Introduction
When you create a tenant, you must also configure it. The majority of that configuration involves the Digipass S3 API Server and its plugins. Configuration information for these components is contained in a JSON that is stored in the Auth Server's database. Use either the Admin Console or the Command Line Interface's nnl-mgmt.sh apiserver command to add or modify these configuration objects.
The API Server has its own configuration object called Main. Most of the API Server plugins also have their own dedicated configuration objects. The two utility apps supplied by Digipass S3 Authentication Software share a configuration object. In addition, Digipass S3 supplies a Default JWT Config object. This page describes the configuration objects for the following plugins and components:
Main for the API Server
In addition, each type of configuration object has its own Main object that tells which plugins of that type are enabled, what are the names of any custom plugins of that type, and other information relevant to that type of configuration object.
The table below tells, for each API Server plugin or component, the type and name of its configuration object together with the circumstances when it is used. One configuration object configures the features for one tenant, so the table below describes the configuration objects for one tenant. Note that there are also plugins without configuration objects and they are not included in the table.
Feature | Config Object Type | Config Object Name | When it is used |
|---|---|---|---|
Main | Main | Always | |
Main | jwt_config | Used by any plugin that uses jwt_config and doesn't have a local config object. | |
Main | nnlapp_config | Used to configure the two utility apps, nnlfedapp and nnlsignin. | |
SessionPlugin | Main | Always. Used to activate and deactivate one or more Session plugins. Also contains configuration properties applicable to all session plugins | |
SessionPlugin | jwt_config | Always | |
SessionPlugin | ua_parser | You implemented web apps that use WebAuthn. Used to identify the client platform or browser. | |
SessionPlugin | jws_config | You want EMV 3DS data returned after successful FIDO registration, authentication, and transaction confirmation. You created one or more Adaptive Rules that return an EMV 3DS FIDO blob. | |
SessionPlugin | ip_address_plugin | You created one or more Adaptive Rules that use client IP address in their condition. | |
SessionPlugin | credsim_config | You implemented a native or web app that uses FIDO2, and your app needs to pass a username for an authentication operation. Use this plugin only if you don't want the server to reveal information on whether the unauthenticated user has FIDO credentials or not. | |
PolicyPlugin | Main | Activate and deactivate the Policy plugin. | |
PolicyPlugin | default_config | Your app performs FIDO or OOB registration and doesn't pass the optionsData.policyName parameter. Use this plugin to resolve the policy name using default_config instead. | |
TransactionPlugin | Main | Used to activate and deactivate the Transaction plugin. | |
TransactionPlugin | jwt_config | Your App supports transaction confirmation. | |
ExternalAuthenticationPlugin | Main | Activate and deactivate a JWT or a Password External Authentication plugin. | |
ExternalAuthenticationPlugin | jwt_config | You want users to authenticate with passwords or any other authentication method not supported by Digipass S3. | |
ExternalAuthenticationPlugin | pwd_plugin_config | You want your users to authenticate with passwords. | |
ExternalIdentityProvider | Main | Activate or deactivate one or more OIDC-enabled external identity providers. | |
ExternalIdentityProvider | <External IdP registration ID> | Your External IdP is an OIDC server that authenticates the user and obtains the required session for FIDO registration. |