List
Syntax
./nnl-mgmt.sh app list [-name <package-name>][-tenantid <tenantid>]Parameter | Description |
|---|---|
name | Optional. Full package name of the app to list. If no package name is specified, all apps for the specified tenant are listed. |
tenantid | Optional. Apps are listed for this tenant ID. Default is the default tenant. |
Description
Lists the tenant's client apps. Both the app's name and its package name are displayed.
Example
./nnl-mgmt.sh app list -name "ios:com.noknok.ios.onramp" -tenantid defaultExport
Syntax
./nnl-mgmt.sh app export -name <package-name> [-dir <app-dir> | -file <file-path>] [-with-dependencies <yes|no> -include-metadata <yes|no> -tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Name of an app to export. |
dir | Optional. Name of the destination directory where the system stores the exported file. By default, the file is stored in the current directory. |
file | Optional. The file path where the system stores the exported file. The file cannot already exist. |
tenantid | Optional. Configured apps are exported from this tenant. Default is the default tenant. |
with-dependencies | Optional. Indicates if the system should export the app’s dependencies, such as Adaptive Rulesets, lists, authenticator groups, and FIDO Policies.
|
include-metadata | Optional. Only an option when with-dependencies is yes. Indicates if the system should export authenticator metadata that is referenced in FIDO Policies used by Adaptive Rulesets that are configured in a configured app.
|
Description
Exports the specified app(s) for the given tenant. If only apps are exported, the system creates a JSON file. If apps, their dependencies, and authenticator metadata are included, the system creates a ZIP file.
Specify either a directory or a file path where the system exports the objects, but not both. If you specify the directory, then the system generates the file name.
Dependencies for an app include Adaptive Rulesets and the FIDO Policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any Adaptive Rulesets.
Examples
Export an app without dependencies. This results in a JSON file in /home/zsmith with a generated filename.
./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -dir /home/zsmith -tenantid NorthAmericaExport an App without dependencies. This results in a JSON file with the file path /home/zsmith/my_app.json.
./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -file /home/zsmith/my_app.json ‑tenantid NorthAmericaExport an App with dependencies. This results in a ZIP file.
./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata no -tenantid Europeor equivalently:
./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -dir /home/zsmith ‑with‑dependencies yes -tenantid EuropeExport an App, its dependencies, and authenticator metadata. This results in a ZIP file:
./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata yes -tenantid AsiaImport
Syntax
./nnl-mgmt.sh app import -file <property-file> [-overwrite <yes|no> -include-metadata <yes|no> -tenantid <tenantid>]Parameter | Description |
|---|---|
file | Mandatory. Name of a file to import. Can be either a JSON file or ZIP file. |
overwrite | Optional. Specifies whether or not to overwrite an existing app, ruleset and its dependent objects that have the same name. The value is one of the following:
|
include-metadata | Optional. Specifies whether or not to import authenticator metadata. Applies when the ZIP file contains one or more apps and their authenticator metadata files.
|
tenantid | Optional. Configured apps are imported into this tenant. Default is the default tenant. |
Description
Imports configured apps from the specified import file into the designated tenant. The import file can either be a JSON or ZIP file. A JSON file contains only apps. A ZIP file contains apps, objects that the apps depend on (dependencies), and optionally, authenticator metadata used by the app's Adaptive Rulesets. Dependencies for an app include Adaptive Rulesets and the FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the Adaptive Rulesets.
By default, the imported file size must be less than 512KB. Change the maximum file size by setting the nnl.app.file.size.kb property for the Admin tenant. For example, to increase the maximum file size to 1MB:
./nnl-mgmt.sh properties set -name nnl.app.file.size.kb -value 1024 ‑tenantid AdminIf you manually prepare a JSON file containing an app for import or for inclusion in a ZIP file, ensure that the values of properties requiring encryption are encrypted beforehand. The following properties, if present, must be encrypted when manually entering them into a JSON file for import.
oob.hms.service.appsecret
oob.fcm.service.account.key.secret
nnl.play.integrity.jwt.verification.key
nnl.play.integrity.jwt.decryption.key
nnl.play.integrity.service.account.key.secret
oob.ios.apns.server.cert.password
oob.ios.apns.server.token.signing.key.secret
If overwrite is yes, then existing apps, Adaptive Rulesets, FIDO policies, lists, and authenticator groups with the same name are overwritten. overwrite handles objects differently depending on their type and status, as shown in the table below.
Type of object | Status of Existing Object | |
|---|---|---|
app | NA | Overwrite the existing app with the app from the file. |
Adaptive Ruleset | draft | Overwrites the existing Adaptive Ruleset with the one from the file and changes its status to active. |
active | Overwrites the existing Adaptive Ruleset with the one from the file and its status remains active. | |
FIDO Policy | draft | Overwrites the existing FIDO Policy with the one from the file and changes its status to active. Note that all Adaptive Rulesets, whether active or draft, must use active FIDO policies. |
active | Overwrites the existing FIDO policy with the one from the file and its status remains active. | |
Lists | N/A | Overwrites the existing list with the one from the file. Note that this occurs even if the list is being used by a different active Adaptive Ruleset. |
Authenticator Groups | N/A | Overwrites the existing authenticator group with the one from the file. Note that this occurs even if the authenticator group is being used by a different active FIDO Policy. |
You can optionally set include-metadata to yes in order to import authenticator metadata. Use this option in limited situations, for example, if you want to copy authenticator metadata from a development deployment to a production deployment. Authenticator metadata is accessible to all tenants in a Digipass S3 installation so overwriting metadata could have unintended consequences.
This command fails in the following scenarios:
An app with the same package name exists and you specify -overwrite no.
The app file is larger than the value of the Admin tenant property nnl.app.file.size.kb. If that property is undefined, then the command fails when the app file is larger than 512 KB, which is the default maximum size.
The -file parameter is not specified.
Examples
Import apps from a JSON file into the finance tenant:
./nnl-mgmt.sh app import -file ios_com_noknok_ios_passport_App_1720603866568.json -overwrite yes ‑tenantid financeImport apps, dependencies, and authenticator metadata from a ZIP file into the finance tenant:
./nnl-mgmt.sh app import -file ios_com_noknok_ios_passport_App_1720603866568.zip -overwrite yes ‑include‑metadata yes ‑tenantid financeImport apps and dependencies, but not the authenticator metadata, from a ZIP file into the finance tenant:
./nnl-mgmt.sh app import -file ios_com_noknok_ios_passport_App_1720603866568.zip -overwrite yes ‑include‑metadata no ‑tenantid financeDelete
Syntax
./nnl-mgmt.sh app delete -name <package-name> [-tenantid <tenantid>]Parameter | Description |
|---|---|
name | Mandatory. Name of the app to delete. If you don’t provide a name, the command fails. |
tenantid | Optional. The system deletes the configured app in this tenant ID. Default is the default tenant. |
Description
Deletes an app for the given tenant.
Example
./nnl-mgmt.sh app delete -name ios:com.noknok.ios.passport -tenantid default