Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Use a specific crypto provider

Prev Next

You can configure the API Server to use a specific crypto provider for all cryptographic operations. The API Server property nnl.jce.provider specifies the security provider that you want the API Server to use.

  1. Place the appropriate jars for your chosen crypto provider into the tomcat/webapps/nnlgateway/WEB-INF/lib/ directory. For example, bc-fips-x.x.x.jar and bcpkix-fips-x.x.x.jar in case of Bouncy Castle FIPS.

  2. When you initiate Tomcat, specify the crypto provider that the API Server uses for all cryptographic operations by setting the nnl.jce.provider Java system property. For example, if you are using Bouncy Castle FIPS:

CATALINA_OPTS=-Dnnl.jce.provider=org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider

If you are using Bouncy Castle FIPS in particular, you can force it to work in FIPS-approved mode by also setting the following Java system property:

CATALINA_OPTS=-Dorg.bouncycastle.fips.approved_only=true
  1. Specify the cryptographic algorithm and key in jwt_config.