Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Update Authenticator List

Prev Next

You should periodically update the Server's authenticator metadata. This protects you against vulnerabilities in trusted authenticators and gets the latest certification status for authenticators. The recommended frequency is once a week.

Step 1. Download the Most Recent Metadata

Use the ./nnl-mgmt.sh auth_metadata download command to download the metadata for all authenticators for all FIDO protocols registered at the Fido Alliance, which is a larger set than what Digipass S3 Authentication Software provides.

  • To download current MDS3 authenticator metadata into a specific directory, use the <NNL_HOME>/admin/bin/nnl-mgmt.sh auth_metadata download command.

./nnl-mgmt.sh auth_metadata download -dir <directory> [-disablecrl <yes|no>]
  • If the latest MDS3 metadata blob file is already downloaded from the metadata service, use the ./nnl-mgmt.sh auth_metadata process command to process it.

./nnl-mgmt.sh auth_metadata process -file <mds3 blob.jwt file> -dir <directory> [-disablecrl <yes|no>]

Both of these commands extract individual metadata, place it into the directory depending on its protocol, and generate 3 reports. Output from the process command is the same as the output from the download command.

Check the 3 generated reports for any of the changes listed below:

  • An existing authenticator is revoked Delete the authenticator to avoid security issues.

  • Updates to existing authenticators: Update so your customers use the latest versions of the authenticators.

  • New authenticator: You can review the metadata and decide if you want to use this authenticator.

See Authenticator Metadata Commands for details about what these commands do, where you can find the downloaded metadata, and where to find the logs with summary information for each authenticator.

Step 2. Update the Metadata in the Auth Server’s Database

Use the nnl-mgmt.sh command auth_metadata update to update authenticator metadata in the Auth Server’s database. Refer to Authenticator Metadata Commands.

Example: Upload metadata for one authenticator

Update metadata for Android faceprint authenticator 4e4e#4038 downloaded into directory /path/to/download/directory/metadata/uaf

./nnl-mgmt.sh auth_metadata import -file /path/d/download/directory/metadata/uaf/4e4e#4038.json

Example: Upload metadata from a directory

If several authenticators need updated metadata files, you can copy their metadata files to a different directory. The example below uses the -dir option to upload all the metadata files contained in <NNL_HOME>/admin/bin/updated-metadata.

cd <NNL_HOME>/admin/bin
./nnl-mgmt.sh auth_metadata import -dir updated-metadata