Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Configuring Tutorial app

Prev Next

This section describes common scenarios that require configuring Tutorial App.

Using your server

To use your own Digipass S3 Server with Tutorial App, you must modify the following values in TutorialAppPlus/TutorialAppPlus/config.json:

  • version

  • host

  • fido_appid

  • fido2_page

  • reg_endpoint

  • auth_endpoint

  • login_url

  • fed_login_url

  • fed_logout_url

  • federation_enabled

  • sso_enabled

A convenient way to override these values is to open the Tutorial App and click on Scan QR Code from the menu in the upper left corner. Then follow the instructions at Configuring iOS or Android Tutorial App to point your Tutorial App to your Authentication Server.

Supporting AppAuth

Google AppAuth is a method for providing integration with OpenID Connect. Digipass S3 Authentication Software supports AppAuth. Performing FIDO Authentication using AppAuth requires that you provide a set of parameters. All server-specific parameters, which should be modified for each particular OpenID Connect server, are grouped in one place in the Constants.swift file of the Tutorial App for ease of maintenance. Listed below are string resource names and descriptions of the AppAuth parameters.

  • kAuthorizationEndpoint: An endpoint to which the AppAuth authorization request should be sent. For a particular OIDC server integration, this value should be in the form https://hostname/as/authorization.oauth2

  • kTokenEndpoint: An endpoint to which the token exchange request should be sent. For a particular OIDC server integration, this value should be in the form https://hostname/as/token.oauth2

  • kRedirectURI: The redirect URI to use for receiving the authorization response. This should be in the following format:
    <YourSchemaName>:<RedirectURI>
    AppAuth redirects requests to your app. Note that for a particular OIDC server integration, your schema name should be added to the app plist file in the URL Schemes section. It is used by iOS to open the app, which is responsible for further processing. For more information, refer to the Apple documentation.

  • kClientID: The OAuth2 client id used to identify the client to the authorization server.

  • kClientSecret: Client secret value used on OAuth2 client registration

  • PING_SCOPES: The scope string to use for the authorization request. Any value understood by your authorization server can be used. The scope value should contain "openid" in case multiple scopes are specified, with values separated by spaces. For example, "rlwp openid".

The current implementation does not support dynamic client registration, as the registration endpoint is set to nil during initialization of the OIDCServiceConfiguration object. Therefore, you must provide the kClientID and kClientSecret values.

There is also the AUTH_CODE_RESPONSE_TYPE = "code" parameter which is a constant and not dependent on the server, so it is set in the code and is not added to the string resources.

There could also be additional parameters specific to a particular server and which are not usable with other server implementations. For example, the operation = "INIT_OOB_GUI" parameter for a Ping server implementation. These kinds of parameters are not declared in string resources, as they are not common and should instead be added in the code as additional parameters using the additionalParameters argument of the OIDAuthorizationRequest class constructor.

Using Netverify

The Digipass S3 App SDK allows you to use the Netverify SDK for the Photo ID authentication method. To use the Netverify SDK:

  1. Download the Netverify iOS Frameworks from the Jumio web page. Then copy JumioCore.framework and Netverify.framework files into the frameworks folder.

  2. Add the JumioCore.framework and Netverify.framework files to the Embedded Binaries section:

  3. Find the “PictureMethod” folder in the Tutorial App package, this contains the files necessary for Netverify support. Add the content separately (NetverifyStartViewController.swift, NetverifyStartViewController.xib, PictureIdMethodUi.swift, UIPresenter.swift).

  4. Open the commented #import <JumioCore/JMDeviceInfo.h> and #import <UIKit/UIKit.h> lines in the file TutorialAppPlus-Bridging-Header.h.

  5. To use the Picture method, define a new factory class as a subclass of NNLMethodUIFactory and set your new factory class as the NNLMethodUIFactory instance like this:

let defaultFactory = NNLMethodUIFactory.getInstance()
let factory = PictureMethodFactory(factory: defaultFactory)
NNLMethodUIFactory.setInstance(factory)

In TutorialApp the SampleMethodUiFactory has all necessary implementations and will start supporting the method after adding the PictureIdMethodUi.swift file.

  1. Edit NetVerifyStartViewController.swift. Add your API Token and API Secret in the function setupUi().

  2. Make sure that your app target version is Jumio Sdk version 3.9.4 or later.

Using keychain sharing

The Digipass S3 App SDK allows you to share FIDO credentials between iOS apps developed by the same vendor. This allows the user to register using one app to create a credential and authenticate to the other apps using the same credential. The user does not need to register separately to each app as long as the apps are from the same vendor.

To enable credential sharing in Tutorial App, perform the following steps:

  1. In the Target Build Settings, enable Keychain Sharing and group name as shown in the following image:

    This creates an entitlements file in the project, as shown in the following image:

  2. Add the shared access group to app Info.plist file. The SharedAccessGroup key should be used in the Info.plist file.

  3. Create application groups in the project file. Here is an example of adding an application group to the project file:

  4. Add the App Group to the Info.plist file. The SharedAppGroup key should be used in the Info.plist file. Note that you should set the same value you set in the app’s settings in the previous image.

