One critical part of your FIDO2 configuration is specifying an RP ID for your organization and a facet ID for each of your web and mobile apps. The RP ID is the domain for your organization.
The FIDO2 protocol requires that the RP ID and facet IDs must satisfy specific requirements. If you are not familiar with these requirements, please read section FIDO2: RP IDs and Facet IDs. Otherwise, assign your domain to the RP ID, then move on to Authenticating with the User Name or Alternate Step: Configuring Your Proxy (if you implemented your own proxy to replace the API Server).
The RP ID plays an important part in user registrations. When private and public keys are created as part of the user registration process, Digipass S3 Authentication Software associates the RP ID with those keys. Consequently, avoid changing the RP ID because it invalidates existing registrations.
Assign the RP ID
You can use either the Admin Console or nnl-mgmt.sh to assign a value to the RP ID.
Using the Admin Console
Login and, if needed, switch to the desired tenant. Navigate to the FIDO2 properties, Configuration > Authentication Methods > FIDO2/WebAuthn.
Click the value for RP ID. Enter your domain and save.
Using nnl-mgmt.sh
Modify the tenant property webauthn.application.id to assign a value to RP ID. Below is an example using nnl-mgmt.sh's set properties command to update the default tenant's webauthn.application.id property to example.com.
./nnl-mgmt.sh properties set -name webauthn.application.id -value example.comFor details about this command, see Set Property.