← Back to plugin index

FIDO Attestation Certificate Trust Verifier

Description
Verifies that the attestation certificate and the associated chain of certificates provided in an attestation statement produced by a FIDO authenticator during registration can be trusted. Currently, only the following attestation statement formats are supported:

An attestation certificate in such an attestation statement is valid if trust can be derived back to a trusted certificate (a.k.a. trust anchor) configured in the truststore, requiring that

  • the attestation certificate and every certificate in the chain is valid at the time of registration;
  • the signature of the attestation certificate and every certificate in the chain (excepted the last one) can be verified using the public key attested in the next certificate;
  • the signature of the attestation certificate or of at least one certificate in the chain can be verified by a public key attested in one of the trusted certificates configured in the trust store.

Type name
FidoAttestationCertificateTrustVerifier
Class
com.airlock.iam.factor.application.configuration.fido.FidoAttestationCertificateTrustVerifierConfig
May be used by
License-Tags
FIDO
Properties
Trust Store (trustStore)
Description
The truststore containing the trusted certificates to verify the attestation certificate produced by a FIDO authenticator during registration. The certificates must be in X509 format and all X509 certificates in the truststore will be used for verification and assumed to be trusted.

Security warning: Putting a certificate in the trust store has security implications. In particular, trusting a certificate implies trusting every chain of certificates that can be derived back to this trusted certificate. Depending on your requirements as to which type of FIDO authenticators should or should not be accepted, it might be advisable to not directly trust root certificates of a particular FIDO authenticator manufacturer, in order to ensure that future FIDO authenticators from this manufacturer will not be automatically accepted. If the system needs to be as closed as possible, then trusting only the deepest intermediate certificate in the chain would be advisable.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Maximum Certificate Chain Length (maximumCertificateChainLength)
Description
Maximum length of certificate chain to verify. Longer chains of certificates will fail this verification.

It is recommended to keep this value as low as possible to ensure that Airlock IAM is not overly burdened by such verifications (denial of service).

Attributes
Integer
Optional
Default value
3
YAML Template (with default values)

type: FidoAttestationCertificateTrustVerifier
id: FidoAttestationCertificateTrustVerifier-xxxxxx
displayName: 
comment: 
properties:
  maximumCertificateChainLength: 3
  trustStore: