Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Platform Independent Issues

Prev Next

Review the following list of general troubleshooting steps prior to contacting Digipass S3 support:

  1. Review the Server and API Server logs and look for exceptions, errors, and failures.

  2. Check that the correct metadata for your ASM is present on the Server.

  3. Check that the AAID for your ASM is present in the Server policy.

  4. Check that you have connectivity to your Server and are able to browse to the facets.uaf file from your web browser.

  5. Clear any data that is cached by your app and any UAF client.

  6. Ensure that the session is communicating using HTTPS. The UAF protocol mandates TLS protected communication.

  7. Verify that your Server has a valid certificate and that your device trusts the Server certificate.

  8. Verify that your app is correctly installed and opens successfully.

  9. Verify your network connectivity.

  10. Verify that the Server FIDO policy accepts the authentication methods installed on the device.

  11. If there are issues with user authentication, check the Authentication Server's diagnostic logs in <TOMCAT_HOME>/logs/nnl.log.

  12. When testing using Tutorial App, verify that the server URL is configured correctly. Follow the instructions to configure the Tutorial App for Android or iOS or Web.

Tutorial App Does Not Work, User is Unable to Login

Problem

Tutorial App does not work; the user is unable to login.

Description

To use Tutorial App, Tutorial Web App should be deployed. Tutorial Web App is the login servlet, so make sure that it is deployed without any errors.

On the mobile devices, Tutorial App may display the error message:

Login Failed

Steps

Verify that you are using "noknok" as the password for the Tutorial App.

Check the following:

  1. Configure Tutorial App to use your server. Follow the instructions to configure the Tutorial App for  Android or iOS or Web.

  2. Verify that the Server URL for Tutorial Web App is correct. For example, here are the default values:

    https://evaluation94.noknoktest.com:8443/gwtutorial/configure

    The page displays the configured URLs. Verify the value for "login_url". You can directly edit the contents and save.

  3. Using the Admin Console:

    1. Choose Configuration>Authentication Methods>Other Methods. Confirm that Password-based External Auth is in the list.

    2. Choose Authentication>Adaptive Rulesets to confirm that the External Auth method is in the active ruleset.

    3. Click on Configuration>API Server>JWT Authentication Method and examine jwt_config.json to make sure that audiences and issuer are configured correctly:

  4. When using the LastPass browser extension for passkeys, ensure that the application runs on Tomcat’s default port. The extension does not operate correctly when Tomcat is configured with a non-default port, and passkey functionality may fail in that setup.

Client Error: NO_MATCH

Problem

Your client app displays the following error message from the Authentication Server:

Client Error: NO_MATCH

Description

This error is the result of an unsuccessful registration or authentication attempt. The NO_MATCH response indicates one of:

  • The Client has no registered authenticators with the Server that can be used for authentication.

  • The Client has registered all available authenticators with the Server so no other authenticator can be registered.

Steps

To avoid displaying this message to the user, your code should perform a check FIDO policy operation prior to performing a FIDO operation. Use the checkRegPossible(), checkAuthPossible(), and checkTransPossible() methods to perform a check policy for registration, authentication, and transaction confirmation, respectively.

If check policy fails, it indicates that subsequent FIDO operations will also fail. Your code can modify the UI to prevent the user from triggering the NO_MATCH message.

See Registering and Sign-in sections in the Developer Guide for iOS, Android, and Web. Also see the source code for the Tutorial App for examples of how to use the checkRegPossible(), checkAuthPossible(), and checkTransPossible() methods.