Skip to content

Nitrokey/fido-authenticator

 
 

Repository files navigation

fido-authenticator

FIDO authenticator Trussed® app.

Built with Trussed.

As used in the SoloKeys Solo 2 and Nitrokey 3.

Specifications

Setup

For attestation to work, the authenticator's state needs to be provisioned with a batch attestation key and certificate. They are expected in files /fido/sec/00 and /fido/x5c/00, respectively.

In the context of the SoloKeys Solo 2, "secure" devices are pre-provisioned; for "unlocked" devices, if the firmware contains the provisioner app, this can be done with the CLI:

solo2 pki dev fido batch.key batch.cert
solo2 app provision store-fido-batch-key batch.key
solo2 app provision store-fido-batch-cert batch.cert

License

fido-authenticator is fully open source.

All software, unless otherwise noted, is dual licensed under Apache 2.0 and MIT. You may use fido-authenticator software under the terms of either the Apache 2.0 license or MIT license.

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

All documentation, unless otherwise noted, is licensed under CC-BY-SA. You may use fido-authenticator documentation under the terms of the CC-BY-SA 4.0 license.

About

FIDO authenticator Trussed app.

Resources

License

Apache-2.0, MIT licenses found

Licenses found

Apache-2.0
LICENSE-APACHE
MIT
LICENSE-MIT

Stars

Watchers

Forks

Packages

No packages published

Languages

  • Rust 100.0%