This v9.5 article is also available in v10.0
Note that there may be additional functionalities discussed in Utility app configuration (v10.0).
The Digipass S3 Server and Web App SDK both ship with two utility apps developed at Digipass S3 Labs, nnlsignin and nnlfedapp. Use nnlsignin together with a Digipass S3 Federation Adapter to bring FIDO authentication into a Federation Server. Use nnlfedapp to support Federated Credential Management accessible through an OIDC flow.
To deploy these apps when you install the Server, set the DEPLOY_OPTIONAL_WEB_APP_LIST property in the nnl-install.properties file as described in Install the Digipass S3 Servers on Linux. You can also deploy them with the Web App SDK.
These two utility apps use the Web App SDK to perform various operations. You can configure how the Web App SDK behaves for these utility apps by creating the nnlapp_config object of type Main. Upload nnlapp_config to the API Server using the Admin Console. Navigate to Configuration > API Server > Main > Digipass S3 App Config and click the Upload button.
If your Digipass S3 Server is deployed on premises and the default values do not work for you, modify the default values by editing nnlfedapp/config/config.js or nnlsignin/config/config.js. Then set only tenant-specific fields inside nnlapp_config.fedAppConfig and nnlapp_config.signinConfig.
The nnlapp_config configuration object is tenant-specific and it contains:
Field | Description |
|---|---|
appSdkConfig | Optional: Specifies options for the AppSdkConfig object. For more details about those options, see the AppSdkConfig object in the ClientAPI docs for Digipass S3 Web App SDK. |
authOpts | Optional. Specifies authentication options in nnlsignin. For more information see the authOpts parameter of the AdaptiveUI.getAuthenticationView() function in the Client API docs for Digipass S3 Web SDK. |
fedAppConfig | Optional. A configuration object that specifies options for nnlfedapp. See table below for specific fields inside this object. These configurations override the defaults set in nnlfedapp/config/config.js. |
fidoRegOpts | Optional. Specifies options when nnlfedapp registers FIDO authenticators. For more details see the Extras parameter of the AppSdk.getFidoRegistrationView() function in the Client API docs for Digipass S3 Web App SDK. |
manageRegOpts | Optional. Specifies options when nnlfedapp manages registrations. For more details see the Extras parameter of the AppSdk.getManageRegistrationsView() function in the Client API docs for Digipass S3 Web SDK. |
regOpts | Optional. Specifies options when nnlfedapp registers non-FIDO authentication methods. For more details see the regOpts parameter of the AdaptiveUI.getRegistrationView() function in the Client API docs for Digipass S3 Web App SDK. |
signinConfig | Optional. A configuration object that specifies options for nnlsignin. See table below for specific fields inside this object. These configurations override the defaults set in nnlsignin/config/config.js file. |
suggestRegOpts | Optional. Specifies Suggest Registration options in nnlsignin. For more information see the suggestRegOpts parameter of the AdaptiveUI.getAuthenticationView() function in the Client API docs for Digipass S3 Web SDK. |
The fedAppConfig object nested inside nnlapp_config can have the following fields:
Field | Description |
|---|---|
nnlappsdk_url | The URL where the Digipass S3 Web App SDK is located. Default value is "${host}/nnlappsdk-${appsdk_version}" |
reg_endpoint | The registration endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/reg" |
auth_endpoint | The authentication endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/auth" |
storage_endpoint | The endpoint of the cookie-based storage. The default value is "${host}/nnlgateway/storage" |
ui_config_url | The URL of the root configuration directory for the JSON UI Configuration files used by nnlfedapp. Default value is null. See App UI Customization for details on how to create your UI Configuration files, and see the section Storing Your UI Configuration Files Using a Remote Server for information about how to structure the directories that contain your UI configuration. |
setupMobile | Specifies the behavior of the Set Up New Device button in nnlfedapp. This parameter accepts three values: NEVER, ALWAYS, and CONDITIONALLY. If set to NEVER, the button is always hidden. If set to ALWAYS, the button is always displayed regardless of the adaptive rules configured on the server. If set to CONDITIONALLY, the button is displayed only when the adaptive rules configured on the server allow for OOB registration. |
nnlfedapp substitutes actual values for ${host}, ${tenant_id} and ${appsdk_version}.
To configure OIDC parameters for nnlfedapp, see Credential Management Page page.
The signinConfig object nested inside nnlapp_config can have the following fields:
Field | Description |
|---|---|
auth_endpoint | The authentication endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/auth" |
auth_start_mode | The mode that authentication should start in. For available values see the AutoStart enum in the Web App SDK API Docs. The default value is "SIGN_IN". |
cookie_domain | The domain of the authentication cookie that nnlsignin uses to pass the JWT of authenticated user to the Digipass S3 Federation Adapter. |
cookie_name | The name of the authentication cookie that nnlsignin uses to pass the JWT of an authenticated user to the Digipass S3 Federation Adapter. |
federation_resume_uri | Default value is null. The nnlsignin app can pass the JWT of an authenticated user to the Digipass S3 Federation Adapter in 2 different ways: 1. Drop the JWT into the cookie and redirect to the Federation Server. In this case the nnlsignin app and the Federation Server are assumed to be on the same origin or share the same parent origin. In this case, signinConfig.federation_resume_uri parameter is not used and should be left with its default value. or In some cases the signinConfig.federation_resume_uri is a base URI because a full form-post URL may require the resume path which is known only at runtime. The Digipass S3 Federation Adapter may provide the resume path to nnlsignin during the redirect. The nnlsignin app then concatenates the resume path with the base URI before making the form-post: form_post_url = signinConfig.federation_resume_uri + resume_path. |
nnlappsdk_url | The URL where the Digipass Web App SDK is located. Default value is "${host}/nnlappsdk-${appsdk_version}" |
reg_endpoint | The registration endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/reg" |
storage_endpoint | The endpoint of the cookie based storage. The default value is "${host}/nnlgateway/storage" |
ui_config_url | The URL of the root configuration directory for the JSON UI Configuration files used by nnlsignin. Default value is null. See App UI Customization for details on how to create your UI Configuration files, and see the section Storing Your UI Configuration Files Using a Remote Server for information about how to structure the directories that contain your UI configuration. |
web_oob_url | The URL of the page that processes the scanned QR code for Appless OOB operations. Default value is "${host}/nnlsignin/oobrecv.html". This field is mandatory if you use OOB authentication. |
nnlsignin substitutes actual values for ${host}, ${tenant_id} and ${appsdk_version}.
Example nnlapp_config Configuration Object
{
"appSdkConfig": {
"otp": {
"maxFalseAttempts": 1,
"lockoutPeriod": 5
},
"darkMode": "on"
},
"fedAppConfig": {
"ui_config_url": "https://example.com/fedapp_ui_config"
},
"fidoRegOpts": {
"askSecurityKeyCredentialName": false
},
"manageRegOpts": {
"options": {
"needDetails": 3
}
},
"signinConfig": {
"federation_resume_uri": "http://ping.noknokeval.com:9031/as/authorization.oauth2",
"ui_config_url": "https://example.com/signin_ui_config"
},
"authOpts": {
"signInWithMobile": "CONDITIONALLY"
},
"suggestRegOpts": {
"askSecurityKeyCredentialName": true,
"autoReg": true,
"suggestRegEnabled": true
}
}