Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Comment on FIDO2 CTAP 2.3 standard and Server Requirements published by Post-Quantum Signatures for JOSE and COSE – Mike Jones: self-issued

Дата публикации: 20-05-2026 06:56:16

[…] Yubico has created prototype Yubikeys (hardware passkeys) supporting ML-DSA signatures. The algorithms are now recommended in the FIDO2 CTAP2.3 Server […]

Основное содержимое страницы с новостью.

FIDO logoThe FIDO Alliance has published the CTAP 2.3 Specification. No breaking changes were introduced between CTAP 2.2 and CTAP 2.3. Implementations of CTAP 2.2 are thus conformant to CTAP 2.3, therefore, a decision was made to provide certification of CTAP 2.3 implementations and not have a separate certification category for CTAP 2.2 implementations.

These are the features added and refined in CTAP 2.3:

  • Multiple Data Transfer Channels for Hybrid Interactions: CTAP 2.3 adds support for multiple data transfer channels for Hybrid interactions. Specifically, QR-Initiated transactions can now specify the data transfer channel to use. The default is Websockets (which was supported by CTAP 2.2). The new data transfer channel that can be specified is Bluetooth Low Energy.
  • Long Touch for Reset: CTAP 2.3 adds support for Long Touch for Reset. This feature allows the authenticator to communicate to the platform that the authenticator reset ceremony requires a long touch.
  • Added “FIDO_2_3” to Supported Versions List: The value “FIDO_2_3” was added to the list of supported versions in authenticatorGetInfo to indicate support for CTAP 2.3. Note that no value was created to indicate support for CTAP 2.2.
  • ISO7816 (NFC) Evidence of User Interaction: Clarified intended behaviors providing Evidence of User Interaction for authenticators supporting the ISO7816 contact interface or the ISO14443 contactless interface (NFC) without a method to collect a user gesture inside the authenticator boundary other than through a power on gesture.
  • setMinPINLength: Clarified in authenticatorGetInfo that setMinPINLength may be used when the Authenticator supports PIN entry via built-in User Verification.
  • authenticatorReset: Stated that either authenticatorReset SHOULD be supported or the authenticator MUST provide an alternate way to reset of the device back to a factory default state.
  • pinComplexityPolicy and setMinPINLength: The description of the interactions between pinComplexityPolicy and setMinPINLength was refined.
  • smart-card: smart-card was added to the list of FIDO Interfaces.
  • FIDO Applet Selection: Prohibited the authenticator from allowing the FIDO Applets to be implicitly selected or enabled.
  • NFCCTAP_GETRESPONSE: Refined NFCCTAP_GETRESPONSE timeout behaviors.

A corresponding version of the Server Requirements document was also published: Server Requirements (WebAuthn Level 3 and CTAP2.3). Recent server requirements additions are:

More good working moving passkeys forward!

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1 Comment on Post-Quantum Signatures for JOSE and COSE by Post-Quantum Signatures for JOSE and COSE – Q-PrEP 022.4603-07-2026
2 Comment on Post-Quantum Presentation at TDI 2026 by Post-Quantum Signatures for JOSE and COSE – Mike Jones: self-issued 024.1320-05-2026
3 Comment on Updates to Audience Values for OAuth 2.0 Authorization Servers by Progress Report on Handling an Actionable Security Vulnerability – Mike Jones: self-issued 015.3129-05-2026
4 Comment on OpenID Connect RP Metadata Choices is an Implementer’s Draft by Final OpenID Connect RP Metadata Choices Specification – Mike Jones: self-issued 011.2301-04-2026
5Announcing FusionAuth 1.63 - The Proof Pangolin012.6726-02-2026
6OASIS Approves Two Public-Key Cryptography Standards to Advance Post-Quantum Security and Interoperability015.715-07-2026
7 Comment on Initial Drafts of 1.1 OpenID Federation Specs by Final 1.1 OpenID Federation Specs – Mike Jones: self-issued 017.7511-05-2026
8Invitation to comment on KMIP Specification v3.0 and KMIP Profiles v3.0 – ends 13 August 202609.6214-07-2026
9Cracking Encryption: The Quantum Threat0726-06-2024
10OpenID4VP and OpenID4VCI conformance tests are complete and open for self-certification05.6307-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 25.71. Источник: self-issued.info.