Fed App for federated credential management

Prev Next

This v10.0 article is also available in v9.5

Note that some functionalities may not be available in Federated Identity Management (v9.5).

The Fed App, a.k.a nnlfedapp, provides federated credential management, making it possible   for end users to login to your application with an external IdP.

The DigipassONE API Server can be configured to support an OIDC flow to an external identity provider where:

  • the user logs in with an existing authentication method, e.g., a password

  • the user is then brought to the Federated Credential Management Page, where they can also manage their credentials.

To implement the Fed App for your applications:

Step 1: Configure the Fed App (front end)

To customize how the Federated Credential Management page will appear to your users, update the following fields in the fedAppConfig object which is nested inside nnlapp_config:1

Field

Default value2

Description

Notes

nnlappsdk_url

"${host}/nnlappsdk-${appsdk_version}"

The URL where the DigipassONE Web App SDK is located.

-

reg_endpoint

"${host}/nnlgateway/nnl/${tenant_id}/reg"

The registration endpoint for the API Server.

-

auth_endpoint

"${host}/nnlgateway/nnl/${tenant_id}/auth"

The authentication endpoint for the API Server.

-

storage_endpoint

"${host}/nnlgateway/storage"

The endpoint of the cookie-based storage.

-

ui_config_url

null

The URL of the root configuration directory for the JSON UI Configuration files used by nnlfedapp.

See App UI Customization for details on how to create your UI Configuration files.
See the section Storing Your UI Configuration Files Using a Remote Server for information on how to structure the directories that contain your UI configuration.

setupMobile

ALWAYS

Specifies the behavior of the Set Up New Device button in nnlfedapp. This parameter accepts three values: NEVER, ALWAYS, and CONDITIONALLY.

If set to NEVER, the button is always hidden.
If set to ALWAYS, the button is always displayed regardless of the adaptive rules configured on the server.
If set to CONDITIONALLY, the button is displayed only when the adaptive rules configured on the server allow for OOB registration.

checkSessionIframeEnabled

false

Enables periodic session-state checks against the IdP using a session iframe URL.

When enabled, the app tries the API Server-configured checkSessionIframeUrl first; if missing, it uses the IdP metadata check_session_iframe endpoint.  This allows the app to detect IdP session changes (such as IdP user sign-out) and keep the local application session in sync.      

1 See Utility app configuration.
2 Fed App substitutes actual values for ${host}, ${tenant_id} and ${appsdk_version}.

Step 2: Configure the OIDC (back-end)

Enable external IdP on the DigipassONE API Server by:

  1. Uploading an external IdP configuration file via the Admin Console.

  2. Navigating to Configuration > API Server > Federated Identity Management > External Identity Provider and clicking Add OIDC Provider.

External IdP configuration file

The JSON configuration file includes mandatory and optional fields for configuration:

Field Name

Requirement

Description

Notes

registrationId

Mandatory

String. The registrationId is a unique identifier, within the tenant, for the registration of an OIDC client.

-

clientId

Mandatory

String. OAuth 2.0 Client identifier which uniquely identifies the client to the IdP server.

-

clientSecret

Mandatory

String. A secret that proves the authenticity of the Client's requests.

-

authorizationGrantType

Mandatory

OAuth 2.0 authorization grant type, used to exchange an authorization code for an access token.

The only type supported is authorization_code.

clientAuthenticationMethod

Mandatory

The authentication method used when authenticating the client with the authorization server.

One of the following standard methods for client authentication:

  • client_secret_basic

  • client_secret_post

responseMode

Optional

Instructs the authorization server how to return the authorization code to the client.

Supported values are:

  • query - the code is returned in a URL query parameter. This is the default.

  • form_post - the code is submitted in a form body in a POST request.

scopes

Mandatory

The scope(s) requested during the authorization request flow.

You must include the scope openid. You can optionally include additional scopes such as email, profile, address, phone, and so on to get additional user info.

authorizationEndpoint

Optional

URI for the authorization endpoint. If not specified, this is retrieved from the metadata.

See issuerUri (row 13) for details.

tokenEndpoint

Optional

URI for the token endpoint. If not specified, this is retrieved from the metadata.

See issuerUri (row 13) for details.

jwkSetUri

Optional

URI for the JSON Web Key (JWK) Set endpoint. If not specified, this is retrieved from the metadata.

See issuerUri (row 13) for details.

userInfoEndpoint

Optional

URI for the user info endpoint. If not specified, this is retrieved from the metadata.

See issuerUri (row 13) for details.

redirectUri

Mandatory

The end user is redirected to this endpoint after authentication is completed.

