Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Operations Checklist

Prev Next

Completed?

Recommendation

Use the Digipass S3 health check endpoints as frequently as you need to monitor trouble spots.

If your company policy requires rotation of encryption keys, you can schedule creating a new encryption key to replace one in current use.

Use a diagnostic log level of ERROR during production.

Select an appropriate logging level for your needs that balances the amount of information captured with the troubleshooting you have to do

If you don’t have regulatory requirements, turn off audit logging to reduce I/O and disk storage requirements.

Move older audit logs to archival storage to control disk usage by audit logs.

Purge inactive registrations once a quarter. To minimize impact on system performance, schedule this purge operation at a time when you expect a low usage.

Fetch authenticator metadata periodically. Fetch the metadata statements by the date of the next update listed in the report.

Review the report generated by the metadata fetch script.

  • Determine new authenticators you want your end-users to use. Import the metadata for those authenticators and update your FIDO policies.

  • Identify authenticators you want to discontinue due to security compromises. Update your FIDO policies to remove these authenticators. In addition, disable the metadata for those authenticators.

Monitor the following:

  • CPU utilization

  • Memory usage

  • Disk utilization

  • Server health using health check endpoints of the Digipass S3-server components

  • Load balancer pool distribution statistics

  • Total number of registration and authentication attempts and failures

  • Digipass S3's transient data purge

  • cron jobs

Ideally, have autoscaling in place to automatically increase resources when load or utilization increases.

If your monitoring tools examine data over time, balance the cost to retrieve and store that data versus how much data to collect, how frequently to collect that data, and how long to store the data.

Upgrade Digipass S3 products in the following order: database schema upgrades, Authentication Server upgrades, and API Server upgrades.

When updating Servers, initially update only one site and stop database replication traffic until the update is tested successfully. Once the first site is successfully updated, update the second site and re-enable database replication between sites.

In order to detect slow responses to REST API calls, configure the elapsed time threshold system property nnl.api.elapsed.time.threshold.millis. If the response time to a REST API operation request is longer than this property's value (default: 3000 milliseconds), the Server logs a warning in the Diagnostic nnl.log file.