The Authentication Server has many properties that control its functions, and this section describes them all. We categorize the properties based on their scope:
App properties apply to only one specific client app.
Tenant properties apply to just one tenant in your deployment.
Admin tenant properties affect the job of the administrator.
System tenant properties impact the entire Server.
App properties
This section describes properties that are specific to a client application.
To configure these properties using the Admin Console, select the desired tenant, navigate to Configuration > Apps, and select the specific app from the list.
To configure these properties using nnl-mgmt.sh, you must prepend the package name to the property name.
Apple Push Notification (APNs) properties
The following properties are required if you use Apple push notification (APNs) for OOB authentication.
Label in Admin Console | App Property and Description |
|---|---|
APNs Certificate Content | <package name>##oob.ios.apns.server.cert.content |
Stores the certificate content in the database for an APNs push notification. | |
APNs Certificate Filename | <package name>##oob.ios.apns.server.cert.filename |
The certificate filename. | |
APNs Certificate Location | <package name>##oob.ios.apns.server.cert |
Warning: Deprecated but supported for backwards compatibility. Please use <package name>##oob.ios.apns.server.cert.content instead. Certificate location required for APNs push notification. | |
APNs Certificate Password | <package name>##oob.ios.apns.server.cert.password |
Encrypted Certificate Password required for APNs push notification. See the Apple Developer documentation for instructions on obtaining an APNs certificate and password. | |
Key ID | <package name>##oob.ios.apns.server.token.keyid |
The 10-character Key ID for your token signing key. Get this value from your Apple Developer account. | |
Team ID | <package name>##oob.ios.apns.server.token.teamid |
The 10-character Team ID you use for developing your company’s apps. Get this value from your Apple Developer account. | |
Token Signing Key | <package name>##oob.ios.apns.server.token.signing.key.secret and <package name>##oob.ios.apns.server.token.signing.key.filename |
An authentication token signing key, specified as a text filename with a .p8 file extension. Obtain or generate the file from your Apple Developer account. If you are not using the Secrets Plugin, then set the app-specific property <package name>##oob.ios.apns.server.token.signing.key.filename to the name of the file containing the private key. Both the CLI (nnl-mgmt.sh) and the Admin Console automatically encrypt the content of the file and store that content in the app-specific property <package name>##oob.ios.apns.server.token.signing.key.secret. If you are using the Secrets Plugin and want to store the key in an external secrets manager, then set the app-specific property <package name>##oob.ios.apns.server.token.signing.key.secret to the handle to the key in the external secrets manager.
| |
Use APNs Production Server | <package name>##oob.ios.apns.prod.server |
Boolean property that specifies which APNs server to use for push notification.
| |
iOS Application Name | <package name>##app.names |
After adding the above oob iOS properties, you must add this property to describe the Appnames (iOS Application name). |
Apple App Attest Property
The Team ID property is required if you use Apple App Attest.
Label in Admin Console | App Property and Description |
|---|---|
Team ID | <package name>##ios.teamid |
The 10-character Team ID you use for developing your company’s apps. Get this value from your Apple Developer account. |
Android Push Notification Properties
The following properties are required if you use Android push notification for OOB authentication.
To obtain the FCM Sender ID and the HTTP key, see Configure Out-of-band Authentication.
Label in Admin Console | App Property and Description |
|---|---|
FCM Sender ID | <package name>##oob.android.notification.sender.id |
The Firebase Cloud Messaging sender ID is required so your app can send an Android push notification. | |
FCM Push Message Priority | <package name>##oob.fcm.push.priority |
Optional. Sets the priority of Firebase push messages. FCM attempts to deliver HIGH priority messages immediately, waking a sleeping device when necessary. Default value: HIGH. Valid values: NORMAL/HIGH, case insensitive. | |
FCM HTTP Key | <package name>##oob.fcm.service.account.key.secret and <package name>##oob.fcm.service.account.key.filename |
The Auth Server uses this key to mint the OAuth 2.0 access token that FCM uses to authorize requests. If you are not using the Secrets Plugin, then set just the app-specific property <package name>##oob.fcm.service.account.key.filename to the name of the file containing the private key. Both the CLI (nnl-mgmt.sh) and the Admin Console automatically encrypt the content of that file and store that content in the app-specific property <package name>##oob.fcm.service.account.key.secret. If you are using the Secrets Plugin and want to store the key in an external secrets manager, then set the app-specific property <package name>##oob.fcm.service.account.key.secret to the handle to the key in the external secrets manager.
