Utility app configuration

Prev Next

This v10.0 article is also available in v9.5

Note that some functionalities may not be available in Utility app configuration (v9.5).

The DigipassONE Server and Web App SDK ship with two utility apps that enable strong passkey authentication with External IdP integration: nnlsignin, a.k.a the Sign In App and nnlfedapp, a.k.a., the Fed App.

Along with the DigipassONE Federation Adapter, the Sign In App enables FIDO authentication on a Federation Server. Meanwhile, the Fed App makes Federated Credential Management accessible through an OIDC flow.

Deploying the utility apps

The utility apps can be deployed during server installation by:

  • setting the DEPLOY_OPTIONAL_WEB_APP_LIST property in the nnl-install.properties file, or

  • configuring the Web App SDK.

The Web App SDK can be configured by:

  1. Creating the nnlapp_config object of type Main.

  2. Uploading nnlapp_config to the API Server using the Admin Console.

  3. Navigating to Configuration > API Server > Main > Digipass S3 App Config1 and clicking the Upload button.

On-premises

If your server is on-prem and the default values do not apply, you can modify the values by:

  1. Setting only tenant-specific fields inside nnlapp_config.fedAppConfig and nnlapp_config.signinConfig, and

  2. Editing nnlfedapp/config/config.js or nnlsignin/config/config.js.

1In some instances, this may appear as OneSpan App Config.

The nnlapp_config object

The nnlapp_config object is tenant-specific and contains:

Field

Requirement

Description

Notes

appSdkConfig

Optional

Specifies options for the AppSdkConfig object.

See the AppSdkConfig object in the Client API docs.

authOpts

Optional

Specifies authentication options in nnlsignin.

See the authOpts parameter of the AdaptiveUI.getAuthenticationView() function in the Client API docs.

fedAppConfig

Optional

A configuration object that specifies options for nnlfedapp. See the table below for specific fields inside this object. These configurations override the defaults set in nnlfedapp/config/config.js.

fidoRegOpts

Optional

Specifies options when nnlfedapp registers FIDO authenticators.

See the Extras parameter of the AppSdk.getFidoRegistrationView() function in the Client API docs.

manageRegOpts

Optional

Specifies options when nnlfedapp manages registrations.

See the Extras parameter of the AppSdk.getManageRegistrationsView() function in the Client API docs.

regOpts

Optional

Specifies options when nnlfedapp registers non-FIDO authentication methods.

See the regOpts parameter of the AdaptiveUI.getRegistrationView() function in the Client API docs.

signinConfig

Optional

A configuration object that specifies options for nnlsignin.

These configurations override the defaults set in nnlsignin/config/config.js file.

suggestRegOpts

Optional

Specifies Suggest Registration options in nnlsignin.

See the suggestRegOpts parameter of the AdaptiveUI.getAuthenticationView() function in the Client API docs.

Example nnlapp_config object:

{
    "appSdkConfig": {
        "otp": {
            "maxFalseAttempts": 1,
            "lockoutPeriod": 5
        },
        "darkMode": "on"
    },
    "fedAppConfig": {
        "ui_config_url": "https://example.com/fedapp_ui_config"
    },
    "fidoRegOpts": {
        "askSecurityKeyCredentialName": false
    },
    "manageRegOpts": {
        "options": {
            "needDetails": 3
        }
    },
    "signinConfig": {
        "federation_resume_uri": "http://ping.noknokeval.com:9031/as/authorization.oauth2",
        "ui_config_url": "https://example.com/signin_ui_config"
    },
    "authOpts": {
        "signInWithMobile": "CONDITIONALLY"
    },
    "suggestRegOpts": {
        "askSecurityKeyCredentialName": true,
        "autoReg": true,
        "suggestRegEnabled": true
    }
}

The appSdkConfig, authOpts, fidoRegOpts, manageRegOpts, regOpts and suggestRegOpts fields are used to configure the Web App SDK upon which the Sign In App and Fed App rely.

Configuring the Sign In and Fed App

Once you have configured the Web App SDK via the nnlapp_config you may proceed with:

  • Configuring the nnlsignin via the nnlapp_config.signinConfig object.

  • Configure nnlfedapp via the nnlapp_config.fedAppConfig object.