The Federated credential management page allows an end user to register a new authenticator and manage existing registrations. This page is available to any user with a valid JSON Web Token (JWT). You can obtain the ID token, which is a JWT, from any external OIDC-compliant identity provider (IdP).
To make use of the credential management page included in nnlfedapp, follow these steps:
To deploy these utility apps during Server installation, set the installation property DEPLOY_OPTIONAL_WEB_APP_LIST in the nnl-install.properties file. See Install on Linux section List Optional Web Applications for more information.
Step 1. You have 2 options, depending on where you would like to deploy nnlfedapp:
Option a. To deploy nnlfedapp with the S3 Suite during Server installation, set the installation property DEPLOY_OPTIONAL_WEB_APP_LIST in the nnl-install.properties file. See Install on Linux section List Optional Web Applications for more information.
Option b. To deploy nnlfedapp on a Tomcat server of your choice, extract nnlfedapp.war from the Nok Nok Web App SDK package into the webapps directory of your chosen application server.
Step 2. Add nnlfedapp as an OIDC client in your Identity Provider Configuration. See table of External Identity Provider Configuration fields for details including clientId, clientSecret and other important configuration parameters.
Step 3. Examine your external IdP server to find the OIDC endpoints. You need one of the following:
authorizationEndPoint, tokenEndpoint and userInfoEndPoint
the OpenID discovery endpoint, which is the issuerUri provided by your external identity provider
Step 4. Create a configuration JSON file for your external identity provider. See External Identity Provider Configuration for details.
Step 5. Log into the Nok Nok Admin Console and go to Configuration > API Server.

In the Federated Identity Management panel, expand the External Identity Providers panel. Click Add OIDC Provider to upload the configuration file you created in Step 4. Click Choose File, click Submit, and then click Activate on the right.

Step 6. In your web browser, navigate to the following URL to access the Federation Credential Management page.
https://<host>/nnlfedapp/req.jsp?reg_id=<registrationId>&tenant_id=<tenant_id>