|
Google Play Integrity properties
The properties in this section are required to verify Google Play Integrity for an Android app. Find the values for these properties in the Google Play Console. You must first link the Google Cloud project that you're using for the Play Integrity API in the Google Play Console. These properties were introduced in Digipass S3 version 9.1.0.
All Android apps need to set the Project Number and the APK Signing Certificate. The other required properties depend on whether decryption and verification of your app's integrity token takes place locally on the Authentication Server or remotely on Google Play’s server.
local: If you decrypt and verify locally on the Digipass S3 Auth Server, assign values to the Decryption Key property and the Verification Key property.
remote: If you decrypt and verify remotely on Google Play's server, assign the name of the file containing the Service Account Key Secret to the Service Account Key Filename property. If you are using the Secrets Plugin to store the Service Account Key Secret, assign a handle to the Service Account Key Secret property that is stored in an external vault.
Using the Secrets Plugin to Store Play Integrity Secrets
If your Digipass S3 deployment uses the Secrets Plugin to store these Google Play Integrity secrets, then set a property's value to the handle that is stored in the external secrets vault specified in the Secrets Plugin. If you use nnl-mgmt.sh to set these properties, the value must be prefixed with the literal "{handle}". See Crypto and Secrets Plugins.
Label in Admin Console | App Property and Description |
|---|---|
Project Number | <package name>##nnl.play.integrity.project.id |
Google Cloud project number that is linked to your Android app. This property must be configured for Play Integrity verification. Note that the Digipass S3 property nnl.play.integrity.project.id corresponds to the Google property "Project Number". | |
APK Signing Certificate SHA256 Digests | <package name>##nnl.play.integrity.apk.cert.digest.sha256 |
A comma-separated list of SHA256 digest of app certificates. The Play server compares the application integrity field "certificateSha256Digest" in the Play Integrity verdict against the values configured in this property. | |
Decryption Key | <package name>##nnl.play.integrity.jwt.decryption.key |
Decrypts the integrity verdict locally in the Auth Server. Must be configured if you want to decrypt and verify the integrity verdict in the Auth Server. If you assign a value to this property using nnl-mgmt.sh, you must first encrypt that value using /mfas/install/nnl-encrypt-password.sh. If you use the Admin Console to assign the value, it automatically encrypts the value. If you are using the Secrets Plugin to store the Decryption Key property, see Using the Secrets Plugin to Store Play Integrity Secrets about how to assign a value. See Example 1 below. | |
Verification Key | <package name>##nnl.play.integrity.jwt.verification.key |
Verifies the integrity verdict locally in the Auth Server. Must be configured if you want to decrypt and verify the integrity verdict in the Auth Server. If you assign a value to this property using nnl-mgmt.sh, you must first encrypt that value using /mfas/install/nnl-encrypt-password.sh. If you use the Admin Console to assign the value, it automatically encrypts the value. If your Digipass S3 deployment uses the Secrets Plugin, see Using the Secrets Plugin to Store Play Integrity Secrets about how to assign a value. See Example 2 below. | |
Service Account Key | <package name>##nnl.play.integrity.service.account.key.filename and <package name>##oob.fcm.service.account.key.secret |
