XiTatiON

Results 30 comments of XiTatiON

Also keen to throw my support behind this feature. Happy to help test it as it's developed if required. Use case is I run Kanidm and Cloudflare Tunnel, user experience...

> Can you reproduce on https://webauthn.firstyear.id.au/ This one worked fine. See attached screenshots. ![Screenshot 2023-11-30 130706](https://github.com/kanidm/kanidm/assets/1818975/b7ebbc65-d79d-432c-ac4b-e45906055f97) ![Screenshot 2023-11-30 130820](https://github.com/kanidm/kanidm/assets/1818975/026ab63f-56bd-4ca5-877b-7c0ccbf014fc) ![Screenshot 2023-11-30 130855](https://github.com/kanidm/kanidm/assets/1818975/fe466c8b-2854-49d2-a8bf-83f0747e4279) ![Screenshot 2023-11-30 130611](https://github.com/kanidm/kanidm/assets/1818975/6a65611e-d208-4f23-8aed-452be418e17e) ![Screenshot 2023-11-30 130635](https://github.com/kanidm/kanidm/assets/1818975/f0953228-e945-4f05-97f4-b99bbaa13a35)

> Also please try https://webauthn.io/?regUserVerification=preferred&attestation=none&attachment=all&algES256=true&algRS256=true&discoverableCredential=discouraged&authUserVerification=preferred > > Note that I have pre-configured that link to not damage your keys. This one also appears to work fine. See attached screenshots. ![Screenshot...

Ok I've found another piece to this puzzle. My password manager "Keeper" has a browser plugin they have recently added a "Passkeys aspect to it, I usually just cancel on...

> There are some minor fixes to webauthn flows in webauthn-rs since the release. I have updated the maintenance branch and I am preparing updated containers now. I'll let you...

I've pinged Keeper too, would be nice if you can disable the Webauthn / Passkey enrolment for all sites or on a per URL basis. Don't like the idea of...

> Passkeys are "self contained multifactor authentication". Keeper should be asking you for user verification each time to proceed. Good point, and I assume it likely would ask for a...

> Unrelated, but if you use yubikeys, you should be aware of https://fy.blackhats.net.au/blog/2023-02-02-how-hype-will-turn-your-security-key-into-junk/ > > Kanidm does the right thing here, but other sites dont so watch out. This is...

> Can you confirm your rp-id and origins are correct? Should be the domain name and origin values in the server.toml. > > I'm looking at the code and both...

Certs are all lets encrypt wildcards for the domain it's hosted on. I have it setup with Split DNS for internal / external access. I use Cloudflare tunnel for external...