FIDO Attestation Certificate Trust Verifier
- "packed" attestation statement (see Webauthn - Packed Attestation Statement Format)
- "fido-u2f" attestation statement (see Webauthn - FIDO U2F Attestation Statement Format)
An attestation certificate in such an attestation statement is valid if trust can be derived back to a trusted certificate (a.k.a. trust anchor) configured in the truststore, requiring that
- the attestation certificate and every certificate in the chain is valid at the time of registration;
- the signature of the attestation certificate and every certificate in the chain (excepted the last one) can be verified using the public key attested in the next certificate;
- the signature of the attestation certificate or of at least one certificate in the chain can be verified by a public key attested in one of the trusted certificates configured in the trust store.
trustStore) Security warning: Putting a certificate in the trust store has security implications. In particular, trusting a certificate implies trusting every chain of certificates that can be derived back to this trusted certificate. Depending on your requirements as to which type of FIDO authenticators should or should not be accepted, it might be advisable to not directly trust root certificates of a particular FIDO authenticator manufacturer, in order to ensure that future FIDO authenticators from this manufacturer will not be automatically accepted. If the system needs to be as closed as possible, then trusting only the deepest intermediate certificate in the chain would be advisable.
maximumCertificateChainLength) It is recommended to keep this value as low as possible to ensure that Airlock IAM is not overly burdened by such verifications (denial of service).
type: FidoAttestationCertificateTrustVerifier
id: FidoAttestationCertificateTrustVerifier-xxxxxx
displayName:
comment:
properties:
maximumCertificateChainLength: 3
trustStore: