This v10.0 article is also available in v9.5
Note that some functionalities may not be available in Utility app configuration (v9.5).
The DigipassONE Server and Web App SDK ship with two utility apps that enable strong passkey authentication with External IdP integration: nnlsignin, a.k.a the Sign In App and nnlfedapp, a.k.a., the Fed App.
Along with the DigipassONE Federation Adapter, the Sign In App enables FIDO authentication on a Federation Server. Meanwhile, the Fed App makes Federated Credential Management accessible through an OIDC flow.
Deploying the utility apps
The utility apps can be deployed during server installation by:
setting the
DEPLOY_OPTIONAL_WEB_APP_LISTproperty in thennl-install.propertiesfile, orconfiguring the Web App SDK.
The Web App SDK can be configured by:
Creating the
nnlapp_configobject of typeMain.Uploading
nnlapp_configto the API Server using the Admin Console.Navigating to Configuration > API Server > Main > Digipass S3 App Config1 and clicking the Upload button.
On-premises
If your server is on-prem and the default values do not apply, you can modify the values by:
Setting only tenant-specific fields inside
nnlapp_config.fedAppConfigandnnlapp_config.signinConfig, andEditing
nnlfedapp/config/config.jsornnlsignin/config/config.js.
1In some instances, this may appear as OneSpan App Config.
The nnlapp_config object
The nnlapp_config object is tenant-specific and contains:
Field | Requirement | Description | Notes |
|---|---|---|---|
appSdkConfig | Optional | Specifies options for the AppSdkConfig object. | See the AppSdkConfig object in the Client API docs. |
authOpts | Optional | Specifies authentication options in nnlsignin. | See the |
fedAppConfig | Optional | A configuration object that specifies options for nnlfedapp. See the table below for specific fields inside this object. These configurations override the defaults set in | |
fidoRegOpts | Optional | Specifies options when nnlfedapp registers FIDO authenticators. | See the |
manageRegOpts | Optional | Specifies options when nnlfedapp manages registrations. | See the |
regOpts | Optional | Specifies options when nnlfedapp registers non-FIDO authentication methods. | See the |
signinConfig | Optional | A configuration object that specifies options for nnlsignin. | These configurations override the defaults set in |
suggestRegOpts | Optional | Specifies Suggest Registration options in nnlsignin. | See the |
Example nnlapp_config object:
{
"appSdkConfig": {
"otp": {
"maxFalseAttempts": 1,
"lockoutPeriod": 5
},
"darkMode": "on"
},
"fedAppConfig": {
"ui_config_url": "https://example.com/fedapp_ui_config"
},
"fidoRegOpts": {
"askSecurityKeyCredentialName": false
},
"manageRegOpts": {
"options": {
"needDetails": 3
}
},
"signinConfig": {
"federation_resume_uri": "http://ping.noknokeval.com:9031/as/authorization.oauth2",
"ui_config_url": "https://example.com/signin_ui_config"
},
"authOpts": {
"signInWithMobile": "CONDITIONALLY"
},
"suggestRegOpts": {
"askSecurityKeyCredentialName": true,
"autoReg": true,
"suggestRegEnabled": true
}
}The
appSdkConfig,authOpts,fidoRegOpts,manageRegOpts,regOptsandsuggestRegOptsfields are used to configure the Web App SDK upon which the Sign In App and Fed App rely.
Configuring the Sign In and Fed App
Once you have configured the Web App SDK via the nnlapp_config you may proceed with:
Configuring the nnlsignin via the
nnlapp_config.signinConfigobject.Configure nnlfedapp via the
nnlapp_config.fedAppConfigobject.