webauthn icon indicating copy to clipboard operation
webauthn copied to clipboard

Attestation on Get Assertion

Open timcappalli opened this issue 3 years ago • 3 comments

Topic from June F2F meeting

With the changing security properties of WebAuthn credentials, we need to re-evaluate the need for an RP to request attestation during a Get Assertion.

timcappalli avatar Jun 09 '22 18:06 timcappalli

2022-06-09 - during F2F, general consensus that allowing this at the spec level is a good idea.

timcappalli avatar Jun 09 '22 19:06 timcappalli

@agl suggested this would be covered in the DPK PR

sbweeden avatar Jun 09 '22 20:06 sbweeden

Is this being covered specifically in regards to DPK or for other credentials as well? I'd prefer the latter.

nicksteele avatar Jun 09 '22 20:06 nicksteele

Done in the DPK changes.

agl avatar Jan 11 '23 20:01 agl

Done

nicksteele avatar Jan 11 '23 20:01 nicksteele

Fixed in #1663.

emlun avatar Jan 11 '23 20:01 emlun