Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Authentication Server properties

Prev Next

The Authentication Server has many properties that control its functions, and this section describes them all. We categorize the properties based on their scope:

App properties

This section describes properties that are specific to a client application.

To configure these properties using the Admin Console, select the desired tenant, navigate to Configuration > Apps, and select the specific app from the list.

To configure these properties using nnl-mgmt.sh, you must prepend the package name to the property name.

Apple Push Notification (APNs) properties

The following properties are required if you use Apple push notification (APNs) for OOB authentication.

Label in Admin Console

App Property and Description

APNs Certificate Content

<package name>##oob.ios.apns.server.cert.content

Stores the certificate content in the database for an APNs push notification.

APNs Certificate Filename

<package name>##oob.ios.apns.server.cert.filename

The certificate filename.

APNs Certificate Location

<package name>##oob.ios.apns.server.cert

Warning: Deprecated but supported for backwards compatibility. Please use

<package name>##oob.ios.apns.server.cert.content instead.

Certificate location required for APNs push notification.

APNs Certificate Password

<package name>##oob.ios.apns.server.cert.password

Encrypted Certificate Password required for APNs push notification. See the Apple Developer documentation for instructions on obtaining an APNs certificate and password.

Key ID

<package name>##oob.ios.apns.server.token.keyid

The 10-character Key ID for your token signing key. Get this value from your Apple Developer account.

Team ID

<package name>##oob.ios.apns.server.token.teamid

The 10-character Team ID you use for developing your company’s apps. Get this value from your Apple Developer account.

Token Signing Key

<package name>##oob.ios.apns.server.token.signing.key.secret

and

<package name>##oob.ios.apns.server.token.signing.key.filename

An authentication token signing key, specified as a text filename with a .p8 file extension. Obtain or generate the file from your Apple Developer account.

If you are not using the Secrets Plugin, then set the app-specific property <package name>##oob.ios.apns.server.token.signing.key.filename to the name of the file containing the private key. Both the CLI (nnl-mgmt.sh) and the Admin Console automatically encrypt the content of the file and store that content in the app-specific property <package name>##oob.ios.apns.server.token.signing.key.secret.

If you are using the Secrets Plugin and want to store the key in an external secrets manager, then set the app-specific property <package name>##oob.ios.apns.server.token.signing.key.secret to the handle to the key in the external secrets manager.

If you use nnl-mgmt.sh to enter the handle to this property, prepend the handle with "{handle}".

Use APNs Production Server

<package name>##oob.ios.apns.prod.server

Boolean property that specifies which APNs server to use for push notification.

  • true: Use the APNs production server

  • false (default): Use the APNs development server

iOS Application Name

<package name>##app.names

After adding the above oob iOS properties, you must add this property to describe the Appnames (iOS Application name).

Apple App Attest Property

The Team ID property is required if you use Apple App Attest.

Label in Admin Console

App Property and Description

Team ID

<package name>##ios.teamid

The 10-character Team ID you use for developing your company’s apps. Get this value from your Apple Developer account.

Android Push Notification Properties

The following properties are required if you use Android push notification for OOB authentication.

To obtain the FCM Sender ID and the HTTP key, see Configure Out-of-band Authentication.

Label in Admin Console

App Property and Description

FCM Sender ID

<package name>##oob.android.notification.sender.id

The Firebase Cloud Messaging sender ID is required so your app can send an Android push notification.

FCM Push Message Priority

<package name>##oob.fcm.push.priority

Optional. Sets the priority of Firebase push messages. FCM attempts to deliver HIGH priority messages immediately, waking a sleeping device when necessary.

Default value: HIGH. Valid values: NORMAL/HIGH, case insensitive.

FCM HTTP Key

<package name>##oob.fcm.service.account.key.secret and

<package name>##oob.fcm.service.account.key.filename

The Auth Server uses this key to mint the OAuth 2.0 access token that FCM uses to authorize requests.

If you are not using the Secrets Plugin, then set just the app-specific property <package name>##oob.fcm.service.account.key.filename to the name of the file containing the private key. Both the CLI (nnl-mgmt.sh) and the Admin Console automatically encrypt the content of that file and store that content in the app-specific property <package name>##oob.fcm.service.account.key.secret.

