Re: [webauthn] Confused About What To Do With Attestation Trust Paths (#1662)

The procedure is not normative in this spec, but typically you would ensure that the certificate is signed by a trust root from [FIDO metadata services](https://fidoalliance.org/metadata/), or from metadata obtained directly from the vendor(s) of the authenticators you are willing to accept.

-- 
GitHub Notification of comment by sbweeden
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1662#issuecomment-896467206 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 11 August 2021 03:14:11 UTC