Credential sharing is AAID based, and keychain sharing does not apply to all authenticators. The following authenticators are designed to support credential sharing using keychain sharing:

AAID

Behavior Description

Code to Add Authenticator

4e4e#4093

Same as 4e4e#400a (UVS behavior for Touch ID) but supports credential sharing

TouchIDASM.addTouchIDNoLinkageShareableAuthenticator()

4e4e#4094

Same as 4e4e#400b (Key deletion behavior for Touch ID) but supports credential sharing

TouchIDASM.addTouchIDLinkageShareableAuthenticator()

4e4e#4095

Same as 4e4e#4009 (Passcode) but supports credential sharing

TouchIDASM.addPasscodeShareableAuthenticator()

4e4e#4096

Same as 4e4e#4014 (Passcode or Touch ID) but supports credential sharing

TouchIDASM.addTouchIDWithPasscodeShareableAuthenticator()

4e4e#4097

Same as 4e4e#4005 (Legacy Passcode) but supports credential sharing

TouchIDASM.addTouchID8ShareableAuthenticator()

4e4e#4098

Same as 4e4e#4025 (Silent authenticator) but supports credential sharing

SilentASM.addSilentShareableAuthenticator()

4e4e#4099

Same as 4e4e#4026 (Silent authenticator) but supports credential sharing

SilentASM.addSilent8ShareableAuthenticator()

4e4e#409a

Same as 4e4e#4027 (PIN authenticator) but supports credential sharing

PinASM.addPinShareableAuthenticator()

4e4e#409b

Same as 4e4e#4028 (PIN authenticator) but supports credential sharing

PinASM.addPin8ShareableAuthenticator()

4e4e#409c

Same as 4e4e#400e (Yes/No presence authenticator) but supports credential sharing

PresenceASM.addPresenceShareableAuthenticator()

4e4e#409d

Same as 4e4e#400f (Yes/No presence authenticator)
but supports credential sharing

PresenceASM.addPresence8ShareableAuthenticator()

4e4e#409e

Same as 4e4e#800a (Sample ASM) but supports credential sharing

SampleASM.addSampleShareableAuthenticator()

4e4e#409f

Same as 4e4e#8005 (Sample ASM) but supports credential sharing

SampleASM.addSample8ShareableAuthenticator()

All other authenticators still work locally.

Using a FIDO client for credential sharing

Tutorial App can be configured to work with a FIDO UAF Client installed on your device.

  1. Launch the Tutorial App project in Xcode by double-clicking the TutorialAppPlus.xcodeproj project file.

  2. Open the AppDelegate.swift file in the Tutorial App.

  3. Change the useRemoteClient flag to true. See code below.

  4. Build and run Tutorial App.

let useRemoteClient = true

Ensure that a FIDO client is installed on the device. Note that the OneSpan Passport app is also a FIDO client.

Note also that in this configuration, no embedded authenticators in your app are available for operation.

Using Passport app for credential sharing

When you have multiple mobile apps, you can designate one of the apps to perform authentication for the related apps. FIDO credentials are shared between the apps. In this scenario the user has to register once using the designated authentication app and does not have to register into each app. This app owns and manages the FIDO credentials for the related apps.

In this section we show you how to use the Passport App as the authentication app. You can also use your own app instead of the Passport App using the same approach.

Building Tutorial app to use Passport app

Tutorial App can hand off all FIDO operations to the Passport App. Alternatively, it can specifically use the Passport App as a FIDO client.

  1. Launch the Tutorial App project in Xcode by double-clicking the TutorialAppPlus.xcodeproj project file.

  2. Open the AppDelegate.swift file in the Tutorial App and do the following:

    1. Follow the instructions above for "Using a FIDO Client for Credential Sharing"

    2. Add the mfac_cfg.json file with "customClient" set to "NokNokUAFClient".

  3. Build and run Tutorial App.

Using Tutorial app with Passport app

Ensure that Passport App has been installed on the target device prior to testing. Launch Tutorial App. It now uses Passport App to perform a FIDO operation, such as prompting the user to register or authenticate by scanning their fingerprint or scanning a QR code.

Server configuration

Besides the client-side changes shown here, successful implementation of the credential sharing feature also requires assigning the AppID on the Digipass S3 Server. See Configure Apps.

Enabling Quick FIDO authentication

You can configure Tutorial App to support Quick FIDO Authentication. Set the Quick mode to any value except None from the Settings screen. As a result, the tutorial app passes the following extra arguments to the NNLAppSDKPlus and to the NNLAdaptiveUI:

Registration: ExtrasQuickAuthEnable:"true" key value is passed to the getFidoRegistrationView() and suggestRegister() functions in the extras parameter.

Authentication: ExtrasKeySignInQuickMode: “<Quick mode>” key value is passed to the getAuthenticationView() function in the authOptions parameter.

Working examples in Tutorial app
  • TAUtils.swift

  • RegisterViewController.swift