Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Configure a Password External Authentication Method

Prev Next

When an end user needs to verify their identity with a Password External Authentication Method, one of your company servers, not the Nok Nok Authentication Server, authenticates the end user. This section refers to this company server as the RP Server.

How a Password External Authentication Method Works

Let's assume that you have implemented user ID and password as a Password External Authentication Method. Figure 7b illustrates how the S3 Suite interacts with your RP Server when an end user wants to authenticate.

Figure 7b S3 Suite Interaction with RP Server during Password External Authentication

  1. Using your client app, the end user decides to login with their ID and password.

  2. Your client app interacts with the Nok Nok App SDK to send the ID and password to the Nok Nok API Server.

  3. The Nok Nok API Server uses the Password External Authentication plugin to interact with the RP Server.

  4. The RP Server authenticates the user and returns success to the Nok Nok API Server.

  5. The Nok Nok API Server sends a request to the Nok Nok Auth Server for a response.

  6. The Nok Nok Auth Server creates a response intended for the App SDK and sends that to the API Server.

  7. The API Server sends the response to the App SDK.

Configuration Instructions

Implementing a Password External Authentication Method requires that you make changes to your client app, implement a REST API in your RP Server that verifies username and password, configure the Password External Authentication plugin to use that REST API, and configure the Password External Authentication method in the Auth Server so it can be used in an Adaptive Rule. This process is described in detail below.

  1. Identify the RP Server that will authenticate the username and password.

  2. Add support in your client app for the Password External Authentication Method by implementing specific classes. These classes in your client app display the UI if needed and send the username and password to the Password External Authentication plugin in the Nok Nok API Server. See Using an External Authentication Method in the Developer Guide for Android, iOS or Web.

  3. Implement a REST API in your RP Server to verify the username and password. The JSON payload for the password verification endpoint has the following attributes:

Request Attribute

Description

userName

Required. The username to verify.

password

Required. The password to verify.

apikey

Optional. API Key to authenticate the caller.

Response Attribute

Description

status

Required. The verification status. Must be either "SUCCESS" or "FAILURE".

message

Conditional. Must be present if the status is "FAILURE". The reason for the verification failure.

  1. Configure the Password External Authentication plugin to call the REST API in your RP Server to validate the username and password. See the Password External Authentication Plugin configuration for more details.

  2. Define the External Authentication Method in the Authentication Server. See Add a New Non-FIDO Authentication Method. The S3 Suite ships with an External Authentication method that you can use.

  3. To use an External Authentication Method during Adaptive Authentication, add the External Authentication Method to the sequence of a new or existing Adaptive Authentication rule. See Step 5D. Enter Sequences.

To use the method for Quick Authentication, modify how your client app performs registration and authentication. See Registering for Quick FIDO Authentication in the Developer Guide for Android, iOS or Web. Also see Implementing Quick Authentication in the Developer Guide for Android, iOS or Web.