Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

API Server configuration

Prev Next

After you import a source tenant's API Server configuration into a target tenant, the target tenant is set up with the same overall API Server configuration, including plugins, that is specified in the exported ZIP file from the source tenant. Because the keys for the source and the target tenant have to be different, you must modify the exported ZIP file before you import that file into the target tenant.

Perform the following steps:

  1. Export an existing tenant's API Server configuration. We refer to this tenant as the source tenant.

  2. Modify the configurations in the exported ZIP file to support the functionality you want in the API Server and its plugins in the target tenant.

  3. Import the updated configuration for the API Server into the target tenant.

  4. After importing generate new configuration objects.

API Server and its plugins each have one or more configuration objects.

Exporting

Using the Admin Console

  1. Login to the Admin Console and, if needed, switch to the tenant whose API Server configuration you want to export.

  2. Navigate to Configuration > Import/Export. Scroll down to the API Server section. In the Export Configuration panel, click Export. The contents are compressed into a ZIP file.

Using nnl-mgmt.sh

The example below shows how to export all the API Server configuration files from the marketing tenant.

./nnl-mgmt.sh apiserver export -tenantid marketing -file config.zip

Modify the API Server's configuration for the target tenant

A ZIP file that you export can have the following internal structure. This example is from exporting the marketing tenant's API Server Configuration. Notice that the tenant ID is also a parent directory name. Configuration files listed under ExternalAuthenticationPlugin, ExternalIdentityProvider, Main, PolicyPlugin, SessionPlugin, and TransactionPlugin correspond to configuration objects in the database. Some of these plugins are optional and do not appear if they were not configured.

configurations
└─ marketing
   ├─ ExternalAuthenticationPlugin
   │    ├─ jwt_config.json
   │    └─ Main.json
   ├─ ExternalIdentityProvider
   │    ├─ Main.json
   │    ├─ <registrationID1>.json
   │    └─ <registrationID2>.json
   ├─ Main
   │    ├─ jwt_config.json
   │    └─ Main.json
   ├─ PolicyPlugin 
   │    ├─ default_config.json
   │    └─ Main.json
   ├─ SessionPlugin
   │    ├─ credsim_config.json
   │    ├─ ip_address_plugin.json
   │    ├─ jws_config.json
   │    ├─ jwt_config.json
   │    ├─ Main.json
   │    └─ ua_parser.json
   └─ TransactionPlugin
        ├─ jwt_config.json
        └─ Main.json

Start by making a backup copy of the zip file that contains the exported configurations. Then unzip the exported configurations and perform the following modifications. For details on each of these objects, refer to API Server Configuration.

  1. Rename the parent directory based on the source tenant ID to be the target tenant ID.

    IF the following files exist, you will need to delete them, but if you have any custom configurations, make a backup copy first!

  2. Delete jwt_config.json from the Main directory.

  3. Delete the files below from the SessionPlugin directory.

    1. jwt_config.json

    2. jws_config.json

    3. credsim_config.json

  4. Delete jwt_config.json from the TransactionPlugin directory.

  5. Delete jwt_config.json from the ExternalAuthenticationPlugin directory.

  6. Review Main/Main.json. Remove any allowed apps from origin_allowlist and compare the response filter configuration in mfas_response_filter to the default value. If the value is different, determine if this is the data that you want allowed through the response filter. See Main to understand this object's configuration.

  7. Review PolicyPlugin/default_config.json. If the FIDO policy names listed here aren't what you plan to use or don't exist, then update them now or use the instructions in Configure Digipass S3 Software to Use Policies to update them later.

  8. Review SessionPlugin/Main.json. Refer to Session Plugin - Main to understand this object's configuration.

    1. If you aren't using Android apps that use FIDO2 or web apps that use WebAuthn, then delete com.noknok.gateway.plugin.session.CredentialSimulator from this file, if present.

    2. If you don't need EMV 3DS data returned from registration, authentication, or transaction confirmation or from an Adaptive Rule, then delete com.noknok.gateway.plugin.session.Emv3dsSessionPlugin.

    3. If you don't have Adaptive Rules that use IP address in their condition, then delete com.noknok.gateway.plugin.session.IPAddressPlugin.

  9. If you aren't using S3 for transaction confirmation, then delete TransactionPlugin/Main.json if it is there.

Zip up the configurations back into a ZIP file.

Importing

Using the Admin Console

  1. Login to the Admin Console and, if needed, switch to the desired tenant.

  2. Navigate to Configuration > Import/Export.

  3. In the API Server section, click Choose File and navigate to the properties file to import.
    You can optionally select the Overwrite existing configurations checkbox. All API Server configurations and objects from the ZIP file are imported from the file, replacing existing configurations and objects.

    Click Import.

Using nnl-mgmt.sh

The example below shows how to import the API Server's configuration from a ZIP file. Remember, the new tenant name is specified in the directory structure in the ZIP file.

./nnl-mgmt.sh apiserver import -file config.zip -overwrite yes

After importing

Since the JWT and JWS objects were deleted and so not imported for security reasons, you need to provide new jwt_config and jws_config objects for the target tenant. See Customize an imported tenant.