The URI must match the predefined pattern:
https://<host:port>/nnlfedapp/resp.jsp?reg_id=<registrationId>&tenant_id=<tenantId>
For example: https://example.com/nnlfedapp/resp.jsp?reg_id=regID&tenant_id=default
where regID is the registration ID listed in the first row of this table.

issuerUri

Mandatory

The issuer URI for an OpenID Connect 1.0 Provider. The provider supplies OIDC Provider Metadata for configuration.

Refer to OpenID Connect Discovery 1.0 incorporating errata set 2.  If any one of these parameters is not provided: authorizationEndpoint, tokenEndpoint,         userInfoEndpoint, or jwkSetUri, then the application appends /.well-known/openid-configuration to the issuerUri and retrieves the OIDC metadata from that URL to populate the missing configuration endpoints.

clientName

Optional

This is a logical name of the client or registration.

If not specified, the registration ID is assigned to clientName.

userNameClaim

Optional

The name of the attribute in the user information response from the external IdP that the API Server uses to identify the end user.

When the API Server creates a session JWT, it uses the value of this attribute to obtain the username.         For example, if you specify userNameClaim to be email, then the API Server generates its JWT with the user's email address as the username. The Server first looks for the attribute in themid_token. If it does not find it in id_token then it gets the attribute from UserInfo. If userNameClaim is not specified, then the API Server uses the value of the sub claim from the id_token returned from the IdP. This parameter was formerly called         userNameAttributeName. Both userNameClaim and userNameAttributeName parameters are supported to ensure backward compatibility.      

userDisplayNameClaim

Optional

The name of the attribute in the claim received from the external IdP that the client app uses as the user's display name. The value is displayed at the top of the credential management page after Signed in as.

If both userDisplayNameClaim and clientUserNameClaim are configured, the Signed in as line displays both values in order to identify both the user and the account they are using.

clientUserNameClaim

Optional

The name of the attribute in the claim received from the external IdP that the client app uses as the username to identify the authenticated user.

This username is displayed in the passkey UI and also at the top of the credential management page after     Signed in as. If you configure both userDisplayNameClaim and clientUserNameClaim, the Signed in as line displays both values in order to identify both the user and the account they are using. If a user has more than one account on the Server, this username must be different for each account.      

checkSessionIframeUrl

Optional

URI for the check-session iframe endpoint used for periodic session-state checks.

When checkSessionIframeEnabled is true in API Server Configuration > API Server > Main > Digipass S3 App Config1, the app uses this API Server external IdP configuration value first; if not specified, this is retrieved from the metadata. If neither is available, session iframe monitoring cannot be performed.

endSessionEndpoint

Optional

URI for the end session endpoint. If not specified, this is retrieved from the metadata.

See issuerUri above for details.

1In some instances, this may appear as OneSpan App Config.

Example JSON files

Client registration JSON without OpenID provider

This is an example of a client registration JSON that does not use an OpenID Provider to supply metadata. As a result, the issuer must be specified in the issuerUri parameter in the configuration, along with the endpoints for:

  • authorization

  • token

  • user info

  • the JWKS

  • endSessionEndpoint

  • checkSessionIframeUrl    

    • if check-session iframe is enabled in API Server app config.

{
  "registrationId":"pingone_external_idp1",
  "clientId":"f840f954-7b0f-4771-a694-fb6d2fecff28",
  "clientSecret":"unencrypted_secret",
  "authorizationGrantType":"authorization_code",
  "clientAuthenticationMethod":"client_secret_basic",
  "redirectUri":"https://<host:port>/nnlfedapp/resp.jsp?reg_id=<regID>&tenant_id=<tenantId>",
  "scopes":["openid", "email"],
  "issuerUri":"https://<external-idp-url>/as",
  "authorizationEndpoint":"https://<external-idp-url>/as/authorize",
  "tokenEndpoint":"https://<external-idp-url>/as/token",
  "userInfoEndpoint":"https://<external-idp-url>/as/userinfo",
  "jwkSetUri":"https://<external-idp-url>/as/jwks",
  "userNameAttributeName":"email",
  "endSessionEndpoint":"https://<external-idp-url>/as/logout",
  "checkSessionIframeUrl":"https://<external-idp-url>/as/check_session_iframe"
}

Client registration JSON with OpenID provider

  An example of a client registration JSON where the OpenID Provider, specified in issuerUri, supplies the configuration metadata.

{
  "registrationId":"pingone_external_idp1",
  "clientId":"f840f954-7b0f-4771-a694-fb6d2fecff28",
  "clientSecret":"unencrypted_secret",
  "authorizationGrantType":"authorization_code",
  "clientAuthenticationMethod":"client_secret_basic",
  "redirectUri":"https://<host:port>/nnlfedapp/resp.jsp?reg_id=<regID>&tenant_id=<tenantId>",
  "scopes":["openid", "email"],
  "issuerUri":"https://<external-idp-url>/as",
  "userNameAttributeName":"email"
}