Review the following list of Android-specific troubleshooting steps prior to contacting Nok Nok support.
Review the device logs by doing the following. Plug the Android device into your computer. Use logcat or Android Studio to review the logs to look for exceptions, errors, and failures.
Verify that you are running a supported OS version, Android 5.0 and later.
Verify that the Android device has never been rooted.
Verify that your Server has TLS 1.2 support.
If you are testing using Tutorial App, ensure that there is at least one ASM available.
ASM (Such as PIN, Fingerprint) Does Not Work on an Android Device
Problem | PIN, Fingerprint or any ASM does not work. |
|---|---|
Description | Using an Android device, you are unable to use the sample PIN, Fingerprint or any other ASM that was provided as part of the App SDK. |
Steps |
|
PROTOCOL_ERROR in Logs
Problem | Logs show a “PROTOCOL_ERROR”. |
|---|---|
Description | Using an Android device, you are unable to register or authenticate using an authenticator. |
Steps |
|
Unable to Register a Fingerprint or PIN Authenticator using a Remote Client
Problem | When using a remote client, unable to register a fingerprint or PIN authenticator. |
|---|---|
Description | Using an Android device, you are unable to register or authenticate using a fingerprint authenticator and the following message appears in the logs: |
Steps | Verify that the Server has TLSv1.2 support. |
Unable to Register a Fingerprint or PIN Authenticator using a Remote Client
Problem | When using a remote client, you are unable to register a fingerprint or PIN authenticator. |
|---|---|
Description | Using an Android device, you are unable to register or authenticate using a fingerprint authenticator and the following message appears in the logs: |
Steps | Check if your facet ID is added to the Server facet ID list. |
Unable to Register a PIN Authenticator Using an Embedded Client
Problem | Unable to register a PIN authenticator using an embedded client. |
|---|---|
Description | Using an Android device, you cannot register or authenticate using a PIN authenticator and the following message appears in the logs: |
Steps | Check that the authenticator metadata has been added to the database and that the AAID has been added to the Server FIDO policy. |
No Response from the Server
Problem | No response from the Server. |
|---|---|
Description | Using an Android device, you are unable to get any response from the Server. The following message appears in the logs: |
Step | Make sure that the certificate on the Authentication Server is valid and verified by a trusted certificate authority. |
UAF Tutorial App Error: APP_NOT_FOUND
Problem | Tutorial App doesn't work with the default evaluation Server. Tutorial App displays the error message: APP_NOT_FOUND |
|---|---|
Description | The facet ID of the application is determined by the signing key. To allow the version of Tutorial App you build to match the facet ID installed on the evaluation Server, you must configure Android Studio to use the default keystore included in the Android Studio folder. |
Steps |
2. Make sure that the FacetID of the application is added to the server database. |
FIDO2 Tutorial App Error: APP_NOT_FOUND
Problem |
APP_NOT_FOUND
The relying party ID is not a registrable domain suffix of, nor equal to the current domain. APP_NOT_FOUND |
|---|---|
Description |
|
Steps |
After following the above instructions, add the app using the Admin Console so the Authentication Server properly recognizes it. Refer to Configuring an Android App. |
FIDO2 Tutorial App Error: Security exception
Problem | The Authentication Server does not recognize Tutorial App or Tutorial Web App as a valid application that it can communicate with. Tutorial App or Tutorial Web App displays the error message: Server_Error 4402 |
|---|---|
Description | The app is not in the allow list on the Server. This error applies to any app, not just the Tutorial Apps. |
Steps | Verify that you added the app using the Server Admin Console. Refer to Configuring an Android App |
MissingRegistered: Missing Registered Class
Problem | Android Lint error: MissingRegistered: Missing registered class. |
|---|---|
Description | Builds fail with the error MissingRegistered: Missing registered class. |
Steps | Identify the manifest entry that is causing the error, remove, and test. For example this entry in AndroidManifest.xml will cause the error and can be removed: <activity android:name="com.fido.android.framework.tm.core.SelectFromDialogActivity" android:screenOrientation="portrait" android:excludeFromRecents="true"> </activity> |
QR Code Works but Push Notifications do not Work on the Client
Push notifications do not work on the Client but QR code functionality does. | |
|---|---|
Description | Push notifications require Google Play Services and/or Huawei Mobile Services. Push notifications also require configuring Firebase Cloud Messaging (FCM) and/or Huawei Mobile Services (HMS) as well as the Authentication Server. |
Steps |
|
NullPointerException
Problem | After INIT_OOB_AUTH completes successfully, the App SDK throws a NullPointerException, and the subsequent FINISH_OOB_AUTH is not executed. |
|---|---|
Description | You did not set both the registration and the authentication URLs for a QR code scan. These URLs override the URLs in the QR code. You must provide both the registration URL and the authentication URL, or both should be null. |
Steps | 1. Ensure that the OobReceiver.setURLs() method is called correctly. 2. On the Admin Console, navigate to Configuration>Authentication methods>Out-of-band. Check that both the Registration URL and the Authentication URL are set correctly. |