Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Android-Specific Issues

Prev Next

Review the following list of Android-specific troubleshooting steps prior to contacting Nok Nok support.

  1. Review the device logs by doing the following. Plug the Android device into your computer. Use logcat or Android Studio to review the logs to look for exceptions, errors, and failures.

  2. Verify that you are running a supported OS version, Android 5.0 and later.

  3. Verify that the Android device has never been rooted.

  4. Verify that your Server has TLS 1.2 support.

  5. If you are testing using Tutorial App, ensure that there is at least one ASM available.

ASM (Such as PIN, Fingerprint) Does Not Work on an Android Device

Problem

PIN, Fingerprint or any ASM does not work.

Description

Using an Android device, you are unable to use the sample PIN, Fingerprint or any other ASM that was provided as part of the App SDK.

Steps

  1. Review logcat logs and server logs and look for exceptions, errors, and failures.

  2. Ensure that the ASM is correctly embedded in the application.

  3. Check that the correct metadata for the ASM is present in the Server DB.

  4. Check that the AAID for the ASM is present in the server policy.

  5. Clear any data that is cached by your app.

  6. Verify that you are running a supported OS version, Android 4.4 or newer

  7. Verify that the Android device has never been rooted.

  8. Verify that your Server has TLS 1.2 support

  9. Verify that your Server has a valid certificate and that your Android device trusts the Server certificate.

PROTOCOL_ERROR in Logs

Problem

Logs show a “PROTOCOL_ERROR”.

Description

Using an Android device, you are unable to register or authenticate using an authenticator.

Steps

  1. Capture the message flow between individual components and validate the messages for FIDO conformance using the Conformance Tool at https://fidoalliance.org/certification/functional-certification/conformance/.

Message flow should be captured between these components:

  • The server and your app

  • Your app and the App SDK

  • The App SDK and the ASM

  1. Verify that your Server has TLS 1.2 support

  2. Verify that your Server has a valid certificate, and that your Android device trusts the Server certificate.

Unable to Register a Fingerprint or PIN Authenticator using a Remote Client

Problem

When using a remote client, unable to register a fingerprint or PIN authenticator.

Description

Using an Android device, you are unable to register or authenticate using a fingerprint authenticator and the following message appears in the logs:

No peer certificate
Server returned error on getRegistrations

Steps

Verify that the Server has TLSv1.2 support.

Unable to Register a Fingerprint or PIN Authenticator using a Remote Client

Problem

When using a remote client, you are unable to register a fingerprint or PIN authenticator.

Description

Using an Android device, you are unable to register or authenticate using a fingerprint authenticator and the following message appears in the logs:

E/MfaRegisterNewAuthenticator(15867): MFAC returned error
D/AFidoTask(15867): resolveResult ostpResult :APP_NOT_FOUND

Steps

Check if your facet ID is added to the Server facet ID list.

Unable to Register a PIN Authenticator Using an Embedded Client

Problem

Unable to register a PIN authenticator using an embedded client.

Description

Using an Android device, you cannot register or authenticate using a PIN authenticator and the following message appears in the logs:

E/UafProcessor(18360): com.fido.uaf.ver0100.types.UafException: No Suitable authenticator
V/ClientAPI(18360): fidoStatus=NO_MATCH
E/RegisterAuthenticatorFragment(18360): Client Error: NO_MATCH

Steps

Check that the authenticator metadata has been added to the database and that the AAID has been added to the Server FIDO policy.

No Response from the Server

Problem

No response from the Server.

Description

Using an Android device, you are unable to get any response from the Server. The following message appears in the logs:

E/HttpClient(23366): javax.net.ssl.SSLHandshakeException: java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.
E/RegisterAuthenticatorFragment(23366): No response from server. Please check your network settings and try again.

Step

Make sure that the certificate on the Authentication Server is valid and verified by a trusted certificate authority.

UAF Tutorial App Error: APP_NOT_FOUND

Problem

Tutorial App doesn't work with the default evaluation Server. Tutorial App displays the error message:

APP_NOT_FOUND

Description

The facet ID of the application is determined by the signing key. To allow the version of Tutorial App you build to match the facet ID installed on the evaluation Server, you must configure Android Studio to use the default keystore included in the Android Studio folder.

Steps

  1. In the Android studio app level build.gradle file, make sure that the signing key is properly configured.

signingConfigs {
   debug {
       storeFile file("${rootProject.projectDir}/../keystores/default.keystore")
       storePassword "android"
       keyAlias "androiddebugkey"
       keyPassword "android"
   }
}

2. Make sure that the FacetID of the application is added to the server database.

FIDO2 Tutorial App Error: APP_NOT_FOUND

Problem

  • Tutorial App doesn't work with your server. Tutorial App displays the error message:

APP_NOT_FOUND

  • Tutorial Web App doesn’t work with your server. It displays the following error messages:

The relying party ID is not a registrable domain suffix of, nor equal to the current domain.

APP_NOT_FOUND

Description

  • Tutorial App: The app's package name and SHA256 fingerprints of the app's signing certificate are missing from the file assetlinks.json.

  • Tutorial Web App: The web app domain is different from the RP ID configured on the evaluation server.

Steps

  • Tutorial Web App: Using the Server Admin Console, configure the RP ID to be the domain suffix or equal to the webapp origin on the server. For instructions on using the Admin Console, refer to Assign the RP ID. For more information about RP ID, see Determining an RP ID.

After following the above instructions, add the app using the Admin Console so the Authentication Server properly recognizes it. Refer to Configuring an Android App.

FIDO2 Tutorial App Error: Security exception

Problem

The Authentication Server does not recognize Tutorial App or Tutorial Web App as a valid application that it can communicate with. Tutorial App or Tutorial Web App displays the error message:

Server_Error 4402

Description

The app is not in the allow list on the Server. This error applies to any app, not just the Tutorial Apps.

Steps

Verify that you added the app using the Server Admin Console. Refer to Configuring an Android App

MissingRegistered: Missing Registered Class

Problem

Android Lint error: MissingRegistered: Missing registered class.

Description

Builds fail with the error MissingRegistered: Missing registered class.

Steps

Identify the manifest entry that is causing the error, remove, and test. For example this entry in AndroidManifest.xml will cause the error and can be removed:

<activity android:name="com.fido.android.framework.tm.core.SelectFromDialogActivity"

android:screenOrientation="portrait"

android:excludeFromRecents="true">

</activity>

QR Code Works but Push Notifications do not Work on the Client

ProblemAdding Huawei Mobile Services Configuration

Push notifications do not work on the Client but QR code functionality does.

Description

Push notifications require Google Play Services and/or Huawei Mobile Services. Push notifications also require configuring Firebase Cloud Messaging (FCM) and/or Huawei Mobile Services (HMS) as well as the Authentication Server.

Steps

NullPointerException

Problem

After INIT_OOB_AUTH completes successfully, the App SDK throws a NullPointerException, and the subsequent FINISH_OOB_AUTH is not executed.

Description

You did not set both the registration and the authentication URLs for a QR code scan. These URLs override the URLs in the QR code. You must provide both the registration URL and the authentication URL, or both should be null.

Steps

1. Ensure that the OobReceiver.setURLs() method is called correctly.

2. On the Admin Console, navigate to Configuration>Authentication methods>Out-of-band. Check that both the Registration URL and the Authentication URL are set correctly.