<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">
<div>The Shibboleth project is pleased to announce the second release candidate of the WebAuthn plugin [1]. </div>
<div><br>
</div>
<div>The second release candidate includes changes to address several issues identified in the first release candidate, which we considered important to resolve before version one. These changes include:</div>
<div>  1. Decoupling the user’s name sent to the authenticator during registration from the username the IdP stores credential registrations against.</div>
<div>  2. Dynamic authenticator metadata lookup (previously it was added once, if enabled, during initial registration).</div>
<div>  3. UI support for naming authenticators/providers not found in the FIDO 2 metadata feed (these are mostly software authenticators). </div>
<div><br>
</div>
<div>In addition, we are developing a basic authenticator policy engine that will enable deployers to allow credential registrations from authenticators based on their capabilities and/or type. Once this is complete, we will release the third and final release
 candidate. Hopefully, the official release will follow soon after that.</div>
<div><br>
</div>
<div>As usual by now, you can find the appropriate version for download by checking the project's Status page [2] from Friday the 27th of September. As this is a release candidate and not a production release, please review the installation instructions on
 the Plugin Testing Wiki page [3].</div>
<div><br>
Note, that a release candidate plugin is for testing purposes only and should not be used in production. Testers are welcome to provide feedback and report bugs on the project's issues page [4].<br>
<br>
Again, we would like to express our gratitude to Timo Tunturi from Aalto University for his valuable feedback on the first release candidate. <br>
<br>
Phil on behalf of the team<br>
<br>
[1] <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3395321933/WebAuthnAuthnConfiguration">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3395321933/WebAuthnAuthnConfiguration</a><br>
<br>
[2] <a href="https://shibboleth.net/cgi-bin/projstatus.cgi">https://shibboleth.net/cgi-bin/projstatus.cgi</a><br>
<br>
[3] <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3256057857/Plugin+Testing">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3256057857/Plugin+Testing</a><br>
<br>
[4] <a href="https://shibboleth.atlassian.net/jira/software/c/projects/JWEBAUTHN/issues">https://shibboleth.atlassian.net/jira/software/c/projects/JWEBAUTHN/issues</a></div>
<br>
<mc type="body"><font size="1"><font face="Corbel"><br>
<p>Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under company number. 05747339, VAT number GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>Jisc Commercial Limited is a wholly owned Jisc subsidiary and a company limited by shares which is registered in England under company number 09316933, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>For more details on how Jisc handles your data see our privacy notice here: https://www.jisc.ac.uk/website/privacy-notice</p>
</font></font>
</body>
</html>