Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Server-Side Components

Prev Next

Digipass S3 Server

The Auth Server provides robust, flexible authentication depending on the user's context. It supports both the FIDO UAF and Web Authentication (WebAuthn or FIDO2) protocols. It is an Apache Tomcat application that can be installed in your datacenter. It sits behind your application infrastructure (for example; firewall, proxy, and so on) and integrates with your application backend.

The Auth Server provides the following functionality and benefits:

  • Offloads authentication functions from your application backend

  • Customizes authentication for your organization using Adaptive Rules and FIDO policies

  • Stores authenticator-related data such as authenticator metadata, key IDs, and user public keys in a database

  • Supports multi-tenancy to enable logically different users on the same server

  • Supports Quick Authentication to improve user response on slow networks and low-bandwidth devices.

  • Implements out-of-band authentication functionality for devices without built-in authenticators.

  • Offers health-check endpoints to verify that the servers are running properly

Digipass S3 API Server

The Digipass S3 API Server sits in front of the Authentication Server and handles all communication between the App SDK and the Authentication Server. The Digipass S3 API Server handles session management and can support custom session management schemes by using custom plugins. It also supplies push notification support, additional data required by the EMV 3DS protocol, information to support WebAuthn, and the IP address for Adaptive Rules. The API Server provides interfaces for integrating with your session, policy, and transaction management services.

The API Server can optionally

  • generate a transaction confirmation token

  • handle communication when your company server performs an external authentication method

  • package and return EMV 3DS Session data

  • trigger push notifications for OOB authentication

  • identify the client platform or browser for web apps

  • extract and send the IP address from the request header

  • enable FIDO2 and WebAuthn authentication where the username is known up front

Server Administration Console

The Digipass S3 Server Administration Console is a web-based GUI tool for managing the Authentication Server and API Server. You can configure FIDO and non-FIDO authentication methods, create and manage admin users, change tenant properties, create Adaptive Rulesets and FIDO policies, manage UAF authenticators, and configure audit logging.

If your production environment does not include the Server Administration Console, you need to use the Server Administration Console in a separate environment such as your development environment. The separate environment that includes the Server Administration Console could be located off-site, but it must be in a secure environment. Finalize your FIDO policies and Adaptive Rules in this separate environment, then import these objects into the production environment using the Digipass S3 command-line tool, nnl-mgmt.sh.

Application Server

The Application Server refers to your server infrastructure. This can include the Application Server, session management, risk management, and transaction management systems.

Integration with IAM and Federation Systems

Digipass S3 integrates with IAMs, federation systems, and identity providers such as Keycloak, PingFederate, and ForgeRock. To incorporate FIDO authentication into a Federated identity provider, Digipass S3 provides adapters.

Digipass S3 provides an app called nnlsignin which integrates with your Federation System through a Digipass S3 adapter. Digipass S3 also provides integration with Federated Systems for credential management using an app called nnlfedapp. For more information, see Utility Apps.