If you are using the Secrets Plugin and want to store the key in an external secrets manager, then set the app-specific property <package name>##oob.fcm.service.account.key.secret to the handle to the key in the external secrets manager.

If you use nnl-mgmt.sh to enter the handle to this property in your external secrets manager, prepend the handle with "{handle}".

Google Play Integrity properties

The properties in this section are required to verify Google Play Integrity for an Android app. Find the values for these properties in the Google Play Console. You must first link the Google Cloud project that you're using for the Play Integrity API in the Google Play Console. These properties were introduced in Digipass S3 version 9.1.0.

All Android apps need to set the Project Number and the APK Signing Certificate. The other required properties depend on whether decryption and verification of your app's integrity token takes place locally on the Authentication Server or remotely on Google Play’s server.

  • local: If you decrypt and verify locally on the Digipass S3 Auth Server, assign values to the Decryption Key property and the Verification Key property.

  • remote: If you decrypt and verify remotely on Google Play's server, assign the name of the file containing the Service Account Key Secret to the Service Account Key Filename property. If you are using the Secrets Plugin to store the Service Account Key Secret, assign a handle to the Service Account Key Secret property that is stored in an external vault.

Using the Secrets Plugin to Store Play Integrity Secrets

If your Digipass S3 deployment uses the Secrets Plugin to store these Google Play Integrity secrets, then set a property's value to the handle that is stored in the external secrets vault specified in the Secrets Plugin. If you use nnl-mgmt.sh to set these properties, the value must be prefixed with the literal "{handle}". See Crypto and Secrets Plugins.

Label in Admin Console

App Property and Description

Project Number

<package name>##nnl.play.integrity.project.id

Google Cloud project number that is linked to your Android app. This property must be configured for Play Integrity verification. Note that the Digipass S3 property nnl.play.integrity.project.id corresponds to the Google property "Project Number".

APK Signing Certificate SHA256 Digests

<package name>##nnl.play.integrity.apk.cert.digest.sha256

A comma-separated list of SHA256 digest of app certificates. The Play server compares the application integrity field "certificateSha256Digest" in the Play Integrity verdict against the values configured in this property.

Decryption Key

<package name>##nnl.play.integrity.jwt.decryption.key

Decrypts the integrity verdict locally in the Auth Server. Must be configured if you want to decrypt and verify the integrity verdict in the Auth Server.

If you assign a value to this property using nnl-mgmt.sh, you must first encrypt that value using /mfas/install/nnl-encrypt-password.sh. If you use the Admin Console to assign the value, it automatically encrypts the value.

If you are using the Secrets Plugin to store the Decryption Key property, see Using the Secrets Plugin to Store Play Integrity Secrets about how to assign a value.

See Example 1 below.

Verification Key

<package name>##nnl.play.integrity.jwt.verification.key

Verifies the integrity verdict locally in the Auth Server. Must be configured if you want to decrypt and verify the integrity verdict in the Auth Server.

If you assign a value to this property using nnl-mgmt.sh, you must first encrypt that value using /mfas/install/nnl-encrypt-password.sh. If you use the Admin Console to assign the value, it automatically encrypts the value.

If your Digipass S3 deployment uses the Secrets Plugin, see Using the Secrets Plugin to Store Play Integrity Secrets about how to assign a value.

See Example 2 below.

Service Account Key

<package name>##nnl.play.integrity.service.account.key.filename and <package name>##oob.fcm.service.account.key.secret

Assign these properties if you are using Google Play's server to decrypt and verify the integrity token. The Auth Server uses this key to mint the OAuth 2.0 access token to call Google API to decrypt and verify Play Integrity verdict remotely on Google Play's server.

If you are not using the Secrets Plugin, then set the app-specific property <package name>##nnl.play.integrity.service.account.key.filename to the name of the file containing the private key. Both the CLI (nnl-mgmt.sh) and the Admin Console automatically encrypt the content of the file and store that content in the app-specific property <package name>##oob.fcm.service.account.key.secret.

If you are using the Secrets Plugin to store the Service Account Key (<package name>##oob.fcm.service.account.key.secret), see Using the Secrets Plugin to Store Play Integrity Secrets about how to assign a value.

See Example 3 below.