Assign these properties if you are using Google Play's server to decrypt and verify the integrity token. The Auth Server uses this key to mint the OAuth 2.0 access token to call Google API to decrypt and verify Play Integrity verdict remotely on Google Play's server. If you are not using the Secrets Plugin, then set the app-specific property <package name>##nnl.play.integrity.service.account.key.filename to the name of the file containing the private key. Both the CLI (nnl-mgmt.sh) and the Admin Console automatically encrypt the content of the file and store that content in the app-specific property <package name>##oob.fcm.service.account.key.secret. If you are using the Secrets Plugin to store the Service Account Key (<package name>##oob.fcm.service.account.key.secret), see Using the Secrets Plugin to Store Play Integrity Secrets about how to assign a value. See Example 3 below. |
Example 1
./nnl-mgmt.sh properties set -name android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.decryption.key ‑value 2HFjVyi5p_K_zEOBKuJ41ORkkUkV4yDZ5QeAacP9ntwXj9vBNeFYF0AK0eX_vVTKwpYNd1syzDrFau8KfCXoScIOLWcPcOMxmih3ogExample 2
./nnl-mgmt.sh properties set -name android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.verification.key -value qgcwHPZbH3v-ScVZ-Z3VrfS9u_z7tCPTxVVDLK8o_TCtBhXNDYwFAhG5-T7-c5gTJ3Z-UFh6Tps9Lk7cbJHEFu74U41plMfQzPRIEnXk9jrqQDnzxMtD2xPXhAEaG0-GYcIkobcSe5L7WoSeBDehOpGwUl4ZovcCRxP_Z2Y3QwQdohm5_iMt_KOYKP--hDTAbT5Zikf9_9ps9nt4Example 2 Output
android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.decryption.key=2HFjVyi5p_K_zEOBKuJ41ORkkUkV4y...
android:com.noknok.android.tutorialappplus##nnl.play.integrity.jwt.verification.key=qgcwHPZbH3v-ScVZ-Z3VrfS9u_z7tC...
android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename=push-integrity-service_account_key.json
android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.secret=ynN9h95IyzcIQ0kx36RbUOWDMvQ6ZESgv...Example 3
./nnl-mgmt.sh properties set -name android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename -value /home/zsmith/push-integrity-service_account_key.jsonExample 3 Output
Validated packageName[android:com.noknok.android.tutorialappplus]
Successfully set property [android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filename] for tenant [default].Example 3 stores the filename in
android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.filenameand stores the encrypted content of the file in
android:com.noknok.android.tutorialappplus##nnl.play.integrity.service.account.key.secret
Tenant properties
This section describes properties for tenants that you create and for the default tenant. The default tenant is automatically created during installation. Users who don't need multi-tenancy utilize the default tenant. Wherever possible, the properties are grouped by function.
You can edit most tenant properties using the Admin Console. You can modify all tenant properties using the nnl-mgmt.sh's properties set command. An example is shown below:
./nnl-mgmt.sh properties set -name nnl.hist.store.operations -value 'FINISH_REG,FINISH_AUTH,UPDATE_REG,DELETE_REG,INIT_ADAPTIVE,SETUP,VERIFY,DELETE_METHODS' -tenantid investmentTo create and configure a new tenant, see Configure tenants.
UAF properties
If you use UAF authentication, make sure these properties have values. You can edit these through the Admin Console, Configuration > Authentication Methods > FIDO UAF.
Label in Admin Console | Tenant Property and Description |
|---|---|
App ID | uaf.application.id |
The App ID is the URL of facets.uaf, the file that contains your organization's list of trusted facet IDs. Digipass S3 strongly recommends that you assign the URL to facets.uaf as the App ID, even if your apps use an embedded FIDO client and, as a result, don't need to use facets.uaf. Assigning facets.uaf's URL also allows Digipass S3 Software to support credential sharing between apps in the future. The format is host:port/path_to/facets.uaf. See Assigning the App ID in Configure Tenants for more details.
