Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

FIDO policies

Prev Next

You can easily export one or more FIDO Policies, along with their dependencies. This enables you to freely experiment with different variations of a policy in your development environment as well as copying a tested and curated policy to your production environment. Dependencies for a FIDO policy include authenticator groups and authenticator metadata.

Exporting

Using the Admin Console

  1. Login to the Admin Console and, if needed, switch to the tenant whose FIDO Policy you want to export.

  2. Navigate to Authentication > FIDO Policies.

    • To export all active FIDO policies, click Export Active.

    • To export a specific policy, either in an active or draft status, locate the policy in the table and, in the same row, click the download icon in the Actions column.

  3. The Export Policy dialog appears.

To include all the authenticator groups that a policy uses, select the With dependencies checkbox.

You can optionally select the Include metadata checkbox to export authenticator metadata that is referenced by the policy. This option is only valid if you checked With dependencies. Use this option in limited situations, such as when you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 installation. Normally, you should use the instructions in Update Authenticator Metadata to import metadata.

  1. Click Export.

    • If you are exporting one or more policies without dependencies or authenticator metadata, the Admin Console saves the policies in a JSON file.

    • If you are exporting policies with their dependencies (and metadata), the Admin Console saves all the objects in a ZIP file.

Using nnl-mgmt.sh

Use the nnl-mgmt.sh policy export command. The following example exports the test1 FIDO policy from the finance tenant into test_directory. The resulting file is a JSON file.

./nnl-mgmt.sh policy export -name test1 -dir test_directory -tenantid finance

For details on the nnl-mgmt.sh policy export command, see FIDO Policy Commands in the reference to Command Line Interface. There are additional parameters to this command to export authenticator groups and authenticator metadata.

Importing

Using the Admin Console

  1. Login to the Admin Console and, if needed, switch to the tenant where you want to import the FIDO Policy.

  2. Navigate to Authentication > FIDO Policies. To import from a policy file, click Import.

  3. The Import Policies dialog appears.

To select the policy file for import, click Choose File and navigate to the file’s location. If the file is larger than 512 KB, you need to use ./nnl-mgmt.sh to change the default maximum size. See Note below.

If the policy file is a ZIP file, you can optionally use the checkboxes in this dialog.

To overwrite policies and dependent objects with the same name, select the Overwrite any existing policy with the same name checkbox. Overwrite handles objects differently depending on their type and status, as shown in the table below.

Object

Status of Existing Object

Result

FIDO Policy

draft

The system overwrites the existing FIDO policy with the one from the file and maintains its status as draft.

active

The system overwrites the existing FIDO policy with the one from the file and changes its status to active.

Authenticator Groups

N/A

The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy.

You can optionally select the Import and overwrite metadata checkbox to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 Suite installation and overwriting metadata could have unintended consequences. Normally, you should use the instructions in Update Authenticator Metadata to import metadata.

Change the default maximum policy size by using nnl-mgmt.sh to update the nnl.policies.file.size.kb property for the Admin tenant, as shown below.

Changing the maximum size of the ruleset file to 1024 KB:

./nnl-mgmt.sh properties set -name nnl.policies.file.size.kb -value 1024 -tenantid Admin

Using nnl-mgmt.sh

Use the nnl-mgmt.sh policy import command. The example below imports the FIDO policies and their dependent objects into the tenant with ID NorthAmerica.

./nnl-mgmt.sh policy import -file EuropePolicies.zip -tenantid NorthAmerica -overwrite yes

For details on nnl-mgmt.sh's policy import command, see FIDO Policy Commands in the reference to Command Line Interface. There are additional parameters to this command to import authenticator metadata.