Example 1

./nnl-mgmt.sh properties set -name android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.decryption.key ‑value 2HFjVyi5p_K_zEOBKuJ41ORkkUkV4yDZ5QeAacP9ntwXj9vBNeFYF0AK0eX_vVTKwpYNd1syzDrFau8KfCXoScIOLWcPcOMxmih3og

Example 2

./nnl-mgmt.sh properties set -name android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.verification.key -value qgcwHPZbH3v-ScVZ-Z3VrfS9u_z7tCPTxVVDLK8o_TCtBhXNDYwFAhG5-T7-c5gTJ3Z-UFh6Tps9Lk7cbJHEFu74U41plMfQzPRIEnXk9jrqQDnzxMtD2xPXhAEaG0-GYcIkobcSe5L7WoSeBDehOpGwUl4ZovcCRxP_Z2Y3QwQdohm5_iMt_KOYKP--hDTAbT5Zikf9_9ps9nt4

Example 2 Output

android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.decryption.key=2HFjVyi5p_K_zEOBKuJ41ORkkUkV4y...
        android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.verification.key=qgcwHPZbH3v-ScVZ-Z3VrfS9u_z7tC...
        android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename=push-integrity-service_account_key.json
        android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.secret=ynN9h95IyzcIQ0kx36RbUOWDMvQ6ZESgv...

Example 3

./nnl-mgmt.sh properties set -name android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename -value /home/zsmith/push-integrity-service_account_key.json

Example 3 Output

Validated packageName[android:com.noknok.android.tutorialappplus]
        Successfully set property [android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename] for tenant [default].

Example 3 stores the filename in

android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename

and stores the encrypted content of the file in

android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.secret

Tenant properties

This section describes properties for tenants that you create and for the default tenant. The default tenant is automatically created during installation. Users who don't need multi-tenancy utilize the default tenant. Wherever possible, the properties are grouped by function.

You can edit most tenant properties using the Admin Console. You can modify all tenant properties using the nnl-mgmt.sh's properties set command. An example is shown below:

./nnl-mgmt.sh properties set -name nnl.hist.store.operations -value 'FINISH_REG,FINISH_AUTH,UPDATE_REG,DELETE_REG,INIT_ADAPTIVE,SETUP,VERIFY,DELETE_METHODS' -tenantid investment

To create and configure a new tenant, see Configure tenants.

UAF properties

If you use UAF authentication, make sure these properties have values. You can edit these through the Admin Console, Configuration > Authentication Methods > FIDO UAF.

Label in Admin Console

Tenant Property and Description

App ID

uaf.application.id

The App ID is the URL of facets.uaf, the file that contains your organization's list of trusted facet IDs. Digipass S3 strongly recommends that you assign the URL to facets.uaf as the App ID, even if your apps use an embedded FIDO client and, as a result, don't need to use facets.uaf. Assigning facets.uaf's URL also allows Digipass S3 Software to support credential sharing between apps in the future.

The format is host:port/path_to/facets.uaf.

See Assigning the App ID in Configure Tenants for more details.

Changing this property invalidates existing registrations on end-user devices.

Challenge Expiration Time

uaf.challenge.validity.seconds

The maximum amount of time, in seconds, that a user has to respond to a push notification or scan a QR code.

Default value: 300

Maximum Number of UAF Authenticators per User

uaf.reg.user.max.authenticators

Maximum number of authenticators that can be registered for a user.

Default value: 32

Outdated Authenticator Version Behavior

uaf.outdated.authenticator.version.behavior

Specifies what the Server should do if an authenticator is outdated. An authenticator is outdated if it has a lower version than the one specified in its corresponding metadata in the Server. Value must be one of:

  • warning (default): Write a warning in the log file, nnl.log. This is a diagnostic log.

  • error: Reject the UAF response and throw an exception.

Request Android Key Attestation

nnl.send.android.key.attestation.extension

Boolean. If true, the Server requests Android key attestation data from the client.

Default value: false

Require Android Key Attestation for AAIDs

uaf.require.android.key.attestation.aaids

Comma-separated list of AAIDs of UAF authenticators for which successful Android Key Attestation is required. For any improper Android Key Attestation extension values, the registration fails. Improper extension values include extension value 'p', 'a', corrupt, or empty.

Each AAID in this list must have corresponding metadata in the database. The authenticators associated with those AAIDs must support Android Key Attestation Extensions.

