Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Delete registrations

Prev Next

Introduction

During normal operation, some number of inactive registrations accumulate. An inactive registration might exist because

  • A user created a registration, but then deleted the app

  • A user created a registration, but didn’t use it

  • A user acquired a new device and created a new registration

For these and other cases, use the nnl-mgmt.sh command-line utility to identify all inactive registrations and disable them, then physically delete them from the database. Nok Nok recommends cleaning out inactive registrations once a quarter.

Specify the tenant and protocol family when you use the nnl-mgmt.sh authenticators command. See detailed documentation for the nnl-mgmt.sh authenticators command.

Before you use nnl-mgmt.sh, you must have assigned the password encryption key to the NNL_PKEY system environment variable. You should have done this in Step 4. Encrypt Credentials Used by the Server

Use cases

There are 2 common use cases for deleting registrations.

Use case 1

Disable and delete registrations that haven’t been used for a specific period of time, such as a year.

The example below disables inactive UAF registrations that haven’t been used for a year in the finance tenant, in batches of size 100. After disabling UAF registrations, delete them. Only disabled registration can be deleted.

./nnl-mgmt.sh authenticators disable -inactivity 365 -tenantid finance -batchsize 100
        ./nnl-mgmt.sh authenticators purge -tenantid finance -batchsize 100

The example below disables inactive FIDO2 registrations that haven’t been used for 180 days in the default tenant, in batches of size 100. After disabling FIDO2 registrations, delete them. Only disabled registrations can be deleted.

./nnl-mgmt.sh authenticators disable -inactivity 180 -pf fido2 ‑tenantid default -batchsize 100
        ./nnl-mgmt.sh authenticators purge -tenantid default -batchsize 100

The example below disables inactive non-FIDO registrations that haven’t been used for a year in the finance tenant, in batches of size 100. After disabling non-FIDO registrations, delete them.

./nnl-mgmt.sh authenticators disable -inactivity 365 -pf other
        -tenantid finance -batchsize 100
        ./nnl-mgmt.sh authenticators purge -tenantid finance -batchsize 100

Use case 2

Enforce an upper limit of registrations for every end user. For example, your company may want to only store 8 registrations per user. In this situation, you want to keep the 8 most recently used registrations, and disable and delete the remaining registrations.

The example below disables UAF registrations other than the 10 most recently used for every user in the finance tenant. After disabling UAF registrations, delete them.

./nnl-mgmt.sh authenticators disable -retain-most-recently-used 10 ‑tenantid finance -batchsize 100
        ./nnl-mgmt.sh authenticators purge -tenantid finance -batchsize 100

The example below disables FIDO2 registrations other than the 6 most recently used for every user in the default tenant. After disabling FIDO2 registrations, delete them.

./nnl-mgmt.sh authenticators disable -pf fido2 ‑retain‑most‑recently‑used 6
        ./nnl-mgmt.sh authenticators purge -batchsize 100