12월 22, 2020

FIDO Certified Servers: Updates for Processing Current Metadata Statements

Yuriy Ackermann, Certification Technical Manager, FIDO Alliance

With the advancement and modifications to specifications and program requirements, certification processes and policies will need to be modified from time-to-time. With the recent changes and publication of the FIDO Authenticator Certification program as they relate to V1.4 of the Security Requirements, and the current FIDO Registry of Values specification, we are recommending currently certified servers make necessary changes.

It is strongly recommended that you update your FIDO2 and UAF servers in order to correctly process current and future metadata statements based on the latest updates to the FIDO Registry of Predefined Values.

The spec changes are as follows:

  • All previous USER_VERIFY methods have been post-fixed with _INTERNAL to identify them explicitly as INTERNAL user verification methods 
    • Example: USER_VERIFY_PRESENCE → USER_VERIFY_PRESENCE_INTERNAL.
  • New USER_VERIFY methods have been added: USER_VERIFY_PASSCODE_EXTERNAL (0x00000800) and USER_VERIFY_PATTERN_EXTERNAL (0x00001000)
  • RS1 or ALG_SIGN_RSASSA_PKCSV15_SHA1_RAW (0x0010) IANA ALG_KEY_COSE “alg” identifier has been changed to -65535

Servers should make the following updates to support these changes:

  • FIDO2 servers: Update pubKeyCredParams to contain -65535 alg
  • FIDO2 and UAF servers: Change old user verification methods values to the new post-fixed values. Example: USER_VERIFY_PRESENCE → USER_VERIFY_PRESENCE_INTERNAL
  • FIDO2 and UAF servers: Run the conformance tools to verify support for these changes

The latest FIDO Registry of Predefined Values is now available in JavaScript.

MORE Announcements


The 2023 Workforce Authentication Report: Embracing the Passwordless Future

Businesses are readily embracing the passwordless road ahead. Which direction...

10월 16, 2023

Businesses are Ready to Ditch Passwords, Says New Report from FIDO Alliance and LastPass

89% of IT leaders expect passwords will represent less than...


FIDO Alliance study reveals growing demand for password alternatives as AI-fuelled phishing attacks rise

Increased desire for biometrics and awareness of passkeys increases imperative...


FIDO Alliance study reveals growing demand for password alternatives as AI-fuelled phishing attacks rise

Increased desire for biometrics and awareness of passkeys increases imperative...