Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Authenticator Metadata Commands

Prev Next

Download from the Metadata Service

Syntax

./nnl-mgmt.sh auth_metadata download -dir <directory> [-disablecrl <yes|no>]

Parameter

Description

dir

Mandatory. Directory where the metadata is downloaded.

disablecrl

Optional. yes disables the check on the Certificate Revocation List. If not provided, the check on CRL is enabled.

Description

Use this command to download and process all MDS3-compatible authenticator metadata to generate 3 reports. The download command requires an outgoing connection to the FIDO Alliance Metadata Service from the computer where it runs.

The command downloads metadata from the FIDO Alliance Metadata Service and creates the directory structure shown below. If the directory you supply contains metadata files and reports from a previous execution of this command, then they are overwritten.

<dir>
  ├── metadata
  │    ├── fido2
  │    ├── u2f
  │    └── uaf
  ├── nnl-mds3-report.csv
  ├── nnl-mds3-report.json
  └── nnl-mds3-summary-report.txt

Each metadata JSON file is located in the protocol directory associated with that authenticator. For example, the file for a Windows Hello hardware authenticator, a FIDO2 authenticator, can be found in the fido2 directory.

The reports are written to the supplied directory. They contain the status and information about each authenticator in different formats. Check nnl-mds3-summary-report.txt for any flagged authenticators. See the FIDO Alliance Metadata Service for more information.

Examples

./nnl-mgmt.sh auth_metadata download -dir project_metadata
startcode./nnl-mgmt.sh auth_metadata download -dir project_metadata -disablecrl yes

Process Previously Downloaded Metadata

Syntax

./nnl-mgmt.sh auth_metadata process -file <mds3 metadata blob file> -dir <dir-path> [-disablecrl <yes|no>]

Parameter

Description

dir

Mandatory. Directory where the metadata is placed after extraction from blob.jwt file.

file

Mandatory. Absolute path to MDS3 metadata blob .jwt file that was previously downloaded from a metadata service.

disablecrl

Optional. yes disables the check on the Certificate Revocation List. If not provided, the check on CRL is enabled.

Description

Use this command to process MDS3-compatible authenticator metadata that has already been downloaded. It extracts individual metadata and places it into the directory depending on its protocol, and generates the same 3 reports as the download command generates. Output from the process command is the same as the output from the download command.

Example

./nnl-mgmt.sh auth_metadata process -file mds3_metadata_blob_file -dir project_metadata

Import

Syntax

./nnl-mgmt.sh auth_metadata import (-dir <auth-spec-dir>|-file <auth‑spec‑file>)

You must supply either the directory name or the file name in your request, otherwise this command fails.

Parameter

Description

dir

Name of the directory which contains the metadata JSON files. You must specify the directory if you do not provide a file name.

file

Name of the JSON file. The auth metadata from the JSON file is loaded into the database. You must specify the file name if you do not provide a directory.

Description

Use this command to import or update authenticator-specific metadata.

  • The authenticator is imported or updated from a directory or JSON file. The -dir option processes all files with a .json extension within the specified directory.

  • Before updating the Server with new metadata statements, validate them first using the FIDO Conformance Tool at https://fidoalliance.org/conformance/.

  • The maximum size of the authenticator metadata file that can be imported is 128 KB. This default maximum size can be changed by setting the nnl.list.auth.metadata.file.size.kb property for the Admin tenant.

Examples

./nnl-mgmt.sh auth_metadata import -dir test_directory 
./nnl-mgmt.sh auth_metadata import -file test_file.json

Change the maximum size of the authenticator metadata file to 20KB:

./nnl-mgmt.sh properties set -name nnl.list.auth.metadata.file.size.kb -value 20 ‑tenantid Admin

Export

Syntax

./nnl-mgmt.sh auth_metadata export (-aaid <aaid>|-aaguid <aaguid>|-acki <acki>) -file <path-to-file>

Parameter

Description

aaid OR

aaguid OR

acki

Mandatory. Authenticator Metadata ID to be exported. One of

  • AAID - Authenticator Attestation ID for UAF authenticator metadata

  • AAGUID - Authenticator Attestation GUID for FIDO2 authenticator metadata

  • ACKI - Attestation Certificate public Key Identifier for U2F authenticator metadata

If there are multiple auth metadata for a given AAID with different auth versions, the auth metadata with the maximum authenticator version is exported.

file

Mandatory. The system exports the authenticator metadata to this file path. If you don’t provide the file path, the command fails.

Description

Exports authenticator-specific metadata to the specified JSON file.

Example

./nnl-mgmt.sh auth_metadata export -aaid <aaid> -file /home/zsmith/exported_metadata.json

List

Syntax

./nnl-mgmt.sh auth_metadata list [-pf (uaf|u2f|fido2)]

Parameter

Description

pf

Optional. Protocol family. One of

  • uaf (default)

  • u2f

  • fido2

Description

Lists the authenticators.

Example

./nnl-mgmt.sh auth_metadata list

Print

Syntax

./nnl-mgmt.sh auth_metadata print (-aaid <aaid>|-aaguid <aaguid>|-acki <acki>)

Parameter

Description

aaid OR

aaguid OR

acki

Mandatory. Authenticator Metadata ID to be listed. One of

  • AAID - Authenticator Attestation ID for UAF authenticator metadata

  • AAGUID - Authenticator Attestation GUID for FIDO2 authenticator metadata

  • ACKI - Attestation Certificate public Key Identifier for U2F authenticator metadata

Description

Prints authenticator metadata.

Example

./nnl-mgmt.sh auth_metadata print -aaid ABCD#ABCD

Delete

Syntax

./nnl-mgmt.sh auth_metadata delete (-aaid <aaid>|-aaguid <aaguid>|-acki <acki>) [-version <version>]

Parameter

Description

aaid OR

aaguid OR

acki

Mandatory. Authenticator Metadata ID to be deleted. One of

  • AAID - Authenticator Attestation ID for UAF authenticator metadata

  • AAGUID - Authenticator Attestation GUID for FIDO2 authenticator metadata

  • ACKI - Attestation Certificate public Key Identifier for U2F authenticator metadata

version

Optional. Version of the authenticator to be deleted. If the authenticator version is not provided, the command deletes authenticators matching the AAID regardless of version.

Description

Deletes authenticator metadata.

Example

./nnl-mgmt.sh auth_metadata delete -aaid ABCD#ABCD -version 1