id,summary,reporter,owner,description,type,status,priority,milestone,component,resolution,keywords,cc 1396,Implement an login extension for WebAuthn,Nicklas Nordborg,Nicklas Nordborg,"!WebAuthn is an authentication protocol that is standardized by W3C. It is supported by later models of !YubiKey and also by several other manufacturers. Support for this protocol exists all the major browsers. It can be compared to the existing !YubiKey implementation that uses a proprietary OTP (one-time-password) protocol. This protocol is also dependent on the !YubiCload servers for validation. https://en.wikipedia.org/wiki/WebAuthn Yubico has a nice server-side implementation: * https://developers.yubico.com/java-webauthn-server/ Documentation for the browser-side API: * https://developer.mozilla.org/en-US/docs/Web/API/Credential_Management_API Some other nice links: * https://betterprogramming.pub/implement-a-passwordless-authentication-app-with-webauthn-aa3635d5d943 * https://www.w3.org/TR/2021/REC-webauthn-2-20210408/ ",task,accepted,major,WebAuthn extension v1.0,net.sf.basedb.webauthn,,,