Re: [webauthn] TPM attestation verification steps inconsistent with FIDO conformance testing tool (#1925)

Personally, I'm fine with either outcome, but do want to clarify the correct approach so that both the WebAuthn spec is accurate (allowing RPs to know exactly what to expect), and so that if necessary I can go back to the FIDO conformance folks and ask for the current test case to be changed.

I realise the FIDO conformance test tool code is not public, but can say from looking at historical checkins in that code that this test case was *explicitly changed* in a code commit from an "expected fail" to an "expected pass" some 5 years ago (Aug 14, 2018), so at least at some point a determination was made that these algorithm identifiers *can* be different.


-- 
GitHub Notification of comment by sbweeden
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/1925#issuecomment-1650787350 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 26 July 2023 00:42:08 UTC