Before you begin the installation process, perform the following tasks. Make sure you have administrator privileges when you create directories and install programs.
1. Ensure that your software infrastructure includes the prerequisites listed in the Installation Requirements section of the Server Release Notes.
2. Determine the total number of Runtime nodes in your deployment. Refer to Best Practices for Deployment for guidance on how to determine the optimal number of Runtime nodes.
3. Provision a valid TLS certificate for the publicly accessible endpoint. Typically, this is the Nok Nok API Server or a load balancer.
4. Make sure you have compatible versions of all required third party software installed. See Server Release Notes for details.
5. Run java -version to verify it is in the path.
6. Verify that the Tomcat work folder allows full access.
7. Verify that Tomcat is correctly configured to use TLS. For information on configuring TLS, see TLS Configuration.
8. Select the database you want to use. This can be a compatible version of Oracle Database, MySQL Server, CockroachDB, or PostgreSQL + corresponding JDBC driver.
9. Install and configure your operational database. Operational data includes registration and transient data as well as Adaptive Rules, data lists required by those Adaptive Rules, FIDO policies, and supporting data.
If you are using AWS RDS with an AWS RDS Wrapper Driver for your operational database, see Installing the Nok Nok Server Using the AWS JDBC Wrapper Driver Technical Note before continuing.
Specify the UTF-8 character encoding when you create the database so that Unicode characters can be stored.
PostgreSQL: CREATE DATABASE nnldb ENCODING 'UTF8'
MySQL: CREATE DATABASE innodb CHARACTER SET utf8mb4
Oracle: CREATE DATABASE nnldb ... CHARACTER SET AL32UTF8
CockroachDB: By default, CockroachDB uses UTF-8 encoding.
Instructions:
Ensure that the database server accepts incoming connections from Nok Nok components.
Determine the file path to the JDBC driver for your database. Note that a PostgreSQL JDBC driver is included as part of the package.
Determine the database port.
Ensure that the access credentials to the database have sufficient privileges to:
PostgreSQL, CockroachDB and MySQL - create tables and users.
Oracle - create tables
You should have the following privileges: select, insert, update, delete, create, references, index, drop, and alter.
Create the Authentication Server database and user. See Important Note above to specify UTF-8 character encoding while creating the database so that Unicode characters can be stored.
If you are installing a PostgreSQL database on Amazon RDS, you need to grant yourself rights to the database.
# Sign in as db_admin
#
CREATE USER db_user WITH PASSWORD 'db_password' CREATEDB;
#
# Create database "nnldb"
#
CREATE DATABASE nnldb ENCODING 'UTF8';
GRANT ALL PRIVILEGES ON DATABASE nnldb TO db_user;
GRANT db_user to db_admin;The second grant is the RDS-specific requirement.
Required only for MySQL: Load the time zone tables. The MySQL installation procedure creates time zone tables, but does not load them. Use the command below to load them manually, see Populating the Time Zone Tables:
# mysql_tzinfo_to_sql /usr/share/zoneinfo | mysql -u root -p mysqlCreate additional database users that you need.
Optional: Now that you have your database installed and configured, you can manually create the database tables. Skip this step if you want Nok Nok's installation script to create the database schema for you.
The table below lists the scripts to use to manually create the Operational Database schema for each type of database.
Database | SQL Script Names | Script Location |
|---|---|---|
Postgres |
| mfas/install/internal/packages/server/sql/ |
| mfas/install/internal/packages/gateway/sqls/sql/ | |
MySQL |
| mfas/install/internal/packages/server/sql/ |
| mfas/install/internal/packages/gateway/sqls/sql/ | |
Oracle |
| mfas/install/internal/packages/server/sql/ |
| mfas/install/internal/packages/gateway/sqls/sql/ | |
CockroachDB |
| mfas/install/internal/packages/server/sql/ |
| mfas/install/internal/packages/gateway/sqls/sql/ |
10. Optional: Determine if you want your users to utilize a mobile app on a mobile phone to perform strong authentication for accessing your web app. This is called out-of-band (OOB) authentication. You can also make this decision after installation. You need to configure apps that you develop to use OOB authentication, follow the steps in Out-of-band.
11. Identify the following locations, located off a root directory:
The full path to the install directory for the Server, for example: /opt/mfas. Referred to as <NNL_HOME> on this page.
The full path to the install directory for Tomcat, for example: /opt/tomcat. Referred to as <TOMCAT_HOME>.
The full path to the JDK install directory. Referred to as <JAVA_HOME>.
You are now ready to install the product.