| |
Challenge Expiration Time | uaf.challenge.validity.seconds |
The maximum amount of time, in seconds, that a user has to respond to a push notification or scan a QR code. Default value: 300 | |
Maximum Number of UAF Authenticators per User | uaf.reg.user.max.authenticators |
Maximum number of authenticators that can be registered for a user. Default value: 32 | |
Outdated Authenticator Version Behavior | uaf.outdated.authenticator.version.behavior |
Specifies what the Server should do if an authenticator is outdated. An authenticator is outdated if it has a lower version than the one specified in its corresponding metadata in the Server. Value must be one of:
| |
Request Android Key Attestation | nnl.send.android.key.attestation.extension |
Boolean. If true, the Server requests Android key attestation data from the client. Default value: false | |
Require Android Key Attestation for AAIDs | uaf.require.android.key.attestation.aaids |
Comma-separated list of AAIDs of UAF authenticators for which successful Android Key Attestation is required. For any improper Android Key Attestation extension values, the registration fails. Improper extension values include extension value 'p', 'a', corrupt, or empty.
| |
UAF List of Trusted Facet IDs | uaf.facet.id |
The list of trusted facet IDs. Each of the apps you implement has its own facet ID and appears in this list. This property is not required, since the Authentication Server can also derive this information from app-specific UAF properties. Default value: (for non-production installations only, this list is left blank for production installations) ios:bundle-id:com.noknok.ios.passport,ios:bundle-id:com.noknok.ios.tutorialappplus,ios:bundle-id:com.noknok.cordovatutorialapp,android:apk-key-hash:SvYZ4Sgas9T2+6DpNj566iscuns,android:apk-key-hash:Bc9rEk16GTEpN3bbD+4zV/H3Msk,com.noknok.uaf.test.client |
FIDO2 properties
If you use FIDO2 authentication, make sure these properties have values. You can edit these through the Admin Console, Configuration > Authentication Methods > FIDO2/WebAuthn.
Label in Admin Console | Tenant Property and Description |
|---|---|
Relying Party ID | webauthn.application.id |
The Relying Party (RP) ID for your organization. This is a domain. All your web apps' facet IDs must contain this domain.
| |
Relying Party Display Name | webauthn.application.rpdisplayname |
The human-readable display name for the RP which is associated with the registration. Default value: DEFAULT_TENANT | |
Challenge Expiration Time | webauthn.challenge.validity.seconds |
Expiration time of the challenge generated for FIDO2 operations, in seconds. Default value: 300 | |
FIDO2 List of Trusted Facet IDs | webauthn.facet.id |
The list of trusted facet IDs for FIDO2 apps. Each of the apps you implement has its own facet ID and appears in this list. By default, webauthn.facet.id is blank for the default tenant. This property is not required because the Authentication Server can also derive this information from app-specific FIDO2 properties. | |
Maximum Number of Authenticators per User | webauthn.reg.user.max.authenticators |
The maximum number of WebAuthn authenticators that a user can register. Default value: 32 | |
User Name to User ID Mapping Mode | webauthn.userid.mapping.mode |
Specifies how the user name maps to the user ID. The user ID is either the same as the user name or it is a salted hash of the user name. One of:
Default value: Salted_username_hash | |
User ID Salt Suffix | webauthn.userid.salt.suffix |
The salt used to hash the user name when webauthn.userid.mapping.mode is Salted_username_hash. Set to a random string, which is uniquely generated for a tenant when it is created. |
UAF transaction properties
To prevent transaction confirmation from being intercepted and abused, the Server generates an image that contains the confirmation text. The following properties are used by the Server to format and generate that image. Use nnl-mgmt.sh's set property command to modify these properties.
Label in Admin Console | Tenant Property and Description |
|---|---|
Background Color | uaf.png.font.bgcolor |
Background font color for transaction text. Default Value: WHITE | |
Font Color | uaf.png.font.fgcolor |
Foreground font color for transaction text. Default Value: BLACK | |
Font Size | uaf.png.font.size |
Font size for transaction text. Default Value: 12 | |
Font Type | uaf.png.font.type |
Font type for transaction text. Possible values are Serif, SansSerif, Monospaced, Dialog, and DialogInput. Default Value: SansSerif |
Out-of-band authentication properties
If your apps use out-of-band (OOB) authentication, these properties need values.
Use the Admin Console to edit these properties. Configuration > Authentication Methods > Out-of-Band.
