Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Server Release Notes for v9.4

Prev Next

January 14, 2026

Server BOM: 9.4.0-139

Auth Server Version: 9.4.0-171

API Server Version: 9.4.0.17

UM Build Version: 9.4.0.11

Web App SDK version: 9.4.0.33

New features

  • Inline registration allows end users to be prompted to register and authenticate if they have no FIDO credential registered yet. When inline registration is enabled and the end user only has a password, the system automatically prompts the end user to register a second-factor authentication method. Inline registration supported only FIDO authentication methods in v9.3, it now also supports non-FIDO methods like Email OTP and SMS OTP. Enable inline registration from the Admin Console by navigating to Configuration>API Server>Session Plugins.

  • Custom API Server Plugins can now have multiple configuration objects, making configuration more convenient and flexible. For example, your custom plugin can have one configuration object that defines custom settings, and another configuration object that defines JWT generation options.

  • You can purchase Digipass security keys from OneSpan and request that they be pre-provisioned for the end users of the S3 Authentication Server. After you import these credentials, your end users can sign in immediately, skipping the registration process.

  • A list of related domains can be configured for a single RP ID. As a result, end users can use a single credential for all of your organization's domains.

  • Server FIDO policies now enable explicit control over the authenticator UI selection by using Public Key Credential Hints (security key, passkey on this device, and passkey on a different device). This replaces the less specific use of Authenticator Attachment and enables more precise control over the end users' registration and authentication experience. When a policy is in effect that has this feature enabled, the returned message size for a registration or authentication operation is increased by approximately 70 bytes.

  • Enable "Conditional-create" in a Server FIDO policy. This allows end users to sign up and create a passkey in one step. In v9.4 this feature can be enabled or disabled from the Server without modifying the application code. When a policy is in effect that has this feature enabled, the returned message size for a registration operation is increased by approximately 160 bytes.

  • Receive authenticator metadata details from the Server after a successful registration or authentication. Additional information about authenticator security characteristics allows the customer to categorize the security strength of the authenticator.

  • You can add a dynamic claim to an adaptive authentication rule. Previously, you could add a static claim with a hardcoded value to the JWT that results from an authentication. Now you can also add a dynamic claim whose value is determined at runtime. For example, you can easily convey to your application whether the end user was authenticated with a password, an OTP, or a passkey.

  • An Admin user can add another Admin user to a different tenant, provided they have user management permissions in both tenants. Previously only Super Admins could add an Admin user to a tenant.

  • When you export a tenant's configuration, the private key is obscured to improve security. When you import that tenant's configuration with an obscured private key back into the Server, the original key value in the database remains unchanged, while all other configuration parameters are updated.

  • Quick Authentication supports the WebAuthn conditional UI.

  • A Registration Rule is now called a Registration Decision Rule in the Admin Console. A PostOperation check to be performed after a sequence of registration decision rules is now called a Supplemental Check.  

  • CockroachDB queries are optimized. During Quick Authentication, cross-region read queries are converted to local region stale-reads. In addition, fewer queries are required for all FIDO authentications.

  • A web app can confirm a transaction using a FIDO Digipass security key that contains a display. The S3 Suite continues to support UAF transaction confirmation using any FIDO2 authenticator.

Customer issues fixed

  • When an end user attempted to delete registrations from different applications concurrently, they sometimes received a null pointer exception.

    Previous Behavior: When an end user attempted to delete registrations from different applications concurrently, they sometimes received a null pointer exception.

    New Behavior: An end user can successfully delete registrations from different applications concurrently.

  • The Server logs the warning "nnl.quick.auth.key.length is not configured" even when the property's value is configured correctly.

    Previous Behavior: The Server logs the warning "nnl.quick.auth.key.length is not configured" even when the property's value is configured correctly.

    New Behavior: When nnl.quick.auth.key.length is configured correctly, the Server does not log a warning saying that the property is not configured.

  • Third party libraries were updated to address the following vulnerabilities:  

    • CVE-2025-7962

    • CVE-2025-58057

    • CVE-2025-58056

    • CVE-2025-55163

    • CVE-2025-12383

  • Customer cannot send push notifications to Android devices via an authenticated proxy server.

    Previous Behavior: Customer cannot send push notifications to Android devices via an authenticated proxy server

    New Behavior: Customer can send push notifications to Android devices via an authenticated proxy server

Installation requirements

  • The package name for the Server is nns3_server_package_9.4.0-139.tgz

Supported operating systems

  • Red Hat Enterprise Linux (RHEL) 9 and 10

  • Rocky Linux 9 and 10

  • Amazon Linux 2023

Supported database servers and versions

  • PostgreSQL 15, 16, 17

    • A PostgreSQL JDBC driver is included in the Server package.

    • PostgreSQL 15 and later does not allow the creation of tables in the public schema by default, so constrain ordinary users to user-private schemas. Set up a default schema search path for the DB user with:  

      CREATE SCHEMA <user-schema> AUTHORIZATION <user>  

    See PostgreSQL documentation for further details.

  • Oracle Database 21c Enterprise, and 23c

    • For best results use the latest available JDBC driver.

  • MySQL Server 8.4.x

    • For best results use the latest available JDBC driver.

  • CockroachDB v23.2.x, v25.2.x

  • AWS Aurora/MySQL 8.0.x

  • AWS Aurora/PostgreSQL 17.6

Supported application servers and versions

  • Apache Tomcat 10.1 and later versions. To configure Tomcat, root or sudo privileges may be required.

Other prerequisites

  • Java Developers Kit (JDK)

    • Oracle JDK 21 and 25

    • RedHat OpenJDK 17, 21 and 25

    • Eclipse Temurin JDK 17, 21 and 25

  • Optional when using Identity Proofing and Account Recovery:

    • Email OTP-based recovery requires an email server supporting SMTP.

    • SMS OTP-based recovery requires a Twilio account with an active ‘From’ number enabled for SMS support.

    • Photo ID-based recovery requires a Jumio Netverify account with address and face-match features enabled.