Digipass S3 Server
The Auth Server provides robust, flexible authentication depending on the user's context. It supports both the FIDO UAF and Web Authentication (WebAuthn or FIDO2) protocols. It is an Apache Tomcat application that can be installed in your datacenter. It sits behind your application infrastructure (for example; firewall, proxy, and so on) and integrates with your application backend.
The Auth Server provides the following functionality and benefits:
Offloads authentication functions from your application backend
Customizes authentication for your organization using Adaptive Rules and FIDO policies
Stores authenticator-related data such as authenticator metadata, key IDs, and user public keys in a database
Supports multi-tenancy to enable logically different users on the same server
Supports Quick Authentication to improve user response on slow networks and low-bandwidth devices.
Implements out-of-band authentication functionality for devices without built-in authenticators.
Offers health-check endpoints to verify that the servers are running properly
Digipass S3 API Server
The Digipass S3 API Server sits in front of the Authentication Server and handles all communication between the App SDK and the Authentication Server. The Digipass S3 API Server handles session management and can support custom session management schemes by using custom plugins. It also supplies push notification support, additional data required by the EMV 3DS protocol, information to support WebAuthn, and the IP address for Adaptive Rules. The API Server provides interfaces for integrating with your session, policy, and transaction management services.
The API Server can optionally
generate a transaction confirmation token
handle communication when your company server performs an external authentication method
package and return EMV 3DS Session data
trigger push notifications for OOB authentication
identify the client platform or browser for web apps
extract and send the IP address from the request header
enable FIDO2 and WebAuthn authentication where the username is known up front
Server Administration Console
The Digipass S3 Server Administration Console is a web-based GUI tool for managing the Authentication Server and API Server. You can configure FIDO and non-FIDO authentication methods, create and manage admin users, change tenant properties, create Adaptive Rulesets and FIDO policies, manage UAF authenticators, and configure audit logging.
If your production environment does not include the Server Administration Console, you need to use the Server Administration Console in a separate environment such as your development environment. The separate environment that includes the Server Administration Console could be located off-site, but it must be in a secure environment. Finalize your FIDO policies and Adaptive Rules in this separate environment, then import these objects into the production environment using the Digipass S3 command-line tool, nnl-mgmt.sh.
Application Server
The Application Server refers to your server infrastructure. This can include the Application Server, session management, risk management, and transaction management systems.
Integration with IAM and Federation Systems
Digipass S3 integrates with IAMs, federation systems, and identity providers such as Keycloak, PingFederate, and ForgeRock. To incorporate FIDO authentication into a Federated identity provider, Digipass S3 provides adapters.
Digipass S3 provides an app called nnlsignin which integrates with your Federation System through a Digipass S3 adapter. Digipass S3 also provides integration with Federated Systems for credential management using an app called nnlfedapp. For more information, see Utility Apps.