There is no current certification for passkey providers. Platforms do not restrict passkey providers. If you’re having issues, there is likely an issue with your provider.
You do not have to be certified to be listed in MDS; follow the instructions here: https://fidoalliance.org/metadata/
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
[email protected].
To view this discussion visit
https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/79e6d8a2-e091-43