This v10.0 article is also available in v9.5
Note that some functionalities may not be available in Federated Identity Management (v9.5).
The Fed App, a.k.a nnlfedapp, provides federated credential management, making it possible for end users to login to your application with an external IdP.
The DigipassONE API Server can be configured to support an OIDC flow to an external identity provider where:
the user logs in with an existing authentication method, e.g., a password
the user is then brought to the Federated Credential Management Page, where they can also manage their credentials.
To implement the Fed App for your applications:
Step 1: Configure the Fed App (front end)
To customize how the Federated Credential Management page will appear to your users, update the following fields in the fedAppConfig object which is nested inside nnlapp_config:1
Field | Default value2 | Description | Notes |
|---|---|---|---|
|
| The URL where the DigipassONE Web App SDK is located. | - |
|
| The registration endpoint for the API Server. | - |
|
| The authentication endpoint for the API Server. | - |
|
| The endpoint of the cookie-based storage. | - |
|
| The URL of the root configuration directory for the JSON UI Configuration files used by nnlfedapp. | See App UI Customization for details on how to create your UI Configuration files. |
|
| Specifies the behavior of the Set Up New Device button in nnlfedapp. This parameter accepts three values: | If set to |
|
| Enables periodic session-state checks against the IdP using a session iframe URL. | When enabled, the app tries the API Server-configured |
1 See Utility app configuration.
2 Fed App substitutes actual values for${host},${tenant_id}and${appsdk_version}.
Step 2: Configure the OIDC (back-end)
Enable external IdP on the DigipassONE API Server by:
Uploading an external IdP configuration file via the Admin Console.
Navigating to Configuration > API Server > Federated Identity Management > External Identity Provider and clicking Add OIDC Provider.
External IdP configuration file
The JSON configuration file includes mandatory and optional fields for configuration:
Field Name | Requirement | Description | Notes |
|---|---|---|---|
| Mandatory | String. The registrationId is a unique identifier, within the tenant, for the registration of an OIDC client. | - |
| Mandatory | String. OAuth 2.0 Client identifier which uniquely identifies the client to the IdP server. | - |
| Mandatory | String. A secret that proves the authenticity of the Client's requests. | - |
| Mandatory | OAuth 2.0 authorization grant type, used to exchange an authorization code for an access token. | The only type supported is |
| Mandatory | The authentication method used when authenticating the client with the authorization server. | One of the following standard methods for client authentication:
|
| Optional | Instructs the authorization server how to return the authorization code to the client. | Supported values are:
|
| Mandatory | The scope(s) requested during the authorization request flow. | You must include the scope |
| Optional | URI for the authorization endpoint. If not specified, this is retrieved from the metadata. | See |
| Optional | URI for the token endpoint. If not specified, this is retrieved from the metadata. | See |
| Optional | URI for the JSON Web Key (JWK) Set endpoint. If not specified, this is retrieved from the metadata. | See |
| Optional | URI for the user info endpoint. If not specified, this is retrieved from the metadata. | See |
| Mandatory | The end user is redirected to this endpoint after authentication is completed. | The URI must match the predefined pattern: |
| Mandatory | The issuer URI for an OpenID Connect 1.0 Provider. The provider supplies OIDC Provider Metadata for configuration. | Refer to OpenID Connect Discovery 1.0 incorporating errata set 2. If any one of these parameters is not provided: |
| Optional | This is a logical name of the client or registration. | If not specified, the registration ID is assigned to |
| Optional | The name of the attribute in the user information response from the external IdP that the API Server uses to identify the end user. | When the API Server creates a session JWT, it uses the value of this attribute to obtain the username. For example, if you specify |
| Optional | The name of the attribute in the claim received from the external IdP that the client app uses as the user's display name. The value is displayed at the top of the credential management page after Signed in as. | If both |
| Optional | The name of the attribute in the claim received from the external IdP that the client app uses as the username to identify the authenticated user. | This username is displayed in the passkey UI and also at the top of the credential management page after Signed in as. If you configure both |
| Optional | URI for the check-session iframe endpoint used for periodic session-state checks. | When |
| Optional | URI for the end session endpoint. If not specified, this is retrieved from the metadata. | See |
1In some instances, this may appear as OneSpan App Config.
Example JSON files
Client registration JSON without OpenID provider
This is an example of a client registration JSON that does not use an OpenID Provider to supply metadata. As a result, the issuer must be specified in the issuerUri parameter in the configuration, along with the endpoints for:
authorization
token
user info
the JWKS
endSessionEndpoint
checkSessionIframeUrl
if check-session iframe is enabled in API Server app config.
{
"registrationId":"pingone_external_idp1",
"clientId":"f840f954-7b0f-4771-a694-fb6d2fecff28",
"clientSecret":"unencrypted_secret",
"authorizationGrantType":"authorization_code",
"clientAuthenticationMethod":"client_secret_basic",
"redirectUri":"https://<host:port>/nnlfedapp/resp.jsp?reg_id=<regID>&tenant_id=<tenantId>",
"scopes":["openid", "email"],
"issuerUri":"https://<external-idp-url>/as",
"authorizationEndpoint":"https://<external-idp-url>/as/authorize",
"tokenEndpoint":"https://<external-idp-url>/as/token",
"userInfoEndpoint":"https://<external-idp-url>/as/userinfo",
"jwkSetUri":"https://<external-idp-url>/as/jwks",
"userNameAttributeName":"email",
"endSessionEndpoint":"https://<external-idp-url>/as/logout",
"checkSessionIframeUrl":"https://<external-idp-url>/as/check_session_iframe"
}Client registration JSON with OpenID provider
An example of a client registration JSON where the OpenID Provider, specified in issuerUri, supplies the configuration metadata.
{
"registrationId":"pingone_external_idp1",
"clientId":"f840f954-7b0f-4771-a694-fb6d2fecff28",
"clientSecret":"unencrypted_secret",
"authorizationGrantType":"authorization_code",
"clientAuthenticationMethod":"client_secret_basic",
"redirectUri":"https://<host:port>/nnlfedapp/resp.jsp?reg_id=<regID>&tenant_id=<tenantId>",
"scopes":["openid", "email"],
"issuerUri":"https://<external-idp-url>/as",
"userNameAttributeName":"email"
}