Re: WWW-Authenticate with webauthn?

Am 17.05.2021 um 06:00 schrieb Soni L.:
> Are there any plans to support WWW-Authenticate with webauthn? (ideally
> only once per session, so something like a timeout=0 flag and converting
> the authentication into a session cookie would probably be needed.)

As far as I can tell: not over here, as webauth has been defined by a
different group of people.

That said: this would be a new HTTP authentication scheme. New schemes
can be registered under "IETF Review"
(<https://www.rfc-editor.org/rfc/rfc5226.html#section-4.1>), but that
does not imply that it needs to happen in *this* Working Group.

Best regards, Julian

Received on Monday, 17 May 2021 07:33:17 UTC