Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Best practices for deployment

Prev Next

Introduction

Production deployments require continuous availability while remaining accessible for updates. Deployments also need to be secured per your organization's security policies. Taking these into consideration, this page outlines the best practices recommended for production deployments of  Digipass S3 Authentication Software, version 9.5.0.

There are also operational aspects of Digipass S3 Authentication Software that include day-to-day operations, preventative maintenance and updates. Find recommendations for these aspects that ensure security and high performance in your deployment in Best Practices for Operation.

The recommendations presented here include key aspects to consider prior to planning a deployment. These include general recommendations for storage, security, server failover, increased availability, and other guidance specific to Digipass S3 Authentication Software. These pre-implementation recommendations are further categorized as follows:

  1. Designing Your Deployment

    1. Database Setup

    2. Data Storage Planning

    3. Database Replication

    4. Authentication Server Cluster

    5. Admin Server

    6. Command-line Tools

    7. Load Balancing

    8. Disaster Recovery

  1. Before Installation

    1. Secure Tomcat

    2. Limit the size of POST requests to Digipass S3 Servers

    3. Configure your network to only allow traffic that is needed

    4. Securing Communication Between Components

    5. Enabling Supported Algorithms in TLS

    6. Securing Credentials

    7. Specifying the database's character encoding

  2. After Installation

    1. Allowed Authenticators

    2. Allowed Apps

    3. Securing Session and Transaction Management

    4. Unused Plugins

    5. Personally Identifiable Information (PII)

Details on these best practices follow. They have been summarized into checklists that you can find in Deployment Checklists.