UAF List of Trusted Facet IDs

uaf.facet.id

The list of trusted facet IDs. Each of the apps you implement has its own facet ID and appears in this list. This property is not required, since the Authentication Server can also derive this information from app-specific UAF properties.

Default value: (for non-production installations only, this list is left blank for production installations)

ios:bundle-id:com.noknok.ios.passport,ios:bundle-id:com.noknok.ios.tutorialappplus,ios:bundle-id:com.noknok.cordovatutorialapp,android:apk-key-hash:SvYZ4Sgas9T2+6DpNj566iscuns,android:apk-key-hash:Bc9rEk16GTEpN3bbD+4zV/H3Msk,com.noknok.uaf.test.client

FIDO2 properties

If you use FIDO2 authentication, make sure these properties have values. You can edit these through the Admin Console, Configuration > Authentication Methods > FIDO2/WebAuthn.

Label in Admin Console

Tenant Property and Description

Relying Party ID

webauthn.application.id

The Relying Party (RP) ID for your organization. This is a domain. All your web apps' facet IDs must contain this domain.

Changing this property invalidates existing registration on end-user devices.

Relying Party Display Name

webauthn.application.rpdisplayname

The human-readable display name for the RP which is associated with the registration.

Default value: DEFAULT_TENANT

Challenge Expiration Time

webauthn.challenge.validity.seconds

Expiration time of the challenge generated for FIDO2 operations, in seconds.

Default value: 300

FIDO2 List of Trusted Facet IDs

webauthn.facet.id

The list of trusted facet IDs for FIDO2 apps. Each of the apps you implement has its own facet ID and appears in this list. By default, webauthn.facet.id is blank for the default tenant. This property is not required because the Authentication Server can also derive this information from app-specific FIDO2 properties.

Maximum Number of Authenticators per User

webauthn.reg.user.max.authenticators

The maximum number of WebAuthn authenticators that a user can register.

Default value: 32

User Name to User ID Mapping Mode

webauthn.userid.mapping.mode

Specifies how the user name maps to the user ID. The user ID is either the same as the user name or it is a salted hash of the user name. One of:

  • Same_as_username

  • Salted_username_hash

Default value: Salted_username_hash

User ID Salt Suffix

webauthn.userid.salt.suffix

The salt used to hash the user name when webauthn.userid.mapping.mode is Salted_username_hash. Set to a random string, which is uniquely generated for a tenant when it is created.

UAF transaction properties

To prevent transaction confirmation from being intercepted and abused, the Server generates an image that contains the confirmation text. The following properties are used by the Server to format and generate that image. Use nnl-mgmt.sh's set property command to modify these properties.

Label in Admin Console

Tenant Property and Description

Background Color

uaf.png.font.bgcolor

Background font color for transaction text.

Default Value: WHITE

Font Color

uaf.png.font.fgcolor

Foreground font color for transaction text.

Default Value: BLACK

Font Size

uaf.png.font.size

Font size for transaction text.

Default Value: 12

Font Type

uaf.png.font.type

Font type for transaction text. Possible values are Serif, SansSerif, Monospaced, Dialog, and DialogInput.

Default Value: SansSerif

Out-of-band authentication properties

If your apps use out-of-band (OOB) authentication, these properties need values.

Use the Admin Console to edit these properties. Configuration > Authentication Methods > Out-of-Band.

Label in Admin Console

Tenant Property and Description

Challenge Expiration Time

oob.challenge.validity.seconds

The maximum period of time, in seconds, in which a user has to respond to a generated challenge for an out-of-band operation. The generated challenge is either a push notification or QR Code.

Default: 180

Registration URL

oob.reg.url

URL required for an out-of-band registration operation.

Example: https://www.example.com:1234/nnlgateway/nnl/reg

Authentication URL

oob.auth.url

URL required for an out-of-band authentication operation.

Example: https://www.example.com:1234/nnlgateway/nnl/auth

Push Handle Expiration Time (Days)

oob.pushhandle.expiry.time.days

Expiration time of push handle, in days.

Default Value: 30

Maximum Number of Push Notification Attempts

oob.maximum.notification.sent.count

Maximum number of push notification attempts. When the limit is reached, the push handle is marked as invalid.

Default Value: 10

Push Notification Authentication Text

oob.auth.notification.text

String to display as the push notification that prompts the user to authenticate if oob.auth.notification.text's value is Static.

