Re: [webauthn] Clarification of valid rpIdHash value requested in section 7 when using AppID extension

@agl - Is it always a fair assumption that an RP *knows* the credential was previously created with the U2F API?  Maybe... but there's absolutely nothing to require that the RP stored this vital piece of information when the server registered the key  handle and credential public key.

-- 
GitHub Notification of comment by sbweeden
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/980#issuecomment-411529859 using your GitHub account

Received on Wednesday, 8 August 2018 19:48:40 UTC