Hi emu folks, I just posted a new version of the EAP-FIDO draft.
We had some discussion on the name "EAP-FIDO" at the last IETF and we have come up with some name options since, but none of them resonate with me yet.
I have started a pad with different name options, everyone is invited to chime in: https://md.kif.rocks/VcVOg34pSFWh64Ev_JsG6Q
For the changes from the previous version:There was some rewording in several paragraphs, I've added some text around error handling.
The most prominent change from the previous draft version is that we now propose that, in the standard usecase, the user only configures the Relying Party ID and that the server certificate is then valid for "eap-fido-authentication.<RPID>" (or something similar, depending on the final name for the protocol).
I am planning to work on an implementation during the hackathon to have a better understanding and can identify possible missing spec and the different error conditions that we need to signal.
I will be presenting my progress at the emu session in Brisbane. Comments are welcome, as always. See you in Brisbane, Janfred On 01.03.24 21:34, internet-dra...@ietf.org wrote:
A new version of Internet-Draft draft-janfred-eap-fido-02.txt has been successfully submitted by Jan-Frederik Rieckers and posted to the IETF repository. Name: draft-janfred-eap-fido Revision: 02 Title: EAP-FIDO Date: 2024-03-01 Group: Individual Submission Pages: 36 URL: https://www.ietf.org/archive/id/draft-janfred-eap-fido-02.txt Status: https://datatracker.ietf.org/doc/draft-janfred-eap-fido/ HTML: https://www.ietf.org/archive/id/draft-janfred-eap-fido-02.html HTMLized: https://datatracker.ietf.org/doc/html/draft-janfred-eap-fido Diff: https://author-tools.ietf.org/iddiff?url2=draft-janfred-eap-fido-02 Abstract: This document specifies an EAP method leveraging FIDO2 keys for authentication in EAP. About This Document This note is to be removed before publishing as an RFC. Status information for this document may be found at https://datatracker.ietf.org/doc/draft-janfred-eap-fido/. Discussion of this document takes place on the EAP Method Update Working Group mailing list (mailto:emu@ietf.org), which is archived at https://mailarchive.ietf.org/arch/browse/emu/. Subscribe at https://www.ietf.org/mailman/listinfo/emu/. The IETF Secretariat
-- Herr Jan-Frederik Rieckers Security, Trust & Identity Services E-Mail: rieck...@dfn.de | Fon: +49 30884299-339 | Fax: +49 30884299-370 Pronomen: er/sein | Pronouns: he/him __________________________________________________________________________________DFN - Deutsches Forschungsnetz | German National Research and Education Network
Verein zur Förderung eines Deutschen Forschungsnetzes e.V. Alexanderplatz 1 | 10178 Berlin https://www.dfn.deVorstand: Prof. Dr.-Ing. Stefan Wesner | Prof. Dr. Helmut Reiser | Christian Zens
Geschäftsführung: Dr. Christian Grimm | Jochem Pattloch VR AG Charlottenburg 7729B | USt.-ID. DE 136623822
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Emu mailing list Emu@ietf.org https://www.ietf.org/mailman/listinfo/emu