Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Customize an imported tenant

Prev Next

This section contains the customizations required for a target tenant that has just been imported from a source tenant.

Step 1: Create Admin users

Create new Admins who can configure the target tenant or add existing Admins to the target tenant. See Admin user management.

Step 2: Change occurrences of tenant ID

If the new target tenant ID is different from the source tenant ID, then you may need to update the RP Display Name by navigating to Configuration > Authentication Methods > FIDO2/WebAuthn in the Admin Console.

Step 3. Update the API Server configurations

For security reasons, the configuration object for a JWT (jwt_config) must be unique for each tenant in a deployment. Otherwise, the resulting sessions may be vulnerable to attacks.

The API Server can potentially use a JWT or JWS configuration object in 5 places:

  • The default JWT Config

  • JWT Processor (for the Session plugin)

  • EMV 3DS Generator – Uses jws_config for configuration instead of jwt_config. These 2 objects are very similar. However, jws_config only contains a generate object because it only needs to create a JWT containing EMV 3DS data.

  • JWT Transaction Processor

  • JWT Authentication Method (for External Authentication)

What you do next depends on if you want to use the default settings or use custom settings for the above objects.

Case 1: You want default settings for API Server configurations

A newly created tenant has no default JWT Config or plugin-specific JWT configurations. Identify the API Server plugins and objects that you plan to use, then generate new jwt_configs. If necessary, you can reset the configurations for the Policy Selector, IP Address Extractor, and User Agent Parser plugins using the Admin Console.

Using the Admin Console

  1. Login and, if needed, switch to the target tenant. Navigate to Configuration > API Server > Authentication API.

  2. Generate a new jwt_config for each plugin or object that uses a jwt_config.

    • Main (The API Server's default JWT Config)

      Expand the Main panel. Find the Default JWT Config label and click its Generate button. Confirm that you want to generate a new configuration object. To view the configuration, click the Default JWT Config label.

    • Session Plugin (JWT Processor plugin's jwt_config)

      Expand the Session Plugins panel. Find the JWT Processor label and click its Edit icon. On the plugin’s configuration page click the Generate button. Confirm that you want to generate a new configuration object. The page will display the newly generated configuration. To activate the plugin, go back to the plugin list and click the JWT Processor’s Activate icon.

  • Transaction plugin (JWT Transaction Processor's jwt_config)

    Expand the Transaction Plugin panel. Find the JWT Transaction Processor label and click its Edit icon. On the plugin’s configuration page click the Generate button. Confirm that you want to generate a new configuration object. The page will display the newly generated configuration. To activate the plugin, go back to the plugin list and click the JWT Transaction  Processor’s Activate icon.

  • External Authentication plugin (JWT Authentication Method's jwt_config)

    Expand the External Authentications Plugins panel. Find the JWT Authentication Method label and click its Edit icon. On the plugin’s configuration page click the Generate button. Confirm that you want to generate a new configuration object. The page will display the newly generated configuration. To activate the plugin, go back to the plugin list and click the JWT Authentication Method’s Activate icon.

  1. Generate a new jws_config for the EMV 3DS Generator plugin. Expand the Session Plugins panel. Find the EMV 3DS Generator label and click its Edit icon. On the plugin’s configuration page click the Generate button. Confirm that you want to generate a new configuration object. The page will display the newly generated configuration. To activate the plugin, go back to the plugin list and click the EMV 3DS Generator’s Activate icon.

  2. Reset the Policy Selector plugin's configuration setting to its default value, see Configure a FIDO policy for non-adaptive registration. You can optionally do this for the IP Address Extractor and User Agent Parser plugins. Refer to IP Address Extractor Plugin.

Using nnl-mgmt.sh

Use the nnl-mgmt.sh apiserver create command to generate new JWT configuration objects. For details on apiserver create command, see reference API Server Configuration Commands.

