Introduction
Production deployments require continuous availability while remaining accessible for updates. Deployments also need to be secured per your organization's security policies. Taking these into consideration, this page outlines the best practices recommended for production deployments of Digipass S3 Authentication Software, version 9.5.0.
There are also operational aspects of Digipass S3 Authentication Software that include day-to-day operations, preventative maintenance and updates. Find recommendations for these aspects that ensure security and high performance in your deployment in Best Practices for Operation.
The recommendations presented here include key aspects to consider prior to planning a deployment. These include general recommendations for storage, security, server failover, increased availability, and other guidance specific to Digipass S3 Authentication Software. These pre-implementation recommendations are further categorized as follows:
Designing Your Deployment
Database Setup
Data Storage Planning
Database Replication
Authentication Server Cluster
Admin Server
Command-line Tools
Load Balancing
Disaster Recovery
Before Installation
Secure Tomcat
Limit the size of POST requests to Digipass S3 Servers
Configure your network to only allow traffic that is needed
Securing Communication Between Components
Enabling Supported Algorithms in TLS
Securing Credentials
Specifying the database's character encoding
After Installation
Allowed Authenticators
Allowed Apps
Securing Session and Transaction Management
Unused Plugins
Personally Identifiable Information (PII)
Details on these best practices follow. They have been summarized into checklists that you can find in Deployment Checklists.