Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Deployment Checklist

Prev Next

Complete?

Recommendation

Specify UTF-8 character encoding while creating the database(s).

Compute your minimum data storage requirements for your databases using the following formulas:

Operational DB:

Minimum data storage = 2 * OpDataSize or
2 * (NumYears *
365) * (5.5KB * AvgDailyReg)

Set up an Operational Database for each Digipass S3 Server cluster. Set up replication for the database(s).

Use active-standby database replication since it simplifies the database replication requirements and production upgrade tests.

Add enough Authentication Servers to a cluster or site to handle the highest peak load with some additional capacity. Use the following formula to calculate.

Number of Authentication Servers in a cluster =

(peak authentication load/ server authentication processing rate) + 1

Number of API Servers = Number of Authentication Servers

If you have a large number of FIDO Policies and Adaptive Rulesets in your deployment, set cache configuration properties to ensure optimal memory usage and performance. Use the highest settings that work for your deployment to minimize early eviction of policies and rulesets.

Deploy at least two Administration Servers.

Dedicate one node for command-line tools in your deployment.

Use an API gateway between incoming traffic and the load balancer to the API Servers nodes.

Place a load balancer between the API gateway and the API Server nodes, unless the API gateway also serves as a load balancer.

Place an internal load balancer between the API Server nodes and the Authentication Server nodes.

Place another internal load balancer in front of the Admin Server nodes.

Place a failover router between the Authentication Server nodes and the replicated Operational Database.

Have a second site in case your first site fails.

Run the Admin Server only in the active site.

Start the standby Admin Server in case of failover from active to standby.

Replicate your site in a different geographical region.

If you don’t want to manage database replication between sites, use a cloud-managed database service.

Lock down your deployment so that your firewall only allows necessary inbound and outbound traffic.

If your company requires TLS among routers, servers, and proxies, you can implement a TLS connection between Digipass S3 Server-side components.

Enable TLS 1.2 and higher with all algorithms required by iOS ATS on the API Server server.

Encrypt database passwords using your own custom key.

Specify UTF-8 character encoding when you create the database so that Unicode characters can be stored.

Where possible, ensure that traffic to the API Server comes from your applications and is not directly open to the Internet.

Identify authentication scenarios that your customers require. Create Adaptive Rules and FIDO policies based on those scenarios.

Identify the smallest set of UAF authenticators to support. Remove authenticators you won’t support from your authenticator groups.

Add the applications you are deploying to the Configuration > Apps page in the Admin Console. Remove any sample or test applications.

If any of your apps use a remote UAF FIDO client, then delete unnecessary apps from facets.uaf and add the apps you are implementing.

If possible, use an asymmetric algorithm, which is more secure, to sign/encrypt your JWT.

Generate a new JWT key when you create a new tenant.

Where possible, ensure a valid session is in place for registration, deregistration, and list registration APIs. This is because these are protected resources.

Remove configurations for the API Server Transaction plugin if your deployment doesn’t support transactions.