You can easily export one or more Adaptive Rulesets, along with their dependencies. This enables you to freely experiment with different variations of a ruleset in your development environment as well as copying a tested and curated ruleset to your production environment.
Dependencies for an Adaptive Ruleset include FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the ruleset.
Exporting
Using the Admin Console
Login to the Admin Console and, if needed, switch to the tenant whose Adaptive Ruleset(s) you want to export.
Navigate to Authentication > Rulesets.
To export all active rulesets, click Export Active.
To export a specific ruleset, either in an active or draft status, locate the ruleset in the table and, in the same row, click the download icon in the Actions column.
The Export Ruleset dialog appears.

To include all the objects that a ruleset uses, select the With dependencies checkbox. Dependencies for an Adaptive Ruleset include FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the ruleset.
You can optionally select the Include authenticator metadata checkbox to export authenticator metadata. This option is only valid if you checked With dependencies. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 installation. Normally, you should use the instructions in Update Authenticator Metadata to import metadata.
Click Export. You are prompted for the destination folder for the export.
If you are exporting one or more rulesets without dependencies or authenticator metadata, the Admin Console saves the ruleset(s) in a JSON file.
If you are exporting rulesets with their dependencies (and authenticator metadata), the Admin Console saves all the objects in a ZIP file.
Using nnl-mgmt.sh
Use nnl-mgmt.sh's ruleset export command. The example below exports the Adaptive Ruleset called PSD2Compliance and its dependent objects from a tenant with ID Europe. The resulting file is a ZIP file.
./nnl-mgmt.sh ruleset export -name PSD2Compliance -tenantid Europe -with-dependencies yesFor details on nnl-mgmt.sh's ruleset export command, see Adaptive Ruleset Commands in the reference Command Line Interface. There are additional parameters to this command to specify the ruleset file’s directory and export authenticator metadata.
Importing
Using the Admin Console
Login to the Admin Console and, if needed, switch to the tenant where you want to import Adaptive Ruleset(s).
Navigate to Authentication > Rulesets. To import from a ruleset file, click Import.
The Import Adaptive Rulesets dialog appears.

To select the ruleset file for import, click Choose File and navigate to the file’s location. If the file is larger than 512 KB, you need to use ./nnl-mgmt.sh to change the default maximum size. See Note below.
If the ruleset file is a ZIP file, you can optionally use the checkboxes in this dialog.
To overwrite rulesets and dependent objects with the same name, select the Overwrite any existing ruleset with the same name checkbox. Overwrite handles objects differently depending on their type and status, as shown in the table below.
Object | Status of Existing Object | Result |
|---|---|---|
Ruleset | draft | The system overwrites the existing ruleset with the one from the file. |
active | The system creates a new draft ruleset with the same name from the one in the file. | |
FIDO Policy | draft | The system overwrites the existing FIDO policy with the one from the file and changes its status to active. All rulesets, whether active or draft, must use active FIDO policies. |
active | The system overwrites the existing FIDO policy with the one from the file and changes its status to active. | |
Lists | N/A | The system overwrites the existing list with the one from the file. This is true even if the list is being used by a different active ruleset. |
Authenticator Groups | N/A | The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy. |
You can optionally select the Import and overwrite metadata checkbox to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in a Digipass S3 installation and overwriting metadata could have unintended consequences. Normally, you should use the instructions in Update Authenticator Metadata to import metadata.
Change the default maximum ruleset size by using nnl-mgmt.sh to update the nnl.rulesets.file.size.kb property for the Admin tenant, as shown below.
Changing the maximum size of the ruleset file to 1024 KB:
./nnl-mgmt.sh properties set -name nnl.rulesets.file.size.kb -value 1024 -tenantid AdminUsing nnl-mgmt.sh
Use nnl-mgmt.sh's ruleset import command. The example below imports the Adaptive Rulesets and their dependent objects into the tenant with ID NorthAmerica.
./nnl-mgmt.sh ruleset import -file EuropeRulesets.zip -tenantid NorthAmerica -overwrite yesFor details on nnl-mgmt.sh's ruleset import command, see Adaptive Ruleset Commands in the reference to Command Line Interface. There are additional parameters to this command to import authenticator metadata.