Label in Admin Console | Tenant Property and Description |
|---|---|
Challenge Expiration Time | oob.challenge.validity.seconds |
The maximum period of time, in seconds, in which a user has to respond to a generated challenge for an out-of-band operation. The generated challenge is either a push notification or QR Code. Default: 180 | |
Registration URL | oob.reg.url |
URL required for an out-of-band registration operation. Example: https://www.example.com:1234/nnlgateway/nnl/reg | |
Authentication URL | oob.auth.url |
URL required for an out-of-band authentication operation. Example: https://www.example.com:1234/nnlgateway/nnl/auth | |
Push Handle Expiration Time (Days) | oob.pushhandle.expiry.time.days |
Expiration time of push handle, in days. Default Value: 30 | |
Maximum Number of Push Notification Attempts | oob.maximum.notification.sent.count |
Maximum number of push notification attempts. When the limit is reached, the push handle is marked as invalid. Default Value: 10 | |
Push Notification Authentication Text | oob.auth.notification.text |
String to display as the push notification that prompts the user to authenticate if oob.auth.notification.text's value is Static. Default Value: Authentication | |
Push Notification Authentication Text Mode | oob.auth.notification.text.mode |
Specifies whether the push notification text that prompts the user to authenticate is static or custom. One of:
Default Value: "Static" | |
Push Notification Transaction Text | oob.transaction.notification.text |
Push notification display text for an out-of-band transaction. Default Value: "Auth Transaction" | |
Push Notification Transaction Text Mode | oob.transaction.notification.text.mode |
Specifies if the push notification text that prompts the user to confirm a transaction is static or custom. One of:
Default Value: "Static" |
Google Geocoding API property
Unlike mobile apps, a web-based app can only send the latitude and longitude of the user's location, not the country code. To enable your web app to use an Adaptive Rule whose condition contains a Countries list, you need to configure the Google Geocoding API. Once that configuration is done, the Digipass S3 Server can get the country code from the latitude and longitude.
This property was introduced in version 8.0.1.
Label in Admin Console | Tenant Property and Description |
|---|---|
Google Geocoder API Key | nnl.geo.coder.google.api.key |
Your encrypted API key for the Google Maps Platform. For instructions on how to obtain and set this key, See Configure the Google Geocoding Service. Also see the System property Google Geocoding API URL under System Tenant Properties. |
Audit Log properties
Audit logging provides a way to help meet regulatory compliance and can also help with debugging. If you don’t have regulatory requirements, turn audit logging off to reduce I/O and disk storage requirements.
You can edit these properties in the Admin Console. Use Configuration > Compliance > Audit Logging.
To learn more about audit logs, see Configure Audit Logging.
Label in Admin Console | Tenant Property and Description |
|---|---|
Enable Runtime Audit Logging in JSON | nnl.audit.logger.enabled |
Boolean. Specify whether audit logging in JSON is turned on for the tenant. One of:
| |
Enable Runtime Audit Logging in CSV | nnl.csv.audit.logger.enabled |
Boolean. Specify whether CSV audit logging is turned on for the tenant. One of:
|
Privacy properties
Choose which individual Personally Identifiable Information (PII) you want to store by using the Admin Console, or by using the CLI to set the nnl.storage.extension.list tenant property.
Using the Admin Console, navigate to Configuration > Compliance > Privacy. By default, the Server stores the end user's location information.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A13%3A18Z&se=2026-09-30T02%3A44%3A18Z&sr=c&sp=r&sig=mvCUXcextK%2BogRF%2FvqhZMk87kFi1l%2BiPOV9ClTdV%2Bqk%3D)
Alternatively you can use the CLI to set the value for the nnl.storage.extension.list property. The following command tells the Server to store the user's location, IP Address, and Wifi SSID.
