Hot Fix 3
Aug 24, 2026
Server BOM: 9.5.0-145
Auth Server Version: 9.5.0-146
API Server Version: 9.5.0.24
UM Build Version: 9.5.0.27
Gateway Build Version: 9.5.0.24
Web App SDK Version: 9.5.0.125
Additional updates to server components
The following libraries were updated to address potential vulnerabilities:
bouncycastlenetty
Hot Fix 2
Jul 31, 2026
Server BOM: 9.5.0.143
Auth Server Version: 9.5.0-144
API Server Version: 9.5.0.20
UM Build Version: 9.5.0.24
Web App SDK Version: 9.5.0.122
Server components updated
The following libraries were updated to address potential vulnerabilities:
bouncycastle - bcprov and bcpkixhttpcorejackson-alllog4jnettypostgresql JDBC driver
Hot Fix 1
June 11, 2026
Server BOM: 9.5.0-129
Auth Server Version: 9.5.0-133
API Server Version: 9.5.0.15
UM Build Version: 9.5.0.20
Web App SDK Version: 9.5.0.46
Customer issue fixed
The MDS import tool has been updated to include smart-card attachmentHint support and improved error handling.
Previous behavior
FIDO metadata imports would fail for entries with a smart-card attachment hint.
Entries would be skipped, but the errors are not logged under Summary for web authenticator metadata.
New behavior
Entries with smart-card attachment hints are now imported successfully.
MDS import tool will now log errors for skipped metadata, including:
Total number of web authenticator metadata failed in the Summary for web authenticator metadata.
Affected files and any corresponding errors in the log file at <NNL_HOME>/admin/logs/nnl-mgmt.log.
Main release
April 30, 2026
Server BOM: 9.5.0-122
Auth Server Version: 9.5.0-126
API Server Version: 9.5.0.15
UM Build Version: 9.5.0.20
Web App SDK version: 9.5.0.46
Rebranding
The Nok Nok S3 Authentication Suite has been renamed to Digipass S3 Authentication Software, which includes the Digipass S3 Server and the Digipass S3 App SDKs. The Nok Nok Admin Console has been renamed to the Digipass S3 Admin Console. The Admin Console’s user interface has the same menu structure, but with a new look.
New features
A FIDO policy can include a Post Operation Rule that checks various signals in a user’s authenticator. The result of a Post Operation Rule can be deny, allow, or increment risk score. A FIDO policy can be configured to deny if the risk score exceeds a threshold. In Configure adaptive rulesets, see Step 3. Create FIDO policies.
Customers can download a checksum with their product package to independently verify the integrity of the software.
Authenticator metadata shipped with the product includes:
DIgipass FX2. This authenticator provides strong, phishing-resistant authentication and transaction signing.
Microsoft Password Manager.
The Server can detect if a passkey is available during adaptive registration.
Previous behavior: The Server can detect if a passkey is available during adaptive authentication.
New behavior: The Server can detect if a passkey is available during adaptive authentication or registration.
The API Server’s IP address extractor plugin generates client IP address extensions when VERIFY, INIT_ADAPTIVE and INIT_ADAPTIVE_REG, as well as non-adaptive REST API operations, are called.
Previous behavior: When the IP address extractor plugin was active, only the non-adaptive REST API operations added the IP address extension to the message that the API server sent to the Authentication server.
New behavior: When the IP address extractor plugin is active, both adaptive and non-adaptive REST API operations generate an IP address extension that the API server sends to the Authentication server.
Customer issues fixed
Third party libraries were updated to address the following vulnerabilities:
CVE-2025-7962
CVE-2025-67735
CVE-2025-68161
In the Admin Console, a user with Read Only permissions cannot view the configurations for API server plugins.
Previous behavior: In the Admin Console, a user with Read Only permissions chooses Configuration>API Server. The user can see a list of the API server plugins, but they cannot choose a plugin and view its configuration.
New behavior: In the Admin Console, a user with Read Only permissions chooses Configuration>API Server to view a list of the API server plugins. The user can then choose a plugin and view its configuration.
Installation requirements
The package name for the Server is nns3_server_package_9.5.0-122.tgz
Supported operating systems
Red Hat Enterprise Linux (RHEL) 9 and 10
Rocky Linux 9 and 10
Amazon Linux 2023
Supported database servers and versions
PostgreSQL 15, 16, 17
A PostgreSQL JDBC driver is included in the Server package.
PostgreSQL 15 and later does not allow the creation of tables in the public schema by default, so constrain ordinary users to user-private schemas. Set up a default schema search path for the DB user with:
CREATE SCHEMA <user-schema> AUTHORIZATION <user>
See PostgreSQL documentation for further details.
Oracle Database 21c Enterprise, and 23c
For best results use the latest available JDBC driver.
MySQL Server 8.4.x
For best results use the latest available JDBC driver.
CockroachDB v23.2.x, v25.2.x
AWS Aurora/MySQL 8.0.x
AWS Aurora/PostgreSQL 17.6
Supported application servers and versions
Apache Tomcat 10.1 and later versions. To configure Tomcat, root or sudo privileges may be required.
Other prerequisites
Java Developers Kit (JDK)
Oracle JDK 21 and 25
RedHat OpenJDK 17, 21 and 25
Eclipse Temurin JDK 17, 21 and 25
Optional when using Identity Proofing and Account Recovery:
Email OTP-based recovery requires an email server supporting SMTP.
SMS OTP-based recovery requires a Twilio account with an active ‘From’ number enabled for SMS support.
Photo ID-based recovery requires a Jumio Netverify account with address and face-match features enabled.