System requirements

Prev Next

Ensure that you verify and meet all system requirements before starting the OneSpan Authentication Server installation.

Hardware requirements

Table: OneSpan Authentication Server hardware requirements describes the minimum hardware requirements for OneSpan Authentication Server.

Table: OneSpan Authentication Server hardware requirements
ComponentMinimum requirements
Processor2.3 GHz (64-bit architectures), 4 CPU cores
Memory4 GB
Available disk space60 GB
Display1024x768

Software requirements

Linux distributions

OneSpan Authentication Server supports the following Linux distributions:

  • Red Hat Enterprise Linux 9, 64-bit (version 9.8 or later if you want to use MariaDB 11.8)

  • Red Hat Enterprise Linux 8.10, 64-bit

  • Rocky Linux 9, 64-bit (version 9.8 or later if you want to use MariaDB 11.8)

  • Rocky Linux 8.10, 64-bit

  • Ubuntu Server 24.04 LTS, 64-bit

  • Ubuntu Server 22.04 LTS, 64-bit

Servers without the X Window System will not be able to run the Configuration Utility, the Maintenance Wizard, or the Audit Viewer.

In addition, ensure that your distribution uses the X11 display server. OneSpan Authentication Server does not support the Wayland display server, which is the default environment on some Linux distributions.

OneSpan Authentication Server is designed to support any language version of the supported operating systems. However, the product has only been comprehensively tested on English language versions.

Audit Viewer and Tcl Command-Line Administration tool support the same operating systems as the server components.

Web servers and browsers

Web servers

If you install the Administration Web Interface using the Web Administration Service setup package, all required third-party products are installed as well.

Web Administration Service includes the Azul Zulu Java Runtime Environment. Most of the security issues found in the standard JRE do not affect Web Administration Service deployments. If you want to use a different and more recent JRE version, you need to set up your own Apache Tomcat or IBM WebSphere web application server running on that JRE and deploy Web Administration Service manually.

The Apache Tomcat web application server included in the Web Administration Service setup package officially supports the JRE version included in the Web Administration Service setup package only. OneSpan cannot and does not guarantee correct operation if a JRE version other than the one included in the setup package is used.

If you want to deploy the Administration Web Interface to an existing Web server manually, the following requirements apply.

The Administration Web Interface can be run on these web application servers (based on the respective JRE):

  • Apache Tomcat 10.1.57

    • Oracle Server Java Runtime Environment 17

    • Azul Zulu 17

  • Open Liberty (tested with 25.0.0.1-full-java17-openj9)

  • WebSphere Liberty (tested with 25.0.0.1-full-java17-openj9-ubi)

The OneSpan Authentication Server product CD contains a version of Web Administration Service adapted for Open Liberty and WebSphere Liberty for manual deployment.

Deployment on OpenLiberty or WebSphere Liberty

To deploy on Open Liberty or WebSphere Liberty, ensure that you choose a version that supports Jakarta EE 10 and JDK 17.

By default, Java EE 8 is used, and you need to explicitly enable Jakarta EE 10 in the web application server configuration file (server.xml):

<featureManager>
    <feature>jakartaee-10.0</feature>
</featureManager>

Browsers

The Administration Web Interface supports the following browsers:

  • Google Chrome

  • Mozilla Firefox

  • Microsoft Edge

The Administration Web Interface supports all browser versions currently supported by the respective vendors.

The Apache Tomcat web server installed with OneSpan Authentication Server is pre-configured to provide the Administration Web Interface via SSL by default. On some browsers, accessing the SSL-secured Administration Web Interface may result in a Certificate Error or Certificate Invalid warning. If this occurs, simply import the Administration Web Interface certificate to the browser's Trusted Sites list, or add an exception for the Administration Web Interface.

For more information, see Encrypted communication.

ODBC databases

OneSpan Authentication Server supports the following database systems as its data store:

  • MariaDB 11.8.6

    OneSpan Authentication Server is fully compatible with data-at-rest encryption as provided by MariaDB.

  • Oracle Database 19c

    OneSpan Authentication Server is fully compatible with Transparent Data Encryption (TDE) as provided by Oracle Database to protect data at rest (tablespace encryption).

  • PostgreSQL 17.9

    OneSpan Authentication Server has been tested with Transparent Data Encryption (TDE) as provided by the Percona TDE extension to protect data at rest (tablespace encryption).

  • Microsoft SQL Server

    • Microsoft SQL Server 2025

    • Microsoft SQL Server 2022

    • Microsoft SQL Server 2019

    • Microsoft SQL Server 2017

    OneSpan Authentication Server supports the SQLServer AlwaysOn Availability Groups feature for Microsoft SQL Server.

    OneSpan Authentication Server is fully compatible with Transparent Data Encryption (TDE) as provided by Microsoft SQL Server to protect data at rest.

ODBC driver

Any ODBC driver used must be Unicode-compliant and use 2-byte SQLWCHAR and 8-byte SQLLEN for 64-bit systems.

Microsoft SQL Server

The required and supported ODBC driver version for each SQL Server version depends on your specific environment. For more information, refer to https://learn.microsoft.com/en-us/sql/connect/odbc/linux-mac/system-requirements?view=sql-server-ver17 (last accessed May 8, 2026).

unixODBC

OneSpan Authentication Server requires unixODBC to be installed and properly configured. unixODBC is an open-source third-party library, and we do not maintain, license, or include it in the product setup.

Depending on your Linux distribution, unixODBC may already be installed. Otherwise, you can obtain and install it from www.unixodbc.org. In any case, it is your responsibility to install unixODBC and keep it up to date.

Other requirements

LDAP servers

OneSpan Authentication Server requires an LDAP server to perform LDAP synchronization. LDAP servers can also be used for back-end authentication.

The following LDAP servers are supported:

  • Microsoft Active Directory Domain Services on Windows Server 2025

  • Microsoft Active Directory Domain Services on Windows Server 2022

  • Microsoft Active Directory Domain Services on Windows Server 2019

  • IBM Security Directory Server 6.3

  • OpenLDAP 2

When configuring LDAP back-end authentication with SASL-DIGEST-MD5, the cyrus-sasl-md5 library must be installed to ensure connectivity between OneSpan Authentication Server and the supported back-end authentication servers!

Virtualization platforms

If required, OneSpan Authentication Server can run as a virtual image (on any supported operating system) on the following hypervisor platforms:

  • Citrix XenServer

  • Microsoft Hyper-V Server

  • VMWare ESXi

OneSpan Authentication Server does not integrate specific hypervisor features, the software is not aware that it is running on a virtualized host. OneSpan support for hypervisors in OneSpan Authentication Server and its related product components is limited to installing, running, and testing the software on all supported operating systems installed as a guest operating system on a virtual machine on the supported hypervisors listed here. OneSpan does neither include nor support specific hypervisor functionality in the software.

Hardware security modules (HSM)

OneSpan Authentication Server supports the following hardware security modules:

  • Entrust nShield 5c

  • Entrust nShield 5s

  • Entrust nShield Connect XC

  • Entrust nShield Solo XC

  • Thales ProtectServer 3 series

When using an Entrust nShield HSM, the Entrust nShield runtime package must be installed on the OneSpan Authentication Server host. In addition, the following Entrust nShield packages provide additional tools to manage the HSM:

  • Entrust nShield Core Tools

  • CodeSafe

For more information, see Hardware security module setup.