Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

App Commands

Prev Next

List

Syntax

./nnl-mgmt.sh app list [-name <package-name>][-tenantid <tenantid>]

Parameter

Description

name

Optional. Full package name of the app to list. If no package name is specified, all apps for the specified tenant are listed.

tenantid

Optional. Apps are listed for this tenant ID. Default is the default tenant.

Description

Lists the tenant's client apps. Both the app's name and its package name are displayed.

Example

./nnl-mgmt.sh app list -name "ios:com.noknok.ios.onramp" -tenantid default

Export

Syntax

./nnl-mgmt.sh app export -name <package-name> [-dir <app-dir> | -file <file-path>] [-with-dependencies <yes|no> -include-metadata <yes|no> -tenantid <tenantid>]

Parameter

Description

name

Mandatory. Name of an app to export.

dir

Optional. Name of the destination directory where the system stores the exported file. By default, the file is stored in the current directory.

file

Optional. The file path where the system stores the exported file. The file cannot already exist.

tenantid

Optional. Configured apps are exported from this tenant. Default is the default tenant.

with-dependencies

Optional. Indicates if the system should export the app’s dependencies, such as Adaptive Rulesets, lists, authenticator groups, and FIDO Policies.

  • Yes: Exports the app’s dependencies.

  • No: (default) Does not export the app’s dependencies.

include-metadata

Optional. Only an option when with-dependencies is yes. Indicates if the system should export authenticator metadata that is referenced in FIDO Policies used by Adaptive Rulesets that are configured in a configured app.

  • Yes: Exports all authenticator metadata referenced by FIDO policies used in the app’s Adaptive Rulesets.

  • No: (default) Does not export authenticator metadata.

Description

Exports the specified app(s) for the given tenant. If only apps are exported, the system creates a JSON file. If apps, their dependencies, and authenticator metadata are included, the system creates a ZIP file.

Specify either a directory or a file path where the system exports the objects, but not both. If you specify the directory, then the system generates the file name.

Dependencies for an app include Adaptive Rulesets and the FIDO Policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any Adaptive Rulesets.

Examples

Export an app without dependencies. This results in a JSON file in /home/zsmith with a generated filename.

./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -dir /home/zsmith -tenantid NorthAmerica

Export an App without dependencies. This results in a JSON file with the file path /home/zsmith/my_app.json.

./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport  -file /home/zsmith/my_app.json ‑tenantid NorthAmerica

Export an App with dependencies. This results in a ZIP file.

./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport  -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata no -tenantid Europe

or equivalently:

./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport -dir /home/zsmith ‑with‑dependencies yes -tenantid Europe

Export an App, its dependencies, and authenticator metadata. This results in a ZIP file:

./nnl-mgmt.sh app export -name ios:com.noknok.ios.passport  -dir /home/zsmith ‑with‑dependencies yes ‑include‑metadata yes -tenantid Asia

Import

Syntax

./nnl-mgmt.sh app import -file <property-file> [-overwrite <yes|no> -include-metadata <yes|no> -tenantid <tenantid>]

Parameter

Description

file

Mandatory. Name of a file to import. Can be either a JSON file or ZIP file.

overwrite

Optional. Specifies whether or not to overwrite an existing app, ruleset and its dependent objects that have the same name. The value is one of the following:

  • Yes: Overwrites objects with the same name.

  • No (default): Does not overwrite an object with the same name.

include-metadata

Optional. Specifies whether or not to import authenticator metadata. Applies when the ZIP file contains one or more apps and their authenticator metadata files.

  • Yes: Imports and overwrites authenticator metadata.

  • No (default): Doesn’t import authenticator metadata.

tenantid

Optional. Configured apps are imported into this tenant. Default is the default tenant.

