Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Step 4. Encrypt credentials used by the server

Prev Next

If you are deploying the Secrets plugin, you are storing all of your credentials in the external secrets manager. In this case you do not need to use an encrypted password, so skip this step. See Implementing the Secrets Plugin.

Prior to installing the Digipass S3 Servers and their components, create a custom password encryption key. Next, run a script which uses that key to encrypt passwords in your installation.

Create Your Custom Password Encryption Key

This step is mandatory for production installations but optional for development installations.

By default, the Authentication Server uses an internal static key for encryption that is the same across different installations of the Authentication Server. You must replace the default key with a custom key. Once you have provisioned the key, assign it to the NNL_PKEY system environment variable so Digipass S3 systems and shell scripts can access the key. If you plan to install several Authentication Servers, use the same key.

Use a script called nnl-key-generator.sh located in mfas/admin/bin. The script doesn't take any arguments, below is sample output:

[nnl@nnl-test-server bin]$ ./nnl-key-generator.sh
 Running nnl-key-generator.sh ...
 Generated encryption key :  EPlk_WqHAIaMTeJWAt5wHg

In a production installation you need to create an environment variable, called NNL_PKEY, on all Digipass S3 nodes. Assign the encryption key to this variable.

For example:

export NNL_PKEY=EPlk_WqHAIaMTeJWAt5wHg

NNL_PKEY must be set before performing any of the following:

  • Encrypting a password with nnl-encrypt-password.sh

  • Running any of the Digipass S3 command-line tools like nnl-mgmt.sh

  • Starting Tomcat

Encrypt Password

Encrypt the following property in nnl-install.properties file, if you are using it:

Property

Description

DB_ENCRYPTED_USER_PASSWD_ENV

Operational Database user password

Using nnl-encrypt-password.sh

If you are editing nnl-install.properties, exit the editor because the script modifies this file. Run the nnl-encrypt-password.sh script to generate an encrypted password or server key.

  • The script takes one parameter: the property name from nnl-install.properties that you want to encrypt.

  • You are prompted for the value to encrypt.

  • The script automatically inserts the encrypted value into nnl-install.properties.

An example to encrypt a database password intended for the DB_ENCRYPTED_USER_PASSWD_ENV property is shown below:

cd <NNL_HOME>/install
./nnl-encrypt-password.sh DB_ENCRYPTED_USER_PASSWD_ENV
Running nnl-encrypt-password.sh ...
Found DB_ENCRYPTED_USER_PASSWD_ENV in nnl-install.properties.
- Enter the value to be encrypted:
- Re-enter the value to be encrypted:
The two entries matched. Generating the encrypted value.
Encrypted value: 7L_vFEs6eR9b2J-4JoTJHyZD-8a5h6vYxW7-2YJvdciGkIGB
Success in encrypting value.
DB_ENCRYPTED_USER_PASSWD_ENV in nnl-install.properties set to the encrypted value.