Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Configure a UAF authentication method

Prev Next

To configure Digipass S3 to support UAF, you need to assign the App ID using the instructions below. In addition, you need to create a FIDO policy to enforce your organization’s choice of UAF authenticators.

Assigning the App ID

The App ID is the URL of facets.uaf, the file that contains your organization's list of trusted facet IDs. A facet ID uniquely identifies a platform-specific version of an application that your organization implements which uses the S3 Authentication Suite. If you have an iOS, Android, and web version of your app, each of these has a unique facet ID.

When you install the Auth Server, facets.uaf is automatically created for the default tenant at <domain>/facets/facets.uaf. You should host facets.uaf on a publicly accessible server. See Sample facets.uaf File for instructions on how to modify this file. An example App ID is shown below:

https://www.example.com/facets/facets.uaf

The App ID plays an important part in user registrations. When private and public keys are created as part of the user registration process, Digipass S3 Authentication Software associates the App ID with those keys. Consequently, avoid changing the AppID because it invalidates existing registrations. Do not leave the App ID blank.

Technically, only a remote FIDO client needs facets.uaf to validate which applications it can communicate with. You may reason that since you're using an embedded FIDO client you don't need to set App ID to the URL for facets.uaf. This prevents you from supporting credential sharing between apps in the future. Consequently, OneSpan strongly recommends that you assign the URL to facets.uaf as the App ID, even if your apps don't need to use facets.uaf.

Add the App ID

Using the Admin Console

  1. Login and, if needed, switch to the desired tenant. Navigate to the UAF properties, Configuration > Authentication Methods > FIDO UAF.

  2. Click the value for App ID. Enter the URL for facets.uaf.

Using nnl-mgmt.sh

Modify the tenant property uaf.application.id to assign a value to App ID. Below is an example using nnl-mgmt.sh's set properties command to change this for the default tenant.

./nnl-mgmt.sh properties set -name uaf.application.id -value https://acme.com/facets/facets.uaf

For details about this command, see Set Property command.

Sample facets.uaf File

{
    "trustedFacets": [
        {
            "version": {
                "major": 1, 
                "minor": 0
            }, 
            "ids": [
                "ios:bundle-id:com.noknok.ios.tutorialappplus", 
                "ios:bundle-id:com.noknok.ios.NokNokPassport", 
                "android:apk-key-hash:lXHH7DSBcDnOS1RQ1Sd95KaitYA", 
                "android:apk-key-hash:SvYZ4Sgas9T2+6DpNj566iscuns", 
                "ios:bundle-id:com.noknok.ios.sampleapp", 
                "https://example.com:8443"
            ]
        }
    ]
}

To create your own facets.uaf, make a copy and update the contents of the ids field. The ids field contains the trusted facets IDs in a comma-separated list. The list should only contain facet IDs from your organization.