Default Value: Authentication

Push Notification Authentication Text Mode

oob.auth.notification.text.mode

Specifies whether the push notification text that prompts the user to authenticate is static or custom. One of:

  • Static: The value of the tenant-specific property oob.auth.notification.text is used for push notification display.

  • Dynamic: The client app sends the string for the push notification. See section Sending Custom Push Notifications in the Android, iOS or WebDeveloper Guide.

Default Value: "Static"

Push Notification Transaction Text

oob.transaction.notification.text

Push notification display text for an out-of-band transaction.

Default Value: "Auth Transaction"

Push Notification Transaction Text Mode

oob.transaction.notification.text.mode

Specifies if the push notification text that prompts the user to confirm a transaction is static or custom. One of:

  • Static: The value of the tenant-specific property oob.transaction.notification.text is used for push notification display.

  • Dynamic: The client app sends the string for the push notification. See section Sending Custom Push Notifications in the Android, iOS or Web Developer Guide.

Default Value: "Static"

Google Geocoding API property

Unlike mobile apps, a web-based app can only send the latitude and longitude of the user's location, not the country code. To enable your web app to use an Adaptive Rule whose condition contains a Countries list, you need to configure the Google Geocoding API. Once that configuration is done, the Digipass S3 Server can get the country code from the latitude and longitude.

This property was introduced in version 8.0.1.

Label in Admin Console

Tenant Property and Description

Google Geocoder API Key

nnl.geo.coder.google.api.key

Your encrypted API key for the Google Maps Platform.

For instructions on how to obtain and set this key, See Configure the Google Geocoding Service.

Also see the System property Google Geocoding API URL under System Tenant Properties.

Audit Log properties

Audit logging provides a way to help meet regulatory compliance and can also help with debugging. If you don’t have regulatory requirements, turn audit logging off to reduce I/O and disk storage requirements.

You can edit these properties in the Admin Console. Use Configuration > Compliance > Audit Logging.

To learn more about audit logs, see Configure Audit Logging.

Label in Admin Console

Tenant Property and Description

Enable Runtime Audit Logging in JSON

nnl.audit.logger.enabled

Boolean. Specify whether audit logging in JSON is turned on for the tenant. One of:

  • true (default): Turns on audit logging in JSON

  • false: Disables audit logging in JSON

Enable Runtime Audit Logging in CSV

nnl.csv.audit.logger.enabled

Boolean. Specify whether CSV audit logging is turned on for the tenant. One of:

  • true (default): Turns on CSV audit logging

  • false: Disables CSV audit logging

Privacy properties

Choose which individual Personally Identifiable Information (PII) you want to store by using the Admin Console, or by using the CLI to set the nnl.storage.extension.list tenant property.

Using the Admin Console, navigate to Configuration > Compliance > Privacy. By default, the Server stores the end user's location information.

Alternatively you can use the CLI to set the value for the nnl.storage.extension.list property. The following command tells the Server to store the user's location, IP Address, and Wifi SSID.

./nnl-mgmt.sh properties set -name nnl.storage.extension.list -value noknok.metrics,noknok.appattest,noknok.uaf.location,noknok.ipaddress,noknok.wifi.ssid

By default, the Server stores metrics and appattest information also, but if you do not include noknok.metrics and noknok.appattest in the list when you set the value for the nnl.storage.extension.list property using the CLI, then the Server does not store metrics nor appattest information.

Since the example properties set command above does not include the -tenantid parameter, it applies only to the default tenant.

Notes:

  • When you use the CLI to set the nnl.storage.extension.list property, if you do not include any of the 5 pieces of information in the value list, whatever you omit is not stored in the database.

  • If the Server does not receive this information from the App SDK, it can't store it.

  • You must store information in the database in order to include it in the runtime audit logs.

  • See section Managing Personally Identifiable Information (PII) in the Android, iOS or Web Developer Guide for information on how your app can allow end users to view and delete their Personally Identifiable Information.

Admin tenant properties

This section describes properties for the Admin tenant. Wherever possible, the properties are grouped by function. You can modify these properties in the Admin Console, unless noted otherwise, provided that you are a Super Admin or an Admin in the Admin tenant. Change the tenant to Admin and navigate to Configuration > Admin.

