WebAuthN level 3 and Passkeys
The FIDO protocol is continuously evolving to meet the market demands, starting with Passkeys adoption and the support of synchronizable credentials targeting mainly consumer markets and wrapping up with Passkeys adoption for Enterprise ready solutions (like Microsoft Authenticator).
To keep Veridium FIDO server up to date with the evolution of the FidoAlliance specifications, there are several steps to accomplish:
Enable FIDO Resident Key authentication as User Engagement in the Veridium IdP;
Veridium Authenticator as Passkey application
Redesign the FIDO server integration APIs
Remove the Veridium device business logic from the FIDO server.
Improve support for authentication device management during enrolment and authentication
Provide out-of-the-box FIDO conformance testing APIs;
Improve Relying Party default configuration;
Improve the FIDO authenticator management list and remove deprecated code;
Fix the FIDO credential enrolment flow on SSP credential registration delegation.
Enable support for commonly used extensions:
User Verification Method Extension (uvm);
Device-bound public key extension (devicePubKey);
Support iframe for cross-domain FIDO passkey registration and authentication:
This may be useful to allow single credential registration for different domains. For example register within Veridium Self Service Portal credentials for Veridium internal/external domains or even Microsoft Entra.
The latest specifications are currently in release/working draft, but they will be published as