File: pub_key_cred_params.md

package info (click to toggle)
chromium 138.0.7204.183-1~deb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm-proposed-updates
  • size: 6,080,960 kB
  • sloc: cpp: 34,937,079; ansic: 7,176,967; javascript: 4,110,704; python: 1,419,954; asm: 946,768; xml: 739,971; pascal: 187,324; sh: 89,623; perl: 88,663; objc: 79,944; sql: 50,304; cs: 41,786; fortran: 24,137; makefile: 21,811; php: 13,980; tcl: 13,166; yacc: 8,925; ruby: 7,485; awk: 3,720; lisp: 3,096; lex: 1,327; ada: 727; jsp: 228; sed: 36
file content (9 lines) | stat: -rw-r--r-- 1,270 bytes parent folder | download | duplicates (8)
1
2
3
4
5
6
7
8
9
# Advice to sites regarding `PublicKeyCredentialCreationOptions.pubKeyCredParams`

In the options for a [Web Authentication](https://www.w3.org/TR/webauthn/) [credential registration request](https://www.w3.org/TR/webauthn/#createCredential), the caller can specify a list of [cryptographic algorithm identifiers](https://www.w3.org/TR/webauthn-2/#typedefdef-cosealgorithmidentifier) in the [`pubKeyCredParams`](https://www.w3.org/TR/webauthn-2/#dictdef-publickeycredentialparameters) field.

If left unspecified, Chrome uses the default values of `ES256` (-7) and `RS256` (-257).

In some situations, a [Relying Party](https://www.w3.org/TR/webauthn-2/#webauthn-relying-party) developer might choose to augment this list with other identifiers. However, developers should be aware that excluding either of the default identifiers has compatibility risks. In particular, `RS256` is necessary for compatibility with Microsoft Windows platform authenticators. `ES256` is a widely supported algorithm and is compatible with most other platform authenticators and roaming authenticators.

Therefore a Relying Party that uses an algorithm identifier list that omits either of those values will see registration failures when users attempt to use incompatible authenticators.