[Bug 3516] ssh-keygen when creating sk fido keys does not create sufficient data for attestation verification.

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Fri Jan 6 13:08:34 AEDT 2023


https://bugzilla.mindrot.org/show_bug.cgi?id=3516

--- Comment #5 from Damien Miller <djm at mindrot.org> ---
> This doesn't help when the challenge *isn't* specified though,
> meaning that if attestation is requested

Attestation without a verifier-specified challenge is pretty worthless,
as otherwise there is no guarantee of freshness, or conversely, it
would allow replay of prior attestations.

-- 
You are receiving this mail because:
You are watching someone on the CC list of the bug.
You are watching the assignee of the bug.


More information about the openssh-bugs mailing list