Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Step 4. Configure Non-FIDO Authentication Methods

Prev Next

As mentioned previously, your Adaptive Rules can register and authenticate with non-FIDO authentication methods. Non-FIDO authentication methods include email OTP, SMS OTP, Photo ID using Jumio Netverify, and External Authentication Methods.

The Auth Server has built-in integration with APIs from Twilio and Jumio NetVerify to support SMS OTP and Photo ID, respectively. Once you've configured the Auth Server with the account credentials and specify values for method-specific attributes, you've completed setup. The App SDK and the Auth Server handle all interaction with the end user and the third party service, respectively, to provide your client app with the result from registration or authentication.

Prior to configuring email OTP, you can optionally create an allowed list of email servers for additional security. Email OTP requires specifying information about the account that sends the OTP and characteristics of the passcode.

You can customize or localize the text used in email and SMS OTP messages. See Customizing Text.

External Authentication allows your end users to authenticate with passwords or other authentication methods not currently supported by Nok Nok. The setup described in Adding a New Non-FIDO Authentication Method only requires the name of the External Authentication Method. Additional configuration is required to fully specify all the information needed for an External Authentication Method, see Configure an External Authentication Method.

Deleting OTP or Photo ID

If you don't plan on using OTP or Photo ID, delete the dummy configurations that ship with the Admin Console. This prevents you from accidentally selecting these methods when you create an authentication sequence.

Navigate to Configuration > Authentication Methods > Other Methods and delete the methods you don't want.

Configuring Email OTP

Prior to configuring the Email OTP authentication method, you can create an allowed list of email servers. While this step is optional it provides additional security. Then use the Admin Console to specify the email account and OTP settings to finish email OTP configuration.

Creating an Allowed List of Email Servers

When you configure the email OTP authentication method in the Admin Console, you specify the email server to use and the login credentials for the email account that sends the OTP. Because there is the potential to use those login credentials for malicious purposes, it is important to ensure that the email server is vetted. You can create an allowed list of email servers. When a system administrator configures the email OTP method in the Admin Console, they can only select one of your allowed email servers.

Update the Email OTP configuration with your list of allowed servers using the instructions below.

  1. Assign your email servers to the allowed list.

    The S3 Suite uses the SYSTEM tenant as a container for reserved properties that are common to all tenants. The property nnl.identity.method.config defines the configuration for all the authentication methods you can use: FIDO authentication, FIDO OOB authentication, SMS OTP, Email OTP, photo ID, and External authentication.

    nnl.identity.method.config expects a configuration JSON as its value, an example is shown below. Notice that each authentication method is an object in this JSON. You assign your email servers to the allow list using the smtp.host.allowlist field of the Email OTP object.

    Replace the highlighted lines with your email servers as comma-separated strings in the array. Do not edit the other fields. For readability, this JSON is formatted with tabs and newlines.

{
        "Email OTP":{
        "className":"com.noknok.identity.method.email.EmailMethodPlugin",
        "systemConfigurations":{
        "serviceFactory":"com.noknok.platform.services.PlatformServiceFactory"
        },
        "genericConfigurations":{
        "smtp.host.allowlist":[
        "smtp.gmail.com",
        "smtp.sendgrid.net",
        "smtp.noknok.com"
        ]
        }
        },
        "SMS OTP":{
        "className":"com.noknok.identity.method.sms.SMSOtpMethodPlugin",
        "systemConfigurations":{
        "serviceFactory":"com.noknok.platform.services.PlatformServiceFactory"
        }
        },
        "Photo ID":{
        "className":"com.noknok.identity.method.nv.NVPictureIdMethodPlugin",
        "systemConfigurations":{
        "serviceFactory":"com.noknok.platform.services.PlatformServiceFactory",
        "server.url":"https://netverify.com/api/netverify/v2/scans/"
        }
        },
        "FIDO Auth":{
        "className":"com.noknok.identity.method.fido.FidoMethodPlugin"
        },
        "FIDO OOB Auth":{
        "className":"com.noknok.identity.method.oob.OOBMethodPlugin"
        },
        "External Auth":{
        "className":"com.noknok.identity.method.external.auth.ExternalAuthMethodPlugin"
        }
        }
  1. Create a properties file. A properties file is a text file with the extension .properties that assigns values to one or more tenant properties. Remove spaces and newlines as well as stringify the JSON you created in Step 1. In the properties file, assign the configuration JSON to nnl.identity.method.config. An example properties file is shown below.

