Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Preregistered Digipass Keys

Prev Next

Introduction

You can purchase Digipass security keys from OneSpan and request that they be preregistered for users of the Nok Nok Authentication Server. OneSpan provides the Digipass security keys to you, along with information in a cryptographically protected CSV or TSV file. Follow these instructions to obtain the metadata for the Digipass security keys and manage Digipass registrations for users of your Nok Nok Authentication Server. This allows end users to immediately use the Digipass, and also allows you to deregister a lost or stolen Digipass.

Prerequisites

  • OneSpan Digipass keys preprovisioned for the Nok Nok Authentication Server.

  • Registration information in a cryptographically protected CSV or TSV file, provided by OneSpan.

  • Admin access to a Nok Nok Authentication Server and its command line interface ./nnl-mgmt.sh

  • A Username in the Nok Nok Auth Server for each end user that needs to use a Digipass.

Instructions

The following sections tell how to:

  • Download and import the metadata for the Digipass security keys.

  • Import the registration information from OneSpan and bind each Digipass to a registered user.

  • Purge a lost or stolen Digipass.

  • Reuse a Digipass.

Obtain the metadata

You only need to download and import the metadata once, no matter how many times you preregister Digipass security keys. However, it is good practice to update the metadata regularly. For instructions see Update authenticator metadata.

Step 1

Download the metadata for all authenticators published to the FIDO Metadata Service, including the Digipass security keys:

./nnl-mgmt.sh auth_metadata download -dir mds

Step 2

Locate the metadata files that contain the word "DIGIPASS", select the one with the correct AAGUID, and move it into a new folder in the fido2 folder.

Step 3

Import the metadata for the Digipass security keys into the Nok Nok Authentication Server:

./nnl-mgmt.sh auth_metadata import -file mds/metadata/fido2/<digipassmetadata>

Import the registrations and bind the Digipass Security Key

Step 1

Import the registration information from the CSV or TSV file into the Nok Nok Authentication Server.

./nnl-mgmt.sh pre_reg import -file <name-of-reg-info-file-from-OneSpan>.tsv -tenantid default

Only complete this Step 1. once for each set of keys. Complete Step 2 as many times as you need to.

Step 2

2.a If you are binding just one Digipass to one user, start by finding the serial number of the Digipass key using the pre_reg list command:

./nnl-mgmt.sh pre_reg list -tenantid default

Bind the serial number to an existing user with the pre_reg bind command.

./nnl-mgmt.sh pre_reg bind -serialnumber <serial number> -username <username> -tenantid default

After you complete this command, the user can authenticate with this Digipass.

2.b If you are binding a set of Digipass Security Keys to a set of end users:

Make a copy of the registration information file that you received from OneSpan. For example, name the copy "bulk_bind.csv". Edit the bulk_bind.csv file so that it has only three columns: serialnumber, username, and userdisplayname and ensure that it is in CSV format.

Using the pre_reg bulkbind command, bind the list of serial numbers to the list of existing users:

./nnl-mgmt.sh pre_reg bulkbind -file bulk_bind.csv -tenantid default

After executing this command, all of the users whose names are in bulk_bind.csv can authenticate with their assigned Digipass.

Step 3

Ship the assigned Digipass to each end user.

Purge a Digipass

If one of the Digipass keys is lost or damaged, or if a former user does not return it, purging it takes any record of the Digipass out of the Auth Server. If you later want to reuse the purged Digipass, treat it as a brand new Digipass key and import the preregistration information again.

To purge a Digipass key, first unbind and delete it. The following CLI commands unbind and delete the Digipass with serial number 7150852047:

./nnl-mgmt.sh pre_reg unbind -serialnumber 7150852047 -tenantid default

        ./nnl-mgmt.sh pre_reg delete -serialnumber 7150852047 -tenantid default

The final step is to purge it from the Authentication Server database.

./nnl-mgmt.sh pre_reg purge -tenantid default

Note that the pre_reg purge command removes all previously deleted Digipass keys from the Server.

Assign a Digipass to a different user

If a preregistered Digipass is shipped to the wrong user, or if a former user returns a Digipass, you can unbind the key from its current user and then rebind it to a different user. The following CLI commands unbind and then rebind the Digipass with serial number 7150852047:

./nnl-mgmt.sh pre_reg unbind -serialnumber 7150852047 -tenantid default

        ./nnl-mgmt.sh pre_reg bind -serialnumber 7150852047 -username Joe -tenantid default

Reference to the CLI pre_reg command

pre_reg modifier

Description

Example

bind

Bind a specific Digipass key identified by a serial number to a particular username.

./nnl-mgmt.sh pre_reg bind -serialnumber 7150852046 -username Joe -tenantid default

bulkbind

Bulkbind one or more Digipass keys to one or more specific users. Each Digipass is identified by a serial number, and each user is identified by a User name.

Bulk bind takes a csv file containing the below columns ordered -

  • Serial number(required)

  • User name(required)

  • Display name(optional)

./nnl-mgmt.sh pre_reg bulkbind -file bulk_bind.csv -tenantid default

delete

Delete the unbound key that is identified by the serial number. Operation fails if the key is bound to a user.

./nnl-mgmt.sh pre_reg delete -serialnumber 7150852047 -tenantid default

help

Displays all possible commands and arguments.

./nnl-mgmt.sh pre_reg help

import

Import the preprovisioning information from the tsv or csv file into the Auth Server.

./nnl-mgmt.sh pre_reg import -file filename.tsv -tenantid default

list

List the status of previously imported preregistrations. Status contains:

PENDING (0) - Unbound key is free to use or bind

ACTIVE (1) - Digipass is bound to a particular user

DELETED (2) - Deleted or lost key

./nnl-mgmt.sh pre_reg list -tenantid default

purge

Purge all previously deleted Digipass security keys from a specific tenant.

./nnl-mgmt.sh pre_reg purge -tenantid default

unbind

Unbind a specific Digipass key from a user. Identify the Digipass by its serial number.

./nnl-mgmt.sh pre_reg unbind -serialnumber 7150852047 -tenantid default