Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Server release notes for v9.5

Prev Next

Hot Fix 3

Aug 24, 2026

Server BOM: 9.5.0-145

Auth Server Version: 9.5.0-146

API Server Version: 9.5.0.24

UM Build Version: 9.5.0.27

Gateway Build Version: 9.5.0.24

Web App SDK Version: 9.5.0.125

Additional updates to server components

The following libraries were updated to address potential vulnerabilities:

  • bouncycastle

  • netty


Hot Fix 2

Jul 31, 2026

Server BOM: 9.5.0.143

Auth Server Version: 9.5.0-144

API Server Version: 9.5.0.20

UM Build Version: 9.5.0.24

Web App SDK Version: 9.5.0.122

Server components updated

The following libraries were updated to address potential vulnerabilities:

  • bouncycastle - bcprov and bcpkix

  • httpcore

  • jackson-all

  • log4j

  • netty

  • postgresql JDBC driver


Hot Fix 1

June 11, 2026

Server BOM: 9.5.0-129

Auth Server Version: 9.5.0-133

API Server Version: 9.5.0.15

UM Build Version: 9.5.0.20

Web App SDK Version: 9.5.0.46

Customer issue fixed

The MDS import tool has been updated to include smart-card attachmentHint support and improved error handling.

Previous behavior

  • FIDO metadata imports would fail for entries with a smart-card attachment hint.

  • Entries would be skipped, but the errors are not logged under Summary for web authenticator metadata.

New behavior

  • Entries with smart-card attachment hints are now imported successfully.

  • MDS import tool will now log errors for skipped metadata, including:

    • Total number of web authenticator metadata failed in the Summary for web authenticator metadata.

    • Affected files and any corresponding errors in the log file at <NNL_HOME>/admin/logs/nnl-mgmt.log.


Main release

April 30, 2026

Server BOM: 9.5.0-122

Auth Server Version: 9.5.0-126

API Server Version: 9.5.0.15

UM Build Version: 9.5.0.20

Web App SDK version: 9.5.0.46

Rebranding

The Nok Nok S3 Authentication Suite has been renamed to Digipass S3 Authentication Software, which includes the Digipass S3 Server and the Digipass S3 App SDKs. The Nok Nok Admin Console has been renamed to the Digipass S3 Admin Console. The Admin Console’s user interface has the same menu structure, but with a new look.

New features

  • A FIDO policy can include a Post Operation Rule that checks various signals in a user’s authenticator. The result of a Post Operation Rule can be deny, allow, or increment risk score. A FIDO policy can be configured to deny if the risk score exceeds a threshold. In Configure adaptive rulesets, see Step 3. Create FIDO policies.

  • Customers can download a checksum with their product package to independently verify the integrity of the software.

  • Authenticator metadata shipped with the product includes:

    • DIgipass FX2. This authenticator provides strong, phishing-resistant authentication and transaction signing.

    • Microsoft Password Manager.

  • The Server can detect if a passkey is available during adaptive registration.

    • Previous behavior: The Server can detect if a passkey is available during adaptive authentication.  

    • New behavior: The Server can detect if a passkey is available during adaptive authentication or registration.

  • The API Server’s IP address extractor plugin generates client IP address extensions when VERIFY, INIT_ADAPTIVE and INIT_ADAPTIVE_REG, as well as non-adaptive REST API operations, are called.

    • Previous behavior: When the IP address extractor plugin was active, only the non-adaptive REST API operations added the IP address extension to the message that the API server sent to the Authentication server.

    • New behavior: When the IP address extractor plugin is active, both adaptive and non-adaptive REST API operations generate an IP address extension that the API server sends to the Authentication server.

Customer issues fixed

  • Third party libraries were updated to address the following vulnerabilities:

    • CVE-2025-7962

    • CVE-2025-67735

    • CVE-2025-68161

  • In the Admin Console, a user with Read Only permissions cannot view the configurations for API server plugins.

    • Previous behavior: In the Admin Console, a user with Read Only permissions chooses Configuration>API Server. The user can see a list of the API server plugins, but they cannot choose a plugin and view its configuration.

    • New behavior: In the Admin Console, a user with Read Only permissions chooses Configuration>API Server to view a list of the API server plugins. The user can then choose a plugin and view its configuration.

Installation requirements

  • The package name for the Server is nns3_server_package_9.5.0-122.tgz

Supported operating systems

  • Red Hat Enterprise Linux (RHEL) 9 and 10

  • Rocky Linux 9 and 10

  • Amazon Linux 2023

Supported database servers and versions

  • PostgreSQL 15, 16, 17

    • A PostgreSQL JDBC driver is included in the Server package.

    • PostgreSQL 15 and later does not allow the creation of tables in the public schema by default, so constrain ordinary users to user-private schemas. Set up a default schema search path for the DB user with:  

      CREATE SCHEMA <user-schema> AUTHORIZATION <user>  

    See PostgreSQL documentation for further details.

  • Oracle Database 21c Enterprise, and 23c

    • For best results use the latest available JDBC driver.

  • MySQL Server 8.4.x

    • For best results use the latest available JDBC driver.

  • CockroachDB v23.2.x, v25.2.x

  • AWS Aurora/MySQL 8.0.x

  • AWS Aurora/PostgreSQL 17.6

Supported application servers and versions

  • Apache Tomcat 10.1 and later versions. To configure Tomcat, root or sudo privileges may be required.

Other prerequisites

  • Java Developers Kit (JDK)

    • Oracle JDK 21 and 25

    • RedHat OpenJDK 17, 21 and 25

    • Eclipse Temurin JDK 17, 21 and 25

  • Optional when using Identity Proofing and Account Recovery:

    • Email OTP-based recovery requires an email server supporting SMTP.

    • SMS OTP-based recovery requires a Twilio account with an active ‘From’ number enabled for SMS support.

    • Photo ID-based recovery requires a Jumio Netverify account with address and face-match features enabled.