You can edit all of these properties using the nnl-mgmt.sh's properties set command. After changing a property using nnl_mgmt.sh, the Auth Server immediately enforces the new value. An example is shown below:

./nnl-mgmt.sh properties set -name nnl.admin.audit.logger.enabled -value false -tenantid Admin

Audit logging

Label in Admin Console

Admin Tenant Property and Description

Enable Admin Audit Logging

nnl.admin.audit.logger.enabled

Optional. Specifies whether the admin audit logging is enabled or not.

  • true (default) - Enable admin audit logging.

  • false - Disable admin audit logging.

Transient data purge

Label in Admin Console

Admin Tenant Property and Description

Enable Transient Data Purge in Background

nnl.transient.data.purge.thread.enabled

Optional. Whether transient data is automatically purged.

  • true (default) - Transient data is automatically purged.

  • false - Transient data is not purged.

Transient Data Purge Interval

nnl.transient.data.purge.interval

Optional. Polling interval, in seconds, for purging transient data. At the specified interval, the Admin Server checks for new expired transient data and deletes it.

Default Value: 30

Transient Data Purge Batch Size

nnl.transient.data.purge.batch.size

Optional. Number of transient data records to delete in one transaction.

Default Value: 100

FIDO metadata

Label in Admin Console

Admin Tenant Property and Description

FIDO Alliance Metadata Service Certificate

nnl.fido.mds3.cert

Mandatory. Certificate that authorizes your access to the FIDO Alliance Metadata Service. The current certificate is valid until March 18, 2029. You must use nnl-mgmt.sh to set this property. Example:

./nnl-mgmt.sh properties set -name nnl.fido.mds3.cert -value "/path/to/NewMDSCert.txt" -tenantid Admin

FIDO Alliance Metadata Service URL

nnl.fido.mds3.url

Mandatory. The URL where you can access the FIDO Alliance Metadata Service. Default value is https://mds.fidoalliance.org. This URL is unlikely to change. You must use nnl-mgmt.sh to set this property, if it needs to be updated. For example:

./nnl-mgmt.sh properties set -name nnl.fido.mds3.cert -value "https://newmds.fidoalliance.org" -tenantid Admin

Enable Metadata Updates

nnl.admin.metadata.edit.enabled

Optional. Enable or disable authenticator metadata updates in the Admin Console.

  • true (default) - Enable authenticator metadata updates.

  • false - Disable authenticator metadata updates. Metadata can be viewed.

Imported file sizes

The following table lists configurable properties, their default values, and the type of imported file that the property applies to. Although these properties are defined on the Admin tenant, the limits apply to all tenants in your deployment. If a user tries to import a file that is larger than the limit, the system shows an error message. This prevents users from uploading large files to the Auth Server either through the Admin Console or by using nnl_mgmt.sh, the command line interface.

Admin Tenant Property

Default Maximum Size

Import File Type

nnl.android.app.file.max.size.mb

100 MB

APK file that you can import for a new Android app.

nnl.api.server.config.file.size.kb

512 KB

nnlgateway.json configuration file

nnl.api.server.config.plugins.file.size.kb

256 KB

API Server configuration files

nnl.app.file.size.kb

512 KB

Client app configuration files

nnl.auth.server.config.file.size.kb

256 KB

Auth Server configuration file

nnl.fcm.http.key.size.kb

10 KB

FCM HTTP key file. The Auth Server uses this key to mint the OAuth 2.0 access token that FCM uses to authorize requests

nnl.ios.app.file.max.size.mb

100 MB

IPA file that you can import for a new iOS app

nnl.ios.token.cert.file.size.kb

10 KB

Encrypted certificate password required for APNs push notification

nnl.ios.token.signing.key.file.size.kb

1 KB

P8 file containing your authentication token signing key

nnl.list.auth.group.file.size.kb

128 KB

Authenticator group list

nnl.list.auth.metadata.file.size.kb

128 KB

Authenticator metadata file

nnl.list.country.file.size.kb

128 KB

Country list

nnl.list.device.model.file.size.kb

128 KB

Device model list

nnl.list.geofence.file.size.kb

128 KB

Geofence list

nnl.list.ip.address.file.size.kb

128 KB

IP address list

nnl.list.wifi.address.file.size.kb

128 KB

WiFi network address list

nnl.policies.file.size.kb

128 KB

FIDO policy file

nnl.rulesets.file.size.kb

512 KB

Adaptive Ruleset file

ZIP file properties

Admin Tenant Property

Default Maximum Size

Description

nnl.zip.entry.threshold.ratio

50

Compression ratio for a ZIP file entry during import

nnl.zip.entry.threshold.size.mb

100 MB

Size for an individual uncompressed entry in a ZIP file

nnl.zip.threshold.entries

1000

Number of entries in a ZIP file that can be imported

External login for the Admin Console

Label in Admin Console

Admin Tenant Property and Description

Enable Using an External Authentication System Instead of the Built-in FIDO Login for the Admin Console

