You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Write documentation, including an example, about how to verify attestations.
Compare AAGUID from the certificate via the id-fido-gen-ce-aaguid extension and comparing it to the expected AAGUID.
Packed Attestation Certificates
Don't require a subjectAltName extension.
TPM Attestation Certificates
Subject must be empty
There must be a SAN as specified in the TPM specs.
EKU = "2.23.133.8.3" OID.
Android Attestation Certificates
dNSName = attest.android.com
AFAICT, Yubico's attestation certificates don't include any EKU or key usage fields. Presumably we shouldn't verify for an EKU and the key usage should be digitalSignature.
AFAICT, Yubico's attestation certificates don't include any EKU or key usage fields. Presumably we shouldn't verify for an EKU and the key usage should be digitalSignature.
/cc @wisespace-io @robn
The text was updated successfully, but these errors were encountered: