Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Enabling FIDO2

Prev Next

The information in this Section is specific to native FIDO2. At this time, FIDO2 multi-device passkey support requires a device running Android 9+. See https://passkeys.dev/device-support/ for current platform compatibility information.

If you want to allow users to seamlessly share FIDO2 credentials across your website and your Android application, the website owner must declare associations with apps in an assetlinks.json file. See https://evaluation93.noknoktest.com:8443/.well-known/assetlinks.json for an example.

The steps to create assetlinks.json are described below. For more information, refer to Google’s documentation about setting up interoperability with your website at https://developers.google.com/identity/fido/android/native-apps.

  1. Create a directory named .well-known under the website root.

  2. Add a json file assetlinks.json to the .well-known directory with the mobile application configurations.

    1. Make sure the file is accessible from a public network, in other words, crawlable from Google and is served with HTTP header Content_Type: application/json.

    2. The file should be accessible without any 301 or 302 redirects.

  3. Add configuration details in the assetlinks.json file. For example, to set up the Tutorial App mobile browser integration via FIDO2, add the following:

[{
    "relation": ["delegate_permission/common.handle_all_urls"],
    "target": {
        "namespace": "android_app",
        "package_name": "com.noknok.android.tutorialappplus",
        "sha256_cert_fingerprints": ["F1:C0:35:0C:F3:54:42:60:21:4B:56:6B:B6:6A:39:18:62:58:01:24:62:61:41:FA:BE:9F:CE:3C:1A:68:28:88"]
    }
}]

When customizing your own app, replace the "com.noknok.android.tutorialappplus" package name with your own package name. You must also provide sha256 fingerprints of your app signing certificates in the "sha256_cert_fingerprints" array. You can provide more than one fingerprint, for example, one fingerprint each for debug and production builds.

  1. Create a directory named WEB-INF under the .well-known directory, then create a file named web.xml that has the following configuration:

<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://java.sun.com/xml/ns/javaee" xmlns:web="http://java.sun.com/xml/ns/javaee" xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" id="WebApp_ID" version="2.5">
    <display-name>.wellknown</display-name>
    <mime-mapping>
        <extension>json</extension>
        <mime-type>application/json</mime-type>
    </mime-mapping>
</web-app>
  1. assetlinks.json needs to be accessible using HTTPs and port 443. You might need to add a connector to your server.xml file in <tomcat_home>/conf as follows:

<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
               maxThreads="150" SSLEnabled="true">
  <SSLHostConfig certificateVerification="none">
    <Certificate certificateKeystoreFile="/usr/share/tomcat/cert/noknoktest.com.pkcs12"
        certificateKeystorePassword="password"
        certificateKeystoreType="PKCS12"
        sslProtocols="TLS"
        type="RSA"
    />
  </SSLHostConfig>
</Connector>

As of January 2023, Android's FIDO2 implementation works without taking the additional steps mentioned in Google's Documentation.