./nnl-mgmt.sh properties set -name nnl.storage.extension.list -value noknok.metrics,noknok.appattest,noknok.uaf.location,noknok.ipaddress,noknok.wifi.ssidBy default, the Server stores metrics and appattest information also, but if you do not include noknok.metrics and noknok.appattest in the list when you set the value for the nnl.storage.extension.list property using the CLI, then the Server does not store metrics nor appattest information.
Since the example properties set command above does not include the -tenantid parameter, it applies only to the default tenant.
Notes:
When you use the CLI to set the nnl.storage.extension.list property, if you do not include any of the 5 pieces of information in the value list, whatever you omit is not stored in the database.
If the Server does not receive this information from the App SDK, it can't store it.
You must store information in the database in order to include it in the runtime audit logs.
See section Managing Personally Identifiable Information (PII) in the Android, iOS or Web Developer Guide for information on how your app can allow end users to view and delete their Personally Identifiable Information.
Admin tenant properties
This section describes properties for the Admin tenant. Wherever possible, the properties are grouped by function. You can modify these properties in the Admin Console, unless noted otherwise, provided that you are a Super Admin or an Admin in the Admin tenant. Change the tenant to Admin and navigate to Configuration > Admin.
You can edit all of these properties using the nnl-mgmt.sh's properties set command. After changing a property using nnl_mgmt.sh, the Auth Server immediately enforces the new value. An example is shown below:
./nnl-mgmt.sh properties set -name nnl.admin.audit.logger.enabled -value false -tenantid AdminAudit logging
Label in Admin Console | Admin Tenant Property and Description |
|---|---|
Enable Admin Audit Logging | nnl.admin.audit.logger.enabled |
Optional. Specifies whether the admin audit logging is enabled or not.
|
Transient data purge
Label in Admin Console | Admin Tenant Property and Description |
|---|---|
Enable Transient Data Purge in Background | nnl.transient.data.purge.thread.enabled |
Optional. Whether transient data is automatically purged.
| |
Transient Data Purge Interval | nnl.transient.data.purge.interval |
Optional. Polling interval, in seconds, for purging transient data. At the specified interval, the Admin Server checks for new expired transient data and deletes it. Default Value: 30 | |
Transient Data Purge Batch Size | nnl.transient.data.purge.batch.size |
Optional. Number of transient data records to delete in one transaction. Default Value: 100 |
FIDO metadata
Label in Admin Console | Admin Tenant Property and Description |
|---|---|
FIDO Alliance Metadata Service Certificate | nnl.fido.mds3.cert |
Mandatory. Certificate that authorizes your access to the FIDO Alliance Metadata Service. The current certificate is valid until March 18, 2029. You must use nnl-mgmt.sh to set this property. Example: | |
FIDO Alliance Metadata Service URL | nnl.fido.mds3.url |
Mandatory. The URL where you can access the FIDO Alliance Metadata Service. Default value is https://mds.fidoalliance.org. This URL is unlikely to change. You must use nnl-mgmt.sh to set this property, if it needs to be updated. For example: | |
Enable Metadata Updates | nnl.admin.metadata.edit.enabled |
Optional. Enable or disable authenticator metadata updates in the Admin Console.
|
Imported file sizes
The following table lists configurable properties, their default values, and the type of imported file that the property applies to. Although these properties are defined on the Admin tenant, the limits apply to all tenants in your deployment. If a user tries to import a file that is larger than the limit, the system shows an error message. This prevents users from uploading large files to the Auth Server either through the Admin Console or by using nnl_mgmt.sh, the command line interface.
