[Bug 3516] ssh-keygen when creating sk fido keys does not create sufficient data for attestation verification.

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Fri Jan 6 15:50:58 AEDT 2023


https://bugzilla.mindrot.org/show_bug.cgi?id=3516

--- Comment #6 from William Brown <william.brown at suse.com> ---
(In reply to Damien Miller from comment #5)
> > This doesn't help when the challenge *isn't* specified though,
> > meaning that if attestation is requested
> 
> Attestation without a verifier-specified challenge is pretty
> worthless, as otherwise there is no guarantee of freshness, or
> conversely, it would allow replay of prior attestations.

Then when attestation is requested, it should be an error to also not
provide a challenge parameter.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.


More information about the openssh-bugs mailing list