Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

API Server configuration

Prev Next

Introduction

When you create a tenant, you must also configure it. The majority of that configuration involves the Digipass S3 API Server and its plugins. Configuration information for these components is contained in a JSON that is stored in the Auth Server's database. Use either the Admin Console or the Command Line Interface's nnl-mgmt.sh apiserver command to add or modify these configuration objects.

The API Server has its own configuration object called Main. Most of the API Server plugins also have their own dedicated configuration objects. The two utility apps supplied by Digipass S3 Authentication Software share a configuration object. In addition, Digipass S3 supplies a Default JWT Config object. This page describes the configuration objects for the following plugins and components:

In addition, each type of configuration object has its own Main object that tells which plugins of that type are enabled, what are the names of any custom plugins of that type, and other information relevant to that type of configuration object.

The table below tells, for each API Server plugin or component, the type and name of its configuration object together with the circumstances when it is used. One configuration object configures the features for one tenant, so the table below describes the configuration objects for one tenant. Note that there are also plugins without configuration objects and they are not included in the table.

Feature

Config Object Type

Config Object Name

When it is used

API Server's Main Configuration

Main

Main

Always

Default JWT Config

Main

jwt_config

Used by any plugin that uses jwt_config and doesn't have a local config object.

Utility App Configuration

Main

nnlapp_config

Used to configure the two utility apps, nnlfedapp and nnlsignin.

Session Plugins' Main Configuration

SessionPlugin

Main

Always.

Used to activate and deactivate one or more Session plugins. Also contains configuration properties applicable to all session plugins

JWT Processor38

SessionPlugin

jwt_config

Always

User Agent Parser

SessionPlugin

ua_parser

You implemented web apps that use WebAuthn. Used to identify the client platform or browser.

EMV 3DS Generator

SessionPlugin

jws_config

You want EMV 3DS data returned after successful FIDO registration, authentication, and transaction confirmation.

You created one or more Adaptive Rules that return an EMV 3DS FIDO blob.

IP Address Extractor

SessionPlugin

ip_address_plugin

You created one or more Adaptive Rules that use client IP address in their condition.

Privacy Credential Generator

SessionPlugin

credsim_config

You implemented a native or web app that uses FIDO2, and your app needs to pass a username for an authentication operation. Use this plugin only if you don't want the server to reveal information on whether the unauthenticated user has FIDO credentials or not.

Policy Selector's Main Configuration

PolicyPlugin

Main

Activate and deactivate the Policy plugin.

Policy Selector

PolicyPlugin

default_config

Your app performs FIDO or OOB registration and doesn't pass the optionsData.policyName parameter. Use this plugin to resolve the policy name using default_config instead.

Transaction Plugin's Main Configuration

TransactionPlugin

Main

Used to activate and deactivate the Transaction plugin.

JWT Transaction Processor

TransactionPlugin

jwt_config

Your App supports transaction confirmation.

External Authentication Plugin's Main Configuration

ExternalAuthenticationPlugin

Main

Activate and deactivate a JWT or a Password External Authentication plugin.

JWT External Authentication

ExternalAuthenticationPlugin

jwt_config

You want users to authenticate with passwords or any other authentication method not supported by Digipass S3.

Password External Authentication

ExternalAuthenticationPlugin

pwd_plugin_config

You want your users to authenticate with passwords.

Main Configuration for External IdPs

ExternalIdentityProvider

Main

Activate or deactivate one or more OIDC-enabled external identity providers.

External IdP configuration for OIDC

ExternalIdentityProvider

<External IdP registration ID>

Your External IdP is an OIDC server that authenticates the user and obtains the required session for FIDO registration.