nnl.identity.method.config={\"Email OTP\":{\"className\":\"com.noknok.identity.method.email.EmailMethodPlugin\",\"systemConfigurations\":{\"serviceFactory\":\"com.noknok.platform.services.PlatformServiceFactory\"},\"genericConfigurations\":{\"smtp.host.allowlist\":[\"smtp.gmail.com\",\"smtp.yahoo.net\",\"smtp.noknok.com\"]}},\"SMS OTP\":{\"className\":\"com.noknok.identity.method.sms.SMSOtpMethodPlugin\",\"systemConfigurations\":{\"serviceFactory\":\"com.noknok.platform.services.PlatformServiceFactory\"}},\"Photo ID\":{\"className\":\"com.noknok.identity.method.nv.NVPictureIdMethodPlugin\",\"systemConfigurations\":{\"serviceFactory\":\"com.noknok.platform.services.PlatformServiceFactory\",\"server.url\":\"https://netverify.com/api/netverify/v2/scans/\"}},\"FIDO Auth\":{\"className\":\"com.noknok.identity.method.fido.FidoMethodPlugin\"},\"FIDO OOB Auth\":{\"className\":\"com.noknok.identity.method.oob.OOBMethodPlugin\"},\"External Auth\":{\"className\":\"com.noknok.identity.method.external.auth.ExternalAuthMethodPlugin\"}}
  1. Update the SYSTEM tenant’s nnl.identity.method.config property by importing your property file with the nnl-mgmt.sh properties import command.

./nnl-mgmt.sh properties import -tenantid system -file email‑allowlist.properties -overwrite yes

For more details about the nnl-mgmt.sh properties import command see Properties Commands.

Configuring the Email OTP Authentication Method

To use email OTP, you must have an email server that supports SMTP.

  1. Navigate to Configuration > Authentication Methods > Other Methods > OTP Using Email.

  2. If you created an allowed list of email servers, select a host from the SMTP Host dropdown. Otherwise, enter your SMTP host in the SMTP Host textbox.

  3. Enter the port number as well as the email account that sends the OTP. You must fill in the From Email Address field if you are configuring SendGrid.

    You can optionally enter From Name, ReplyTo Email Address, and ReplyTo Name. The Password is required.

    Scroll down to specify how long the OTP should be, the amount of time in seconds before it expires, what characters to use for the OTP, and how many attempts the user has to enter the OTP correctly.

Configuring SMS OTP

Using SMS OTP requires a Twilio account with an active ‘From’ number enabled for SMS support.

  1. Navigate to Configuration > Authentication Methods > Other Methods > OTP Using SMS.

  2. Enter your Twilio account ID and authentication token. Specify how long the OTP should be, the amount of time in seconds before it expires, what characters to use for the OTP, and how many attempts the user has to enter the OTP correctly. You need to scroll to see all the fields.

Configuring Photo ID

To use Photo ID, you must set up an account with Jumio Netverify with address and face-match features enabled. Nok Nok's Server interacts with the Jumio Netverify ID service to provide Photo ID verification.

  1. Navigate to Configuration > Authentication Methods > Other Methods > Using Photo ID.

  2. Enter your API token and API secret.

About Photo ID

In this authentication method, the user submits a photo ID and selfie to the Jumio Netverify service using the App SDK's functionality in your client app. Netverify validates the uploaded images and returns a scan reference ID to the App SDK. When the App SDK sends the authentication request to the Auth Server, it sends the scan reference ID. Using the scan reference ID, the Auth Server queries the Netverify service for the results of the scan, which it then returns to the App SDK.

Use the following services from Netverify to implement this authentication method:

  • Mobile SDK - Your client app uses the mobile SDK to initiate the verification of the user. In response, it receives a scan reference ID, which is forwarded to the Server for completing recovery setup or verification.

  • Netverify Retrieval API - This is a REST API-based service that enables the Server to fetch the Photo ID-based verification details from the Netverify service. To do so, the scan reference ID is used to make calls to the Netverify retrieval APIs to fetch scan status and scan details from the Netverify service. From the scan details, a selfie match is confirmed, and the information extracted from the document is used for adaptive registration and authentication.

Add a New Non-FIDO Authentication Method

You can add additional methods, including an External Authentication method, with different values for their fields. If you are adding an External Authentication Method, additional configuration is required to update your client app, augment your RP Server to create and send a JWT after authentication, and configure the External Authentication plugin to validate that JWT. See Configuring an External Authentication Method.

  1. Navigate to Configuration > Authentication Methods > Other Methods.

  2. Click Add Method.

  3. The Add Method dialog appears. Enter your method's name. In addition to letters and digits, only the following characters are allowed in a method name: hyphen (-), underscore (_) and space ( ).

  4. Select one of Email OTP, SMS OTP, Photo ID, or External Auth from the Type dropdown. Click Save.

  5. The dialog updates to show fields appropriate for the selected authentication method. If you added an External Authentication method, there are no fields to fill in. For the other types of methods, refer to the previous sections for guidance on how to fill in the fields.

Customizing Text

You can localize or customize the text used by the system for the Email OTP and SMS OTP authentication methods. This is the text that appears in the message sent to the user.

For example, the subject line and body text of emails sent during an Email OTP authentication can be specified for both the setup and verification emails.

The text can be localized or customized per tenant:

  1. Create a new tenant, e.g. examplecorp.

  2. Go to the <TOMCAT_HOME>/webapps/nnl/WEB-INF/classes directory on the Auth Server or server container and note the _default and _Admin directories.

  3. Copy the _default directory to _<new tenant>, for example, _examplecorp. Do this on all nodes present in the cluster.

  4. Edit the existing properties file(s) or add a language-specific ResourceBundle properties file to this directory to support the desired language.