, CVE-2018-19787), ujson (CVE-2022-31117, CVE-2022-31116, CVE-2021-45958), python-ldap (CVE-2021-46823)

Comparing features between the WAPT Enterprise and Community versions

Current feature list as of 2023-01-10

Comparison of features between the Enterprise and the Community version of WAPT as of 2023-01-10

Feature

Enterprise

Community

Deploy, update and remove software on hosts running Windows logo Debian logo Ubuntu logo Red Hat / CentOS logo Apple logo Suse logo

feature available

feature available

The repository is hosted on infrastructure under your control and not under the control of a large MegaCorp, Inc. that will prioritize its own interests over yours

feature available

feature available

Deploy and update configurations in SYSTEM context

feature available

feature available

Deploy and update configurations in USER context

feature available

feature available

Get a comprehensive inventory of hardware, software and applied WAPT packages

feature available

feature available

Benefit from the differenciated self-service (authorized users may install authorized software from authorized WAPT package stores)

feature available

feature not available

Benefit from simplified Windows Updates that work much better than a standard WSUS (only the required KBs are dowloaded from Microsoft)

feature available

feature not available

Simplify and structure your administrative workload by applying WAPT packages to an OU

feature available

feature not available

Configure and manage easily WAPT store relays to preserve bandwidth in multi-site environments

feature available

feature not available

Get access to ready-to-deploy WAPT packages for common free-to-use software

feature available

feature available

Work with easily verifiable python recipes for installing, updating and removing software and configuration, recipes may embedd Powershell code or scripts made with other languages (ex: for personalizing a software using a LDAP directory)

feature available

feature available

Benefit from hundreds of Helpers for simplifying your software packaging

feature available 1

feature available

Encrypt your sensitive data for transport (software license keys, login, password, server FQDN, API informations for registering software with the vendor, etc)

feature available

feature not available

Automate the auditing of your configurations for an easy, automated and always up-to-date compliance

feature available

feature not available

Benefit from the power of SQL integrated with the WAPT console to make the reports that you need for your daily sysadmin work or that your organisational requires for budgeting decisions

feature available

feature not available

Authenticate your WAPT Administrator against an Active Directory or LDAP

feature available

feature not available 2

Benefit from differenciated roles between software packagers and package deployers so you can delegate your WAPT powers to the most adequate people (packagers know security implications, deployers know user needs)

feature available

feature not available

Licensed under

Proprietary

GPLv3

Verified and approved by national cybersecurity agency French Security Visa, WAPT is the only deployment software in the world with this level of certification

feature available

feature not available

Professional phone support with Tranquil IT

feature available 3

feature not available

Features coming soon

Below is a list of features that we have identified as being really useful to WAPT and WAPT’s user community and that we have already started to work on. No timeline is promised, stay tuned, we are only promising you that we are working very hard to achieve these objectives.

Feature

Enterprise

Community

Multi-tenant, multi-client mode with ACL for MSPs and large multi-departmental or international organisations using an internal PKI based mecanism

feature available

feature not available

Simple to use screensharing for user support, built with the same level of security and privacy as WAPT

feature available

feature not available

History of actions done via WAPT for a complete reporting of a host`s software maintenance lifecycle

feature available

feature not available

Authentication of WAPT Administrators using cryptographic tokens (ex: smartcards)

feature available

feature not available

Access to ready-to-deploy WAPT packages or recipes for licensed business software (common business software for industry, medical, office, public collectivities, cybersecurity, etc)

feature available

feature not available

Access to ready-to-deploy WAPT package extensions for simplifying desktop armoring using Applocker or equivalent

feature available

feature not available

Continued support for Windows XP in WAPT for factory machine tools, Hospital medical equipment, expensive research instruments, etc

feature available 4

feature not available

Operating system image deployment tool integrated within WAPT

feature available

feature not available

Integration of useful subset of WAPT inventory with popular ITSM tools and triggering of actions from the users ITSM console

feature available

feature not available

Summary of operating principles in WAPT

  • WAPT is agent based to allow no inbound open port in hosts` firewalls that initiate a secured bi-directional websocket with the server for allowing real-time reporting and actions;

  • Can work with Trusted Data Gateways using simple task scheduling;

  • Works on the principle of smoothly pulling updates and then applying upgrades at convenient time (works with low / intermittent bandwidth, high latency, high jitter);

  • Does not require an AD (works with Windows Home edition too), but will show the host in its Active Directory tree if the host is joined to an AD;

  • Methods for deploying WAPT agent:

    1. using a GPO or an Ansible script;

    2. manually after having downloaded the agent from the WAPT server or using SSH;

  • Methods for registering hosts with the WAPT server:

    1. automatically using the host`s kerberos account;

    2. manually with the WAPT Superadmin login and password;

  • Upgrades may be triggered:

    1. upon shutdown of the host, the standard mode;

    2. by an authorized WAPT Administrator in an emergency (ex: critical vulnerabilities running in the wild);

    3. by the user at a time she chooses (ex: 24/7 nursing cart unused during lunch break with a simple click);

    4. via a scheduled task running at a predetermined time (best for servers);

  • Security is insured with:

    1. signing of WAPT packages using asymetric cryptography;

    2. authentication of hosts against the WAPT server using symetric cryptography on registering;

    3. confidentiality of the WAPT server using WAPT deployed client certificates;

Footnotes

1

The Enterprise version embeds more SetupHelper functions than the Community version.

2

In the Community version, the WAPT SuperAdmin password is shared between individuals that manage the WAPT server.

3

A minimal volume of licences must be subscribed in order to benefit from Tranquil IT’s telephone support for the daily operation of the software. Additional paid support is available to help you with your WAPT packaging needs.

4

Windows XP does not work with Python > 2.7. So a special branch of WAPT will be frozen with the last build of the WAPT agent running with 2.7. This version of the agent will of course be excluded from the target of evaluation in future security certifications.