Admin Tenant Property | Default Maximum Size | Import File Type |
|---|---|---|
nnl.android.app.file.max.size.mb | 100 MB | APK file that you can import for a new Android app. |
nnl.api.server.config.file.size.kb | 512 KB | nnlgateway.json configuration file |
nnl.api.server.config.plugins.file.size.kb | 256 KB | API Server configuration files |
nnl.app.file.size.kb | 512 KB | Client app configuration files |
nnl.auth.server.config.file.size.kb | 256 KB | Auth Server configuration file |
nnl.fcm.http.key.size.kb | 10 KB | FCM HTTP key file. The Auth Server uses this key to mint the OAuth 2.0 access token that FCM uses to authorize requests |
nnl.ios.app.file.max.size.mb | 100 MB | IPA file that you can import for a new iOS app |
nnl.ios.token.cert.file.size.kb | 10 KB | Encrypted certificate password required for APNs push notification |
nnl.ios.token.signing.key.file.size.kb | 1 KB | P8 file containing your authentication token signing key |
nnl.list.auth.group.file.size.kb | 128 KB | Authenticator group list |
nnl.list.auth.metadata.file.size.kb | 128 KB | Authenticator metadata file |
nnl.list.country.file.size.kb | 128 KB | Country list |
nnl.list.device.model.file.size.kb | 128 KB | Device model list |
nnl.list.geofence.file.size.kb | 128 KB | Geofence list |
nnl.list.ip.address.file.size.kb | 128 KB | IP address list |
nnl.list.wifi.address.file.size.kb | 128 KB | WiFi network address list |
nnl.policies.file.size.kb | 128 KB | FIDO policy file |
nnl.rulesets.file.size.kb | 512 KB | Adaptive Ruleset file |
ZIP file properties
Admin Tenant Property | Default Maximum Size | Description |
|---|---|---|
nnl.zip.entry.threshold.ratio | 50 | Compression ratio for a ZIP file entry during import |
nnl.zip.entry.threshold.size.mb | 100 MB | Size for an individual uncompressed entry in a ZIP file |
nnl.zip.threshold.entries | 1000 | Number of entries in a ZIP file that can be imported |
External login for the Admin Console
Label in Admin Console | Admin Tenant Property and Description |
|---|---|
Enable Using an External Authentication System Instead of the Built-in FIDO Login for the Admin Console | nnl.external.login.enabled |
Optional. Enable using an external login instead of the built-in FIDO login for the Admin Console.
You must use nnl-mgmt.sh to set this property, as shown below. You must also perform the configuration described in Replacing FIDO Login in the Admin Console. | |
Logout Page URL | nnl.logout.url |
Optional. If you are using an external authentication system to sign in your Admin users to the Admin Console, you can optionally assign the URL to your custom logout page using this property. When an Admin user navigates to Settings > Log Out in the Admin Console, the custom logout page is loaded. For details, see Replacing FIDO Login in the Admin Console. You must use nnl-mgmt.sh to set this property, as shown below. |
System tenant properties
Digipass S3 Software uses the SYSTEM tenant as a container for properties that are common to all tenants. The SYSTEM tenant is automatically created and configured when you install the Digipass S3 Server.
Customers rarely need to modify these SYSTEM properties. If you think your installation could benefit from modifying one or more of these properties, please consult with OneSpan customer support.
You can use nnl-mgmt.sh's properties command to list these properties.
./nnl-mgmt.sh properties list -tenantid SYSTEMThese properties can only be changed using the command-line tool nnl-mgmt.sh. After changing the value of a SYSTEM tenant property, you must restart the Server for the change to take effect.
