WebAuthn: Trust anchor for fido alliance blob changed
Mats Luspa
mats.luspa at irf.se
Thu Aug 27 07:19:14 UTC 2026
Hello!
Fido alliance has changed the root certificate to verify the signature
of the blob (the metadata file for all registered passkeys) to
Globalsign R46 (R3 before). See documentation here
https://fidoalliance.org/metadata/
In WebAuthn documentation
https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878944780/WebAuthnMetadata
point out that idp.authn.webauthn.metadata.trustRootFile should be set
with %{idp.home}/credentials/root-r3.crt. It should or must be changed
to root-r46.crt for the new blob. However the metada crls are still
/opt/shibboleth-idp/credentials/root-r3.crl,
/opt/shibboleth-idp/credentials/gsextendvalsha2g3r3.crl which may be
confusing.
I noticed that when our idpshibboleth suddenly stopped working.
/Regards Mats
--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: matsl at irf.se
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: https://www.irf.se/pgp/matsl
Digital vcard: https://www.irf.se/vcard/mats.luspa
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4382 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20260827/0a9f8688/attachment.p7s>
More information about the users
mailing list