Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Sign-in Page

Prev Next

When you use a Federation Server to integrate FIDO authentication into a web app or a webview, you need to have a sign-in web page for your end users. To use the nnlsignin app as your sign-in page:

Step 1. You have 2 options, depending on where you would like to deploy nnlsignin:

Option a. To deploy nnlsignin with the S3 Suite during Server installation, set the installation property DEPLOY_OPTIONAL_WEB_APP_LIST in the nnl-install.properties file. See Install on Linux section List Optional Web Applications for more information.

Option b. To deploy nnlsignin on a Tomcat server of your choice, extract nnlsignin.war from the Nok Nok Web App SDK package into the webapps directory of your chosen application server.

Step 2. Update the information in nnlsignin/config/config.js:

// Configuration object.
var signinConfig = {};
// The version of the Nok Nok JS App SDK the App was built with.
signinConfig.appsdk_version = {{nnl-version}};
// A suffix can be added to this version to point out changes
// to the configuration within the same release.
signinConfig.version = {{nnl-version}};
signinConfig.apiserver = {server-host-where-nnlappsdk-located};
// If you have a single Nok Nok Server tenant, then the tenant_id can be hard
//  coded. If your deployment supports multi-tenancy, get this from the
//  tenant_id query parameter.
signinConfig.tenant_id = {{tenant_id}};
// Default configuration fields.
signinConfig.nnlappsdk_url = "${apiserver}/nnlappsdk-${appsdk_version}";
signinConfig.storage_endpoint = "${apiserver}/nnlgateway/storage";
signinConfig.reg_endpoint = "${apiserver}/nnlgateway/nnl/${tenant_id}/reg";
signinConfig.auth_endpoint = "${apiserver}/nnlgateway/nnl/${tenant_id}/auth";
// For the OOB method to function, the web_oob_url is mandatory, since code sets the QrType to be UNIVERSAL_ANY_RP.
signinConfig.web_oob_url = '${apiserver}/nnlsignin/oobrecv.html';
// If sign-in page and PingFederate Server are hosted on different origins,
// set this to the base URI of the PingFederate Server to enable a form post.
// For example: "/path/to/fedserver" or "${host}/path/to/fedserver".
signinConfig.federation_resume_uri = null;

Replace {{nnl-version}} with the supplied Web App SDK version number. Replace {{tenant-id}} with the supplied tenant name.

signinConfig.federation_resume_uri is a base URI, full or relative, because the nnlsignin app concatenates dynamic, session specific parameters with this base URI before submitting the form POST. If your sign-in page is hosted on the same origin as the Nok Nok Adapter, leave this null.

Step 3. Update the following context parameters in the nnlsignin/WEB-INF/web.xml file:

Parameter name

Description

quick_mode

Specifies quick authentication mode. Refer to the QuickType enumeration in the Web Client API Docs for a list of possible values. The default value is None.

auth_start_mode

Specifies the mode that the authentication should start in. Refer to the AutoStart enumeration in the Web Client API Docs for a list of possible values. The default value is SIGN_IN. If you use inline registration in the Nok Nok Adapter, set auth_start_mode to AUTO_FIDO.

cookie_domain

Domain to set in the authorization cookie before redirecting to Nok Nok Adapter.