Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

API Server properties

Prev Next

API Server configuration properties that are common across all tenants are stored in nnlgateway.json located in the $TOMCAT_HOME/webapps/nnlgateway/WEB-INF/classes/ directory. The table below describes the properties in the nnlgateway.json configuration file.

All client_auth.* properties are related to mutual TLS authentication if it is enabled on the Authentication Server's host. If this is the case, assign true to client_auth.enabled and then configure the other client_auth.* properties. Usually client_auth.enabled is false because mutual TLS authentication is rarely used.

If you are using a development installation, you may want to update the include_in_log.* properties to true so you get more information in the API Server's diagnostic log, nnlgateway.log, to help you debug.

Property

Description

client_auth.enabled

Optional. Whether mutual TLS authentication is enabled on the Authentication Server's host. One of:

  • true: Mutual TLS authentication is enabled

  • false (default): Mutual TLS authentication is not enabled

client_auth.keystore_file

Optional. The keystore file path to use if mutual TLS authentication is enabled.

client_auth.keystore_passphrase

Optional. The keystore’s passphrase.

client_auth.keystore_type

Optional. The keystore type. One of:

  • "pkcs12" (default): as in RFC 7292

  • "jks": Java KeyStore

configuration_type

Mandatory. By default, API Server and plugin configuration is stored in the database. The installer assigns db to this property.

If you need backward compatibility with releases prior to 7.0.0, assign file to this variable after installation. Specifies that API Server and plugin configuration is stored in files.

configuration_update_check_interval

Mandatory. Polling interval, in seconds, to check for configuration updates. The default is 10.

default_tenant_id

Optional. The default tenant ID name. Used when the tenant_id parameter is not specified in the HTTP request. In other words, tenant id cannot be identified from the URL path.

The default value is default.

include_in_log.userName

Optional. Whether to include log messages in nnlgateway.log containing information related to userName. One of:

  • true: Include log messages

  • false (default): Do not include log messages

include_in_log.sessionData

Optional. Whether to include log messages containing information related to sessionData. One of:

  • true: Include log messages

  • false (default): Do not include log messages

include_in_log.message

Optional. Whether to include log messages containing information related to message. One of:

  • true: Include log messages

  • false (default): Do not include log messages

include_in_log.request_all

Optional. Whether to log all requests. One of:

  • true: All requests are logged

  • false (default): No requests are logged.

include_in_log.response_all

Optional. Whether to log all responses. One of:

  • true: All responses are logged

  • false (default): No responses are logged.

mfas_location

Mandatory. The URL where the Authentication Server is hosted. If the URL uses the HTTP protocol instead of the HTTPS protocol, the API Server ignores all client_auth.* and server_auth.* properties in nnlgateway.json.

server_auth.enabled

Optional. To enable/disable TLS server authentication (TLS certificate validation) at the client side. One of:

  • true: authentication is enabled

  • false (default): disabled

server_auth.truststore_file

Optional. The truststore file path (used only when server.auth.enabled is true).

If this property has no value, the API Server uses the default Java runtime environment truststore.

server_auth.truststore_passphrase

Optional. The truststore password (used only when server_auth:enabled is true).

The default value is empty.

server_auth.truststore_type

Optional. The truststore type. One of:

  • "pkcs12" (default): as in RFC 7292

  • "jks": Java KeyStore