  1. Generate jwt_config for all the objects and plugins that need one.

  • Main (The API Server's default JWT Config)

./nnl-mgmt.sh apiserver create -tenantid newtenant -type Main -name jwt_config -issuer "https://myAPIServer.com"
  • Session Plugin (JWT Processor plugin's jwt_config)

./nnl-mgmt.sh apiserver create -tenantid newtenant -type SessionPlugin -name jwt_config -issuer "https://myAPIServer.com"
  • Transaction Plugin (JWT Transaction Processor's jwt_config)

./nnl-mgmt.sh apiserver create -tenantid newtenant -type TransactionPlugin ‑name jwt_config ‑issuer "https://myAPIServer.com"
  • External Authentication plugin (JWT Authentication Method's jwt_config)

./nnl-mgmt.sh apiserver create -tenantid newtenant -type ExternalAuthenticationPlugin -name jwt_config -issuer "https://myAPIServer.com"
  1. Generate a new jws_config for the EMV 3DS plugin

./nnl-mgmt.sh apiserver create -tenantid newtenant -type SessionPlugin -name jws_config

Case 2: You want custom settings for API Server configurations

If your company modified a plugin's JWT configuration object, you want to preserve those changes. A few examples of customizations in a jwt_config include:

  • Different algorithm than HS256

  • Different RP servers as issuers

  • Rotating keys

  • Different token lifetime

  • Storing keys in an external secrets store

At a minimum, you need to generate new keys outside of Digipass S3 Software, and update all the jwt_config objects to use a different key or keys for the algorithms. This is true even if you are only moving a tenant from a development deployment to a production deployment.

If you have a backup copy of your API server configurations that you exported previously, you can use that to help you make these changes.

Refer to Updating the algorithm and key as well as Managing keys for a JWT. If your IAM Server has changed, you need to update the issuers array. If you decide to make further changes, refer to When to modify a JWT configuration object.

For each JWT configuration object that you need to customize:

  1. Using the Admin console, navigate to Configuration>API Server and click the Modify button next to the plugin.

  2. If there is a configuration present, select and copy the configuration. Otherwise, use a backup of the configuration to modify.

  3. Open a text editor and paste the configuration. Make your modifications there and save.

  4. Back in the Admin Console, click Import and choose your modified file. Click Submit.

Step 4: Optional. Copy objects from other tenants

You now have your target tenant but maybe you want to use the FIDO policy and/or an Adaptive Ruleset from source tenant A and some of the data lists from source tenant B. Fortunately, you can export any objects from the other tenants and import them into your target tenant to streamline tenant configuration. These objects include:

  • Authenticator groups

  • Lists of

    • countries

    • device models

    • geofences

    • IP addresses

    • WiFi networks

  • Active Adaptive Rulesets and their rules

  • Active FIDO policies

You can use either the Admin Console or nnl-mgmt.sh to export and import objects. Imported FIDO policies and Adaptive Rulesets have a draft status, so you need to activate them before you can use them. See Export and Import Configurations.

Step 5. Review this tenant's configuration

You may want to update the configuration for some of the API Server plugins. Use the checklist below for common updates to make. For more details about configuration for each API Server plugin, refer to API Server Configuration Objects.

  1. Review the API Server's main configuration. See Main to understand this configuration.

    1. It's likely that the target tenant has different apps than the source tenant. Remove any allowed apps from origin_allowlist.

    2. The API Server limits the data sent from the Auth Server back to the App SDK based on the response filter configuration in mfas_response_filter. Compare what's in mfas_response_filter to the default value. If the value is different, determine if this is the data that you want allowed through the response filter.

  2. Use the instructions in Configure a FIDO policy to review the default FIDO policy that is used for non-adaptive registration. If the FIDO policy name listed there isn’t what you plan to use or doesn't exist, then update it now. Refer to default_config to understand the Policy plugin's configuration.

  3. Session Plugin - MainReview the Session plugin's configuration. Refer to Session Plugin - Main to understand this object's configuration.

    1. If you aren't using Android apps that use FIDO2 or web apps that use WebAuthn, then delete com.noknok.gateway.plugin.session.CredentialSimulator from this file.

    2. If you don't need EMV 3DS data returned from registration, authentication, or transaction confirmation or from an Adaptive Rule, then delete com.noknok.gateway.plugin.session.Emv3dsSessionPlugin.

    3. If you don't have Adaptive Rules that use IP address in their condition, then delete com.noknok.gateway.plugin.session.IPAddressPlugin.

  4. If you aren't using S3 for transaction confirmation, then delete TransactionPlugin/Main.json. Refer to Transaction Plugin.