Name | System Tenant Property | Description |
|---|---|---|
Cache Expiration | nnl.cache.local.expiry.time.seconds | The expiration time, in seconds, for local cache implementation. Default Value: 300 |
Custom Crypto Classname | nnl.crypto.custom.impl.class.name | The name of the class that implements the custom CryptoService. |
Encrypt Transient Data | nnl.db.transient.store.encrypt.data | If true, encrypts transient data that is stored in the database. Default Value: false |
Authentication Method Configurations | nnl.identity.method.config | A JSON containing configurations for the authentication methods used by Digipass S3 Software:
Default Value: {"Email OTP":{"className":"com.noknok.identity.method.email.EmailMethodPlugin","systemConfigurations":{"serviceFactory":"com.noknok.platform.services.PlatformServiceFactory"},"genericConfigurations":{"smtp.host.allowlist":[]}},"SMS OTP":{"className":"com.noknok.identity.method.sms.SMSOtpMethodPlugin","systemConfigurations":{"serviceFactory":"com.noknok.platform.services.PlatformServiceFactory"}},"Photo ID":{"className":"com.noknok.identity.method.nv.NVPictureIdMethodPlugin","systemConfigurations":{"serviceFactory":"com.noknok.platform.services.PlatformServiceFactory","server.url":"https://netverify.com/api/netverify/v2/scans/"}},"FIDO Auth":{"className":"com.noknok.identity.method.fido.FidoMethodPlugin"},"FIDO OOB Auth":{"className":"com.noknok.identity.method.oob.OOBMethodPlugin"},"External Auth":{"className":"com.noknok.identity.method.external.auth.ExternalAuthMethodPlugin"}} |
JCE Providers | nnl.jce.providers | A comma-separated list of Java Cryptography Extension (JCE) providers. Default Value: org.bouncycastle.jce.provider.BouncyCastleProvider |
License Accepted | nnl.license.accept | Must be true for the Server to work. Indicates that you accept the terms of the Digipass S3 license. See the license terms at <NNL_HOME>/licenses/noknok-license.txt. Default Value: true |
Allowed Skew Time | nnl.server.clock.max.skew.millis | Allows the system time to be slightly different among the servers in your cluster. The value is in milliseconds. Default Value: 1000 |
Tenant Properties Polling Interval | nnl.tenantservice.update.poll.interval.seconds | The polling interval in seconds for the Server to read its database and refresh its cache of tenant-specific properties. Default Value: 120 |
Google Geocoding API URL | nnl.geo.coder.api.url | The URL for the Google Reverse Geocoding API. Also see the Google Geocoding API Key. Default Value: https://maps.googleapis.com/maps/api/geocode/json |
HMS Push Notification Classname | oob.hms.notification.class.name | The class for HMS push notifications. This property was introduced in version 7.0.2. In versions 9.0.0 and earlier, this property was required. Default Value:
|
APNS Push Notification Classname | oob.ios.notification.class.name | The class for APNS push notifications. Default Value:
com.noknok.oob.push.impl.APNSNotificationSenderServiceImpl |
Pool Size for APNS Server Connections | oob.ios.apns.server.pool.size | Size for the pool of connections to APNS servers. Max size allowed: 15 Default Value: 5 |
Enable the Listing of Pending Authentications | oob.list.auth.enabled | When true, the REST API operation LIST_OOB_AUTH returns pending out-of-band authentications. This property was introduced in version 9.1.0. Default Value: false |
Advance Policy Cache Expiry | nnl.policy.cache.expiry.time.seconds | Expiration time, in seconds, for entries in the advance policy cache. Introduced in version 9.0.0. Default Value: -1 (cache doesn’t expire) |
Advance Policy Cache Maximum Entries | nnl.policy.cache.max.size | Maximum number of entries that the advance policy cache can hold at one time. Introduced in version 9.0.0. Default Value: -1 (cache doesn’t restrict the number of entries) |
Policy Cache Polling Interval | nnl.policy.update.poll.interval.seconds | The polling interval, in seconds, for the Server to check if there have been any updates to any tenant policies. Default Value: 120 |
Elapsed Time Threshold | nnl.api.elapsed.time.threshold.millis | If the response time (in milliseconds) to a REST API operation request is longer than this property's value, the Server logs a warning in the nnl.log file. Below is an example that was logged after an INIT_ADAPTIVE request: Default Value: 3000 |
Return Elapsed Time in the Response | nnl.api.response.include.elapsed.time | When true, the API Server returns the elapsed time in milliseconds between a REST operation's request and the response, provided that:
Note that when runtime audit logs are enabled, the elapsed time between the request and the API Server's response is always included in the runtime audit logs. Default Value: false |
Here is an example of a response filter that includes the elapsedTime in the response from the API Server. For more information, see Response Filter Configuration.
{
"additionalInfo":{
"elapsedTime":true,
"device":true,
"authenticatorsResult":[
{
"handle":true,
"attachmentHints":true
}
]
}
}For more information about additionalInfo, see additionalInfo in the REST API Reference.