WebAuthn: Trust anchor for fido alliance blob changed

Mats Luspa mats.luspa at irf.se
Thu Aug 27 07:19:14 UTC 2026


Hello!

Fido alliance has changed the root certificate to verify the signature 
of the blob (the metadata file for all registered passkeys) to 
Globalsign R46 (R3 before). See documentation here 
https://fidoalliance.org/metadata/
In WebAuthn documentation 
https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878944780/WebAuthnMetadata 
point out that idp.authn.webauthn.metadata.trustRootFile should be set 
with %{idp.home}/credentials/root-r3.crt. It should or must be changed 
to root-r46.crt for the new blob. However the metada crls are still 
/opt/shibboleth-idp/credentials/root-r3.crl, 
/opt/shibboleth-idp/credentials/gsextendvalsha2g3r3.crl which may be 
confusing.

I noticed that when our idpshibboleth suddenly stopped working.

/Regards Mats

-- 
-- 
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: matsl at irf.se
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
-- 
PGP Public Key: https://www.irf.se/pgp/matsl
Digital vcard: https://www.irf.se/vcard/mats.luspa

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4382 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20260827/0a9f8688/attachment.p7s>


More information about the users mailing list