nnl.external.login.enabled

Optional. Enable using an external login instead of the built-in FIDO login for the Admin Console.

  • true - The Admin Console uses a JWT generated by the external authentication system to sign in Admin users and specify which resources they can access during that login session. This disables the default Admin registration and sign in pages as well as the Admin User Management page.

  • false (default) - The Admin Console uses FIDO authentication to sign in Admin users. The Admin's access to resources is defined using the Admin User Management page.

You must use nnl-mgmt.sh to set this property, as shown below. You must also perform the configuration described in Replacing FIDO Login in the Admin Console.

./nnl-mgmt.sh properties set -name nnl.external.login.enabled -value true -tenantid Admin

Logout Page URL

nnl.logout.url

Optional. If you are using an external authentication system to sign in your Admin users to the Admin Console, you can optionally assign the URL to your custom logout page using this property. When an Admin user navigates to Settings > Log Out in the Admin Console, the custom logout page is loaded. For details, see Replacing FIDO Login in the Admin Console.

You must use nnl-mgmt.sh to set this property, as shown below.

./nnl-mgmt.sh properties set -name nnl.logout.url -value https://<your-domain>/AdminLogout.html -tenantid Admin

System tenant properties

Digipass S3 Software uses the SYSTEM tenant as a container for properties that are common to all tenants. The SYSTEM tenant is automatically created and configured when you install the Digipass S3 Server.

Customers rarely need to modify these SYSTEM properties. If you think your installation could benefit from modifying one or more of these properties, please consult with OneSpan customer support.

You can use nnl-mgmt.sh's properties command to list these properties.

./nnl-mgmt.sh properties list -tenantid SYSTEM

These properties can only be changed using the command-line tool nnl-mgmt.sh. After changing the value of a SYSTEM tenant property, you must restart the Server for the change to take effect.

Name

System Tenant Property

Description

Cache Expiration

nnl.cache.local.expiry.time.seconds

The expiration time, in seconds, for local cache implementation.

Default Value: 300

Custom Crypto Classname

nnl.crypto.custom.impl.class.name

The name of the class that implements the custom CryptoService.

Encrypt Transient Data

nnl.db.transient.store.encrypt.data

If true, encrypts transient data that is stored in the database.

Default Value: false

Authentication Method Configurations

nnl.identity.method.config

A JSON containing configurations for the authentication methods used by Digipass S3 Software:

  • FIDO authentication

  • FIDO OOB authentication

  • Email OTP

  • SMS OTP

  • Photo ID

  • External authentication

Default Value:

{"Email OTP":{"className":"com.noknok.identity.method.email.EmailMethodPlugin","systemConfigurations":{"serviceFactory":"com.noknok.platform.services.PlatformServiceFactory"},"genericConfigurations":{"smtp.host.allowlist":[]}},"SMS OTP":{"className":"com.noknok.identity.method.sms.SMSOtpMethodPlugin","systemConfigurations":{"serviceFactory":"com.noknok.platform.services.PlatformServiceFactory"}},"Photo ID":{"className":"com.noknok.identity.method.nv.NVPictureIdMethodPlugin","systemConfigurations":{"serviceFactory":"com.noknok.platform.services.PlatformServiceFactory","server.url":"https://netverify.com/api/netverify/v2/scans/"}},"FIDO Auth":{"className":"com.noknok.identity.method.fido.FidoMethodPlugin"},"FIDO OOB Auth":{"className":"com.noknok.identity.method.oob.OOBMethodPlugin"},"External Auth":{"className":"com.noknok.identity.method.external.auth.ExternalAuthMethodPlugin"}}

JCE Providers

nnl.jce.providers

A comma-separated list of Java Cryptography Extension (JCE) providers.

