Skip to content

sk-usbhid: set relying party name during enrollment - #708

Open
Masterwow3 wants to merge 1 commit into
openssh:masterfrom
Masterwow3:master
Open

sk-usbhid: set relying party name during enrollment#708
Masterwow3 wants to merge 1 commit into
openssh:masterfrom
Masterwow3:master

Conversation

@Masterwow3

Copy link
Copy Markdown

Pass the application string as the relying party name instead of NULL.

Windows Hello hybrid enrollment requires a non-empty RP name. Without it, enrollment via a phone fails after credential creation.

Tested on Windows 11 (10.0.26200.9168) with an iPhone (iOS 26.6) using hybrid transport. ECDSA-SK enrollment, signing, and verification succeed.

References:

Pass the application string as the relying party name instead of NULL.
This allows Windows Hello hybrid enrollment to create FIDO credentials.

References: PowerShell/Win32-OpenSSH#2279
References: Yubico/libfido2#994
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant