W3C home > Mailing lists > Public > public-webauthn@w3.org > July 2021

Re: [webauthn] Enterprise Attestation Conveyance Preference (#1652)

From: Adam Langley via GitHub <sysbot+gh@w3.org>
Date: Thu, 29 Jul 2021 14:24:54 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-889190278-1627568692-sysbot+gh@w3.org>
> But, is there anything a FIDO Server must do with the results sent by the Authenticator?

The enterprise attestation conveyance is for the case where an RP also controls the authenticators. E.g. a corporate environment where employees are issued authenticators for signing in. While the AAGUID is very unlikely to be uniquely identifying, the attestation statement itself is allowed to be&mdash;which is unique to the enterprise case.

Since this designed for bespoke environments it's difficult to give rules about what they might do. Probably the attestation statement would be in a standard format, but the RP may wish to verify it against custom trust roots. They may wish to parse out bespoke parts of the attestation and check that the authenticator was issued to the account that is trying to register it etc.

-- 
GitHub Notification of comment by agl
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1652#issuecomment-889190278 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Thursday, 29 July 2021 14:24:55 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:44 UTC