Default Value: org.bouncycastle.jce.provider.BouncyCastleProvider

License Accepted

nnl.license.accept

Must be true for the Server to work. Indicates that you accept the terms of the Digipass S3 license. See the license terms at <NNL_HOME>/licenses/noknok-license.txt.

Default Value: true

Allowed Skew Time

nnl.server.clock.max.skew.millis

Allows the system time to be slightly different among the servers in your cluster. The value is in milliseconds.

Default Value: 1000

Tenant Properties Polling Interval

nnl.tenantservice.update.poll.interval.seconds

The polling interval in seconds for the Server to read its database and refresh its cache of tenant-specific properties.

Default Value: 120

Google Geocoding API URL

nnl.geo.coder.api.url

The URL for the Google Reverse Geocoding API. Also see the Google Geocoding API Key.

Default Value: https://maps.googleapis.com/maps/api/geocode/json

HMS Push Notification Classname

oob.hms.notification.class.name

The class for HMS push notifications. This property was introduced in version 7.0.2. In versions 9.0.0 and earlier, this property was required.

Default Value:

  • Version 9.1.0 and later: blank, because the property is optional in these releases.

  • Version 9.0.0 or earlier: com.noknok.oob.push.impl.HMSNotificationSenderServiceImpl

APNS Push Notification Classname

oob.ios.notification.class.name

The class for APNS push notifications.

Default Value:

  • Version 7.0.1 and later: com.noknok.oob.push.http2.impl.Http2APNSNotificationSenderServiceImpl

  • Version 7.0.0 or earlier:

com.noknok.oob.push.impl.APNSNotificationSenderServiceImpl

Pool Size for APNS Server Connections

oob.ios.apns.server.pool.size

Size for the pool of connections to APNS servers. Max size allowed: 15

Default Value: 5

Enable the Listing of Pending Authentications

oob.list.auth.enabled

When true, the REST API operation LIST_OOB_AUTH returns pending out-of-band authentications. This property was introduced in version 9.1.0.

Default Value: false

Advance Policy Cache Expiry

nnl.policy.cache.expiry.time.seconds

Expiration time, in seconds, for entries in the advance policy cache. Introduced in version 9.0.0.

Default Value: -1 (cache doesn’t expire)

Advance Policy Cache Maximum Entries

nnl.policy.cache.max.size

Maximum number of entries that the advance policy cache can hold at one time. Introduced in version 9.0.0.

Default Value: -1 (cache doesn’t restrict the number of entries)

Policy Cache Polling Interval

nnl.policy.update.poll.interval.seconds

The polling interval, in seconds, for the Server to check if there have been any updates to any tenant policies.

Default Value: 120

Elapsed Time Threshold

nnl.api.elapsed.time.threshold.millis

If the response time (in milliseconds) to a REST API operation request is longer than this property's value, the Server logs a warning in the nnl.log file. Below is an example that was logged after an INIT_ADAPTIVE request:

2024-08-14 14:50:09,729 [http-nio-8443-exec-1] [tenantId : default] [CorrelationId : jR0ee5E024td_6_5sAw7WA] com.noknok.unified.rest.v2.metrics.MetricsCollector populateElapsedTimeForResponse - WARN: ID: [jR0ee5E024td_6_5sAw7WA], Operation: [INIT_ADAPTIVE] Elapsed time: [1606 milliseconds]. Exceeds threshold: [1000 milliseconds].

Default Value: 3000

Return Elapsed Time in the Response

nnl.api.response.include.elapsed.time

When true, the API Server returns the elapsed time in milliseconds between a REST operation's request and the response, provided that:

  • You assigned a value of 2 to the optionsData.needDetails field in the REST operation's request.

  • You configured the API Server's response filter to return the elapsed time. See example response filter below.

Note that when runtime audit logs are enabled, the elapsed time between the request and the API Server's response is always included in the runtime audit logs.

Default Value: false

Here is an example of a response filter that includes the elapsedTime in the response from the API Server. For more information, see Response Filter Configuration.

{
        "additionalInfo":{
        "elapsedTime":true,
        "device":true,
        "authenticatorsResult":[
           {
             "handle":true,
             "attachmentHints":true
           }
        ]
        }
}

For more information about additionalInfo, see additionalInfo in the REST API Reference.