-
Type:
Improvement
-
Status: Resolved
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: webauthn
-
Labels:
-
Sprint:FRaaS 2019.17 - Roombas, FRaaS 2020.1 - Roombas
-
Epic Link:
-
Support Ticket IDs:
- Using Windows Hello through FIDO2, a case scenario is to use Windows Tablets with Windows Hello sign-on.
- To meet security requirements, a check of the TPM attestation certificate is made. However, TPM attestation in the FR registration module is not currently supported. As Windows Hello only supports TPM attestation it is necessary to disable attestation in order to register a device. This has security implications and means the model of TPM in use cannot be identified (this is one approach to verify a discrete hardware TPM).