Description

Imports configured apps from the specified import file into the designated tenant. The import file can either be a JSON or ZIP file. A JSON file contains only apps. A ZIP file contains apps, objects that the apps depend on (dependencies), and optionally, authenticator metadata used by the app's Adaptive Rulesets. Dependencies for an app include Adaptive Rulesets and the FIDO policies, authenticator groups, country lists, device model lists, geofence lists, IP address lists, and WiFi network lists used by any rules contained in the Adaptive Rulesets.

By default, the imported file size must be less than 512KB. Change the maximum file size by setting the nnl.app.file.size.kb property for the Admin tenant. For example, to increase the maximum file size to 1MB:

./nnl-mgmt.sh properties set -name nnl.app.file.size.kb -value 1024 ‑tenantid Admin

If you manually prepare a JSON file containing an app for import or for inclusion in a ZIP file, ensure that the values of properties requiring encryption are encrypted beforehand. The following properties, if present, must be encrypted when manually entering them into a JSON file for import.

  • oob.hms.service.appsecret

  • oob.fcm.service.account.key.secret

  • nnl.play.integrity.jwt.verification.key

  • nnl.play.integrity.jwt.decryption.key

  • nnl.play.integrity.service.account.key.secret

  • oob.ios.apns.server.cert.password

  • oob.ios.apns.server.token.signing.key.secret

If overwrite is yes, then existing apps, Adaptive Rulesets, FIDO policies, lists, and authenticator groups with the same name are overwritten. overwrite handles objects differently depending on their type and status, as shown in the table below.

Type of object

Status of Existing Object

Action when overwrite is yes

app

NA

Overwrite the existing app with the app from the file.

Adaptive Ruleset

draft

Overwrites the existing Adaptive Ruleset with the one from the file and changes its status to active.

active

Overwrites the existing Adaptive Ruleset with the one from the file and its status remains active.

FIDO Policy

draft

Overwrites the existing FIDO Policy with the one from the file and changes its status to active. Note that all Adaptive Rulesets, whether active or draft, must use active FIDO policies.

active

Overwrites the existing FIDO policy with the one from the file and its status remains active.

Lists

N/A

Overwrites the existing list with the one from the file. Note that this occurs even if the list is being used by a different active Adaptive Ruleset.

Authenticator Groups

N/A

Overwrites the existing authenticator group with the one from the file. Note that this occurs even if the authenticator group is being used by a different active FIDO Policy.

You can optionally set include-metadata to yes in order to import authenticator metadata. Use this option in limited situations, for example, if you want to copy authenticator metadata from a development deployment to a production deployment. Authenticator metadata is accessible to all tenants in a Digipass S3 installation so overwriting metadata could have unintended consequences.

This command fails in the following scenarios:

  • An app with the same package name exists and you specify -overwrite no.

  • The app file is larger than the value of the Admin tenant property nnl.app.file.size.kb. If that property is undefined, then the command fails when the app file is larger than 512 KB, which is the default maximum size.

  • The -file parameter is not specified.

Examples

Import apps from a JSON file into the finance tenant:

./nnl-mgmt.sh app import -file ios_com_noknok_ios_passport_App_1720603866568.json -overwrite yes ‑tenantid finance

Import apps, dependencies, and authenticator metadata from a ZIP file into the finance tenant:

./nnl-mgmt.sh app import -file ios_com_noknok_ios_passport_App_1720603866568.zip -overwrite yes ‑include‑metadata yes ‑tenantid finance

Import apps and dependencies, but not the authenticator metadata, from a ZIP file into the finance tenant:

./nnl-mgmt.sh app import -file ios_com_noknok_ios_passport_App_1720603866568.zip -overwrite yes ‑include‑metadata no ‑tenantid finance

Delete

Syntax

./nnl-mgmt.sh app delete -name <package-name> [-tenantid <tenantid>]

Parameter

Description

name

Mandatory. Name of the app to delete. If you don’t provide a name, the command fails.

tenantid

Optional. The system deletes the configured app in this tenant ID. Default is the default tenant.

Description

Deletes an app for the given tenant.

Example

./nnl-mgmt.sh app delete -name ios:com.noknok.ios.passport -tenantid default