Skip to content

Commit e2de315

Browse files
author
reffy-bot
committed
Update of ED report from new reffy run
Using reffy commit 17.2.7.
1 parent dcaa744 commit e2de315

File tree

5 files changed

+5682
-5680
lines changed

5 files changed

+5682
-5680
lines changed

ed/algorithms/webauthn-3.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1975,7 +1975,7 @@
19751975
},
19761976
{
19771977
"case": "less than or equal to credentialRecord.signCount:",
1978-
"html": "This is a signal that\n the authenticator may be cloned, i.e. at least\n two copies of the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#credential-private-key\" id=\"ref-for-credential-private-key①⑥\">credential private key</a> may exist and are\n being used in parallel. <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑧⑧\">Relying Parties</a> should incorporate this information\n into their risk scoring.\n Whether the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑧⑨\">Relying Party</a> updates <code><var>credentialRecord</var>.<a data-link-type=\"abstract-op\" href=\"https://w3c.github.io/webauthn/#abstract-opdef-credential-record-signcount\" id=\"ref-for-abstract-opdef-credential-record-signcount④\">signCount</a></code> below in this case, or not, or fails the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#authentication-ceremony\" id=\"ref-for-authentication-ceremony③④\">authentication ceremony</a> or not, is <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨⓪\">Relying Party</a>-specific."
1978+
"html": "This is a signal, but not proof, that the authenticator may be cloned. For example it might mean that: \n <ul>\n <li data-md=\"\">\n <p>Two or more copies of the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#credential-private-key\" id=\"ref-for-credential-private-key①⑥\">credential private key</a> may exist and are being used in parallel.</p>\n </li><li data-md=\"\">\n <p>An authenticator is malfunctioning.</p>\n </li><li data-md=\"\">\n <p>A race condition exists where the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑧⑧\">Relying Party</a> is processing assertion responses in an order other than the order they were generated at the authenticator.</p>\n </li></ul>\n <p><a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑧⑨\">Relying Parties</a> should evaluate their own operational characteristics and incorporate this information into their risk scoring.\n Whether the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨⓪\">Relying Party</a> updates <code><var>credentialRecord</var>.<a data-link-type=\"abstract-op\" href=\"https://w3c.github.io/webauthn/#abstract-opdef-credential-record-signcount\" id=\"ref-for-abstract-opdef-credential-record-signcount④\">signCount</a></code> below in this case, or not, or fails the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#authentication-ceremony\" id=\"ref-for-authentication-ceremony③④\">authentication ceremony</a> or not, is <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨①\">Relying Party</a>-specific.</p>\n <p>For more information on signature counter considerations, see <a href=\"https://w3c.github.io/webauthn/#sctn-sign-counter\">§ 6.1.1 Signature Counter Considerations</a>.</p>"
19791979
}
19801980
]
19811981
}
@@ -2111,15 +2111,15 @@
21112111
"rationale": "for",
21122112
"steps": [
21132113
{
2114-
"html": "<p><a data-link-type=\"dfn\" href=\"https://infra.spec.whatwg.org/#list-iterate\" id=\"ref-for-list-iterate②①\">For each</a> <var>subStmt</var> of <var>attStmt</var>, evaluate the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#verification-procedure\" id=\"ref-for-verification-procedure①③\">verification procedure</a> corresponding to the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#attestation-statement-format-identifier\" id=\"ref-for-attestation-statement-format-identifier⑤\">attestation statement format identifier</a> <code><var>subStmt</var>.fmt</code> with <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#verification-procedure-inputs\" id=\"ref-for-verification-procedure-inputs⑥\">verification procedure inputs</a> <var>subStmt</var>, <var>authenticatorData</var> and <var>clientDataHash</var>.</p>\n <p>If validation fails for one or more <var>subStmt</var>, decide the appropriate result based on <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨④\">Relying Party</a> policy.</p>"
2114+
"html": "<p><a data-link-type=\"dfn\" href=\"https://infra.spec.whatwg.org/#list-iterate\" id=\"ref-for-list-iterate②①\">For each</a> <var>subStmt</var> of <var>attStmt</var>, evaluate the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#verification-procedure\" id=\"ref-for-verification-procedure①③\">verification procedure</a> corresponding to the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#attestation-statement-format-identifier\" id=\"ref-for-attestation-statement-format-identifier⑤\">attestation statement format identifier</a> <code><var>subStmt</var>.fmt</code> with <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#verification-procedure-inputs\" id=\"ref-for-verification-procedure-inputs⑥\">verification procedure inputs</a> <var>subStmt</var>, <var>authenticatorData</var> and <var>clientDataHash</var>.</p>\n <p>If validation fails for one or more <var>subStmt</var>, decide the appropriate result based on <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨⑤\">Relying Party</a> policy.</p>"
21152115
},
21162116
{
2117-
"html": "<p>If sufficiently many (as determined by <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨\">Relying Party</a> policy) <a data-link-type=\"dfn\" href=\"https://infra.spec.whatwg.org/#list-item\" id=\"ref-for-list-item①③\">items</a> of <var>attStmt</var> verify successfully,\nreturn implementation-specific values representing any combination of outputs from successful <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#verification-procedure\" id=\"ref-for-verification-procedure①④\">verification procedures</a>.</p>"
2117+
"html": "<p>If sufficiently many (as determined by <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party②⑨\">Relying Party</a> policy) <a data-link-type=\"dfn\" href=\"https://infra.spec.whatwg.org/#list-item\" id=\"ref-for-list-item①③\">items</a> of <var>attStmt</var> verify successfully,\nreturn implementation-specific values representing any combination of outputs from successful <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#verification-procedure\" id=\"ref-for-verification-procedure①④\">verification procedures</a>.</p>"
21182118
}
21192119
]
21202120
},
21212121
{
2122-
"html": "In addition to setting the <code class=\"idl\"><a data-link-type=\"idl\" href=\"https://w3c.github.io/webauthn/#dom-authenticationextensionsclientinputs-appid\" id=\"ref-for-dom-authenticationextensionsclientinputs-appid\">appid</a></code> extension input,\nusing this extension requires some additional processing by the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party③⓪\">Relying Party</a> in order to allow users to <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#authentication\" id=\"ref-for-authentication①③\">authenticate</a> using their registered U2F credentials:",
2122+
"html": "In addition to setting the <code class=\"idl\"><a data-link-type=\"idl\" href=\"https://w3c.github.io/webauthn/#dom-authenticationextensionsclientinputs-appid\" id=\"ref-for-dom-authenticationextensionsclientinputs-appid\">appid</a></code> extension input,\nusing this extension requires some additional processing by the <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#relying-party\" id=\"ref-for-relying-party③⓪\">Relying Party</a> in order to allow users to <a data-link-type=\"dfn\" href=\"https://w3c.github.io/webauthn/#authentication\" id=\"ref-for-authentication①③\">authenticate</a> using their registered U2F credentials:",
21232123
"rationale": "set",
21242124
"steps": [
21252125
{

0 commit comments

Comments
 (0)