Introduction
You can purchase Digipass security keys from OneSpan and request that they be preregistered for users of the Nok Nok Authentication Server. OneSpan provides the Digipass security keys to you, along with information in a cryptographically protected CSV or TSV file. Follow these instructions to obtain the metadata for the Digipass security keys and manage Digipass registrations for users of your Nok Nok Authentication Server. This allows end users to immediately use the Digipass, and also allows you to deregister a lost or stolen Digipass.
Prerequisites
OneSpan Digipass keys preprovisioned for the Nok Nok Authentication Server.
Registration information in a cryptographically protected CSV or TSV file, provided by OneSpan.
Admin access to a Nok Nok Authentication Server and its command line interface ./nnl-mgmt.sh
A Username in the Nok Nok Auth Server for each end user that needs to use a Digipass.
Instructions
The following sections tell how to:
Download and import the metadata for the Digipass security keys.
Import the registration information from OneSpan and bind each Digipass to a registered user.
Purge a lost or stolen Digipass.
Reuse a Digipass.
Obtain the metadata
You only need to download and import the metadata once, no matter how many times you preregister Digipass security keys. However, it is good practice to update the metadata regularly. For instructions see Update authenticator metadata.
Step 1
Download the metadata for all authenticators published to the FIDO Metadata Service, including the Digipass security keys:
./nnl-mgmt.sh auth_metadata download -dir mdsStep 2
Locate the metadata files that contain the word "DIGIPASS", select the one with the correct AAGUID, and move it into a new folder in the fido2 folder.
Step 3
Import the metadata for the Digipass security keys into the Nok Nok Authentication Server:
./nnl-mgmt.sh auth_metadata import -file mds/metadata/fido2/<digipassmetadata>Import the registrations and bind the Digipass Security Key
Step 1
Import the registration information from the CSV or TSV file into the Nok Nok Authentication Server.
./nnl-mgmt.sh pre_reg import -file <name-of-reg-info-file-from-OneSpan>.tsv -tenantid defaultOnly complete this Step 1. once for each set of keys. Complete Step 2 as many times as you need to.
Step 2
2.a If you are binding just one Digipass to one user, start by finding the serial number of the Digipass key using the pre_reg list command:
./nnl-mgmt.sh pre_reg list -tenantid defaultBind the serial number to an existing user with the pre_reg bind command.
./nnl-mgmt.sh pre_reg bind -serialnumber <serial number> -username <username> -tenantid defaultAfter you complete this command, the user can authenticate with this Digipass.
2.b If you are binding a set of Digipass Security Keys to a set of end users:
Make a copy of the registration information file that you received from OneSpan. For example, name the copy "bulk_bind.csv". Edit the bulk_bind.csv file so that it has only three columns: serialnumber, username, and userdisplayname and ensure that it is in CSV format.
Using the pre_reg bulkbind command, bind the list of serial numbers to the list of existing users:
./nnl-mgmt.sh pre_reg bulkbind -file bulk_bind.csv -tenantid defaultAfter executing this command, all of the users whose names are in bulk_bind.csv can authenticate with their assigned Digipass.
Step 3
Ship the assigned Digipass to each end user.
Purge a Digipass
If one of the Digipass keys is lost or damaged, or if a former user does not return it, purging it takes any record of the Digipass out of the Auth Server. If you later want to reuse the purged Digipass, treat it as a brand new Digipass key and import the preregistration information again.
To purge a Digipass key, first unbind and delete it. The following CLI commands unbind and delete the Digipass with serial number 7150852047:
./nnl-mgmt.sh pre_reg unbind -serialnumber 7150852047 -tenantid default
./nnl-mgmt.sh pre_reg delete -serialnumber 7150852047 -tenantid defaultThe final step is to purge it from the Authentication Server database.
./nnl-mgmt.sh pre_reg purge -tenantid defaultNote that the pre_reg purge command removes all previously deleted Digipass keys from the Server.
Assign a Digipass to a different user
If a preregistered Digipass is shipped to the wrong user, or if a former user returns a Digipass, you can unbind the key from its current user and then rebind it to a different user. The following CLI commands unbind and then rebind the Digipass with serial number 7150852047:
./nnl-mgmt.sh pre_reg unbind -serialnumber 7150852047 -tenantid default
./nnl-mgmt.sh pre_reg bind -serialnumber 7150852047 -username Joe -tenantid defaultReference to the CLI pre_reg command
pre_reg modifier | Description | Example |
|---|---|---|
bind | Bind a specific Digipass key identified by a serial number to a particular username. | ./nnl-mgmt.sh pre_reg bind -serialnumber 7150852046 -username Joe -tenantid default |
bulkbind | Bulkbind one or more Digipass keys to one or more specific users. Each Digipass is identified by a serial number, and each user is identified by a User name. Bulk bind takes a csv file containing the below columns ordered -
| ./nnl-mgmt.sh pre_reg bulkbind -file bulk_bind.csv -tenantid default |
delete | Delete the unbound key that is identified by the serial number. Operation fails if the key is bound to a user. | ./nnl-mgmt.sh pre_reg delete -serialnumber 7150852047 -tenantid default |
help | Displays all possible commands and arguments. | ./nnl-mgmt.sh pre_reg help |
import | Import the preprovisioning information from the tsv or csv file into the Auth Server. | ./nnl-mgmt.sh pre_reg import -file filename.tsv -tenantid default |
list | List the status of previously imported preregistrations. Status contains: PENDING (0) - Unbound key is free to use or bind ACTIVE (1) - Digipass is bound to a particular user DELETED (2) - Deleted or lost key | ./nnl-mgmt.sh pre_reg list -tenantid default |
purge | Purge all previously deleted Digipass security keys from a specific tenant. | ./nnl-mgmt.sh pre_reg purge -tenantid default |
unbind | Unbind a specific Digipass key from a user. Identify the Digipass by its serial number. | ./nnl-mgmt.sh pre_reg unbind -serialnumber 7150852047 -tenantid default |