Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Authenticator Commands

Prev Next

Getactiveusercount

Syntax

./nnl-mgmt.sh authenticators getactiveusercount -from <startdate> -to <enddate> [-tenantid <tenantid> | -alltenants (yes | no)] [-file csv-file-name>]

Parameter

Description

from

Mandatory. Start date. Must be before the end date. Format is yyyy-mm-dd.

to

Mandatory. End date. Must be the same as start date or after it. This date is included in the period of time used to tally the active user count. Format is yyyy-mm-dd

tenantid

Optional. The command only counts active users who belong to this tenant.

alltenants

Optional. Indicates if the command should look at all users, regardless of what tenant they belong to.

  • Yes: Tally all active users by tenant.

  • No (default): Tally active users only for the default tenant.

file

Optional. The name of a .csv file. Output from this command is written to the file instead of to stdout.

Description

Returns the number of unique users who have authenticated at least once between the start and end date. If from and to are the same date, then this command returns the active user count for that date (from 00:00 to 23:59). The command uses the same time zone as the machine where you run it.

If you specify both -alltenants no and -tenantid <tenantid>, then the command returns the active user count for <tenantid>.

Example 1

./nnl-mgmt.sh authenticators getactiveusercount -from 2023-02-01 -to 2023-02-07 -alltenants yes

Sample output

Active User Count
from: 2023-02-01 
to: 2023-02-07
+--------------------------------------------+-----------------------------+
| Tenant ID                                  | Active User Count           |
+--------------------------------------------+-----------------------------+
| default                                    | 355                         |
+--------------------------------------------+-----------------------------+
| Admin                                      | 3                           |
+--------------------------------------------+-----------------------------+
| Test                                       | 1                           |
+--------------------------------------------+-----------------------------+
| TOTAL                                      | 359                         |
+--------------------------------------------+-----------------------------+

Example 2

./nnl-mgmt.sh authenticators getactiveusercount -from 2023-02-01 -to 2023-02-07 -file /tmp/active-users.csv -alltenants yes

Contents of /tmp/active-users.csv file

tenant,activeUsercount
Admin,4
default,16
spc,6
TOTAL,26

Get Stats

Syntax

./nnl-mgmt.sh authenticators getstats [-pf (uaf| fido2| all)] [-aaid <aaid> | -aaguid <aaguid> | -username <username>] -tenantid <tenantid> [-file <csv-file-name>]

The aaid and the username cannot be used in the same command.

Parameter

Description

pf

Optional. Protocol family. One of

  • uaf (default)

  • fido2

  • all

aaid

Optional. Displays the statistics for this UAF authenticator ID.

aaguid

Optional. Displays the statistics for this FIDO2 authenticator ID.

username

Optional. Displays the statistics of a user by providing the relevant user name.

tenantid

Optional. Get statistics for this tenant. Default value is default

file

Optional. CSV filename with absolute path.

Description

This command returns the following statistics for an authenticator.

  • RegCount - Total registration count

  • AuthCount - Total successful authentication count

  • DeletedCount - Total deleted registrations

Depending on the parameters that you provide, get stats can return this information for a single authenticator or for each authenticator in a set of authenticators.

  • For the set of authenticators that are registered by all users in a tenant, only provide tenantid.

  • For the set of authenticators registered by a specific user, provide the username and tenantid.

  • For a specific authenticator, provide either the aaid or aaguid as well as tenantid. You do not need to provide pf. If you provide pf, it must match the authenticator's protocol. The results aggregate statistics for this authenticator across all users in the tenant who registered it.

You can filter the set of authenticators by providing the protocol family. By default, the command only returns results for UAF authenticators. To get results for an authenticator regardless of protocol, assign all to pf.

By default, statistics are displayed. To export the authenticator statistics, provide file.

Examples

./nnl-mgmt.sh authenticators getstats 
./nnl-mgmt.sh authenticators getstats -tenantid finance
./nnl-mgmt.sh authenticators getstats -aaid ABCD#ABCD
./nnl-mgmt.sh authenticators getstats -aaid ABCD#ABCD -tenantid finance
./nnl-mgmt.sh authenticators getstats -username user1
./nnl-mgmt.sh authenticators getstats -username user1 -tenantid finance
./nnl-mgmt.sh authenticators getstats -aaguid  ba86dc56-635f-4141-aef6-00227b1b9af6
./nnl-mgmt.sh authenticators getstats -aaguid  ba86dc56-635f-4141-aef6-00227b1b9af6 -tenantid finance
./nnl-mgmt.sh authenticators getstats -pf fido2
./nnl-mgmt.sh authenticators getstats -pf fido2 -tenantid finance
./nnl-mgmt.sh authenticators getstats -pf all
./nnl-mgmt.sh authenticators getstats -pf all -tenantid finance

Example, with results, of getting stats for all UAF authenticators in the default tenant.

./nnl-mgmt.sh authenticators getstats -pf uaf
+==========+===========+=============+=======================+===========+==========+==============+
| TenantID | AAID      | AuthVersion | Description           | AuthCount | RegCount | DeletedCount |
+==========+===========+=============+=======================+===========+==========+==============+
| default  | ABCD#ABCD | 1           | ABCD#ABCD description | 3         | 2        | 0            |
+==========+===========+=============+=======================+===========+==========+==============+

Example, with results, of getting stats for all FIDO2 authenticators in the default tenant.

./nnl-mgmt.sh authenticators getstats -pf fido2
+==========+======================================+=============+==============================+===========+==========+==============+
| TenantID | AAGUID                               | AuthVersion | Description                  | AuthCount | RegCount | DeletedCount |
+==========+======================================+=============+==============================+===========+==========+==============+
| default  | 08987058-cadc-4b81-b6e1-30de50dcbe96 | 0           | Generic FIDO 2 Authenticator | 0         | 2        | 0            |
+==========+======================================+=============+==============================+===========+==========+==============+

Example, with results, of getting stats for all authenticators in the default tenant, regardless of protocol.

./nnl-mgmt.sh authenticators getstats -pf all
+==========+======================================+=============+==============================+===========+==========+==============+
| TenantID | AAID/AAGUID                          | AuthVersion | Description                  | AuthCount | RegCount | DeletedCount |
+==========+======================================+=============+==============================+===========+==========+==============+
| default  | ABCD#ABCD                            | 1           | ABCD#ABCD description        | 3         | 2        | 0            |
| default  | 08987058-cadc-4b81-b6e1-30de50dcbe96 | 0           | Generic FIDO 2 Authenticator | 0         | 2        | 0            |
+==========+======================================+=============+==============================+===========+==========+==============+

Purge

Syntax

./nnl-mgmt.sh authenticators purge [-tenantid <tenantid>]  [-batchsize <batchsize>]

Parameter

Description

tenantid

Optional. Authenticator data is deleted for this tenant ID. Default value is default

batchsize

Optional. The maximum number of records to delete in one iteration. If not provided, it deletes records in a single iteration.

Description

For the given tenant, permanently deletes all the data marked for deletion that are related to FIDO and non-FIDO authentication methods. Devices marked for deletion are also deleted by this command.

In previous releases, this command had a pf (protocol family) parameter. That parameter is ignored if provided.

Nok Nok recommends using the disable command before using this command. 

Examples

./nnl-mgmt.sh authenticators purge -tenantid finance
startcode./nnl-mgmt.sh authenticators purge -tenantid finance -batchsize 10000

Disable

Syntax

./nnl-mgmt.sh authenticators disable (-inactivity <inactivity-time-in-days> | ‑retain-most-recently-used <number-of-registrations-to-keep>) [-pf (uaf|fido2|other)] [-tenantid <tenantid>] [-batchsize <batchsize>]

Parameter

Description

inactivity

Conditional. The minimum number of days that the registration has been inactive. Cannot be used with retain-most-recently-used.

retain-most-recently-used

Conditional. The maximum number of registrations per user to retain. Only the most recently used registrations are kept. Cannot be used with inactivity.

pf

Optional. Protocol family. One of

  • uaf (default)

  • fido2

  • other

tenantid

Optional. Authenticator metadata is disabled for this tenant ID. Default value is default.

batchsize

Optional. The maximum number of records to disable in one iteration. If not provided, all records are disabled in a single iteration.

batchsize should be less than or equal to 1000 when used with the -retain-most-recently-used parameter.

Description

Disables data related to FIDO and non-FIDO authenticator registrations for the given tenant.
For the specified tenant, this command does one of the following:

  • Finds and disables registrations that have not been used for more than the number of days specified by inactivity.

  • Keeps up to the retain-most-recently-used registrations for each user and disables the rest.

  • Disables registrations for the specified UAF, FIDO2, or non-FIDO (other) authenticators.

You cannot use both inactivity and retain-most-recently-used in this command.

You can use this command in conjunction with the purge command to identify and disable inactive registrations prior to deleting them permanently.

Examples

To identify, disable, and delete FIDO2 registrations that haven’t been used in 1 year or more in the default tenant:

./nnl-mgmt.sh authenticators disable -inactivity 365 -pf fido2
./nnl-mgmt.sh authenticators purge

To identify, disable, and delete UAF registrations other than 10 most-recently-used for every user in the default tenant. Results in every user having, at most, 10 of their most-recently-used registrations.

./nnl-mgmt.sh authenticators disable -retain-most-recently-used 10
./nnl-mgmt.sh authenticators purge

Identify and disable non-FIDO registrations that haven't been used in 1 year in the default tenant. purge deletes 10,000 registrations in each iteration.

./nnl-mgmt.sh authenticators disable -inactivity 365 -pf other -batchsize 10000
./nnl-mgmt.sh authenticators purge -batchsize 10000

To identify and disable UAF registrations that haven’t been used in 4 or more days in the finance tenant.

./nnl-mgmt.sh authenticators disable -inactivity 4 -tenantid finance

To identify and disable user UAF registrations other than 10 recently used in the default tenant. purge deletes 10,000 registrations in each iteration.

./nnl-mgmt.sh authenticators disable -retain-most-recently-used 10 -batchsize 1000
./nnl-mgmt.sh authenticators purge -batchsize 10000

To identify and retain only 10 most recently used user UAF registrations and disable the remaining UAF registrations in the finance tenant.

./nnl-mgmt.sh authenticators disable -retain-most-recently-used 10 -tenantid finance