OneSpan Authentication Server consists of various required and optional components.
Required components
OneSpan Authentication Server service
OneSpan Authentication Server is a server component that performs authentication, signature validation, administration, and provisioning tasks. It runs as a service.
Data store
All information required by OneSpan Authentication Server is stored in an ODBC-compliant database. You can use the embedded MariaDB database included with OneSpan Authentication Server or your own database system.
Web Administration Service
Web Administration Service allows administrating the OneSpan Authentication Server data store using a web interface. It can be installed together with the OneSpan Authentication Server service on the same computer, or separately on another computer.
Web Administration Service includes:
Administration Web Interface
Embedded Web Application Server (Apache Tomcat)
Embedded Java Runtime Environment (Azul Zulu)
Open source software
OneSpan uses various open source software included in OneSpan Authentication Server and its components.
The list of the open source software used and the respective license texts can be found in the OneSpan Authentication Server installation folder or its respective components.
Parts of the open source software is licensed under the General Public License (GPL). Upon customer’s request OneSpan can provide source codes with our adaptations to the respective software on DVD for a small fee for the medium. These source codes can be freely copied, extended, modified, and redistributed without any restrictions from OneSpan or our end-user license agreement.
Optional components
Embedded database
An embedded MariaDB database is available for use with OneSpan Authentication Server. If the embedded database is installed, the DBeaver database tool is also installed.
Message Delivery Component
This is a service delivering authentication information through an email, SMS, voice, or Push Notification gateway to the mobile device of a user. The connection can be secured with SSL.
Each gateway type uses a specific connection protocol:
HTTP/HTTPS (voice, SMS, or Push Notification)
SMPP 3.4 rev 1.2 (SMS only)
SMTP/SMTPS (email only)
Tcl Command-Line Administration tool
Administrative tasks may be carried out using Tcl Command-Line Administration tool, which allows interactive command-line and scripted administration of OneSpan Authentication Server data.
Audit Viewer
The Audit Viewer is a GUI application that can display and filter audit messages from OneSpan Authentication Server. It can read the data from text files and ODBC databases or receive a live feed from OneSpan Authentication Server.
Additional components
OneSpan Authentication Server SDK
The OneSpan Authentication Server SDK allows creation of custom SOAP clients and authentication engines, using the SOAP interface. This is an upgrade add-on to OneSpan Authentication Server and will only be available for installation if it has been purchased. The SDK is available as a separate installation package.
Password Synchronization Manager
Password Synchronization Manager automatically updates a changed Windows password on OneSpan Authentication Server. The product is installed on the Active Directory domain controller. The new Windows password will be reflected as the static password on OneSpan Authentication Server.
When the Windows password is changed, it is updated on the domain controller. PSM checks for the availability of OneSpan Authentication Server before sending the new password to OneSpan Authentication Server so that the data store can be updated.
If OneSpan Authentication Server is not available, the synchronization will fail.
If the user is not defined in OneSpan Authentication Server, only the password on the domain controller will be changed.
For more information, refer to the Password Synchronization Manager User Guide.
Digipass Authentication for Windows Logon
Digipass Authentication for Windows Logon provides strong authentication when logging on to Microsoft Windows. With this type of authentication, a user logs on to Microsoft Windows using the following:
User ID
Password
A one-time password (OTP) generated by an authenticator
Server PIN
The credentials used by Digipass Authentication for Windows Logon are either validated directly by OneSpan Authentication Server (online authentication) or using offline authentication data (OAD) previously generated by OneSpan Authentication Server (offline authentication). Whether Digipass Authentication for Windows Logon performs an online or an offline authentication depends on the availability of the OneSpan Authentication Server instance and is completely transparent to the user.
Digipass Authentication for Windows Logon consists of a client software package, which is installed on the client computer, and server-side functionality, which is part of OneSpan Authentication Server. Digipass Authentication for Windows Logon requires a valid license to enable it on OneSpan Authentication Server.
For more information about Digipass Authentication for Windows Logon, refer to the product documentation.
LDAP Synchronization Tool
LDAP Synchronization Tool is used to synchronize user information on OneSpan Authentication Server with external LDAP databases. For more information, refer to the LDAP Synchronization Tool Administrator Guide.
Data Migration Tool
The OneSpan Data Migration Tool is a general-purpose utility that allows you to migrate your data from one authentication product to another. It requires a separate installation. For more information, refer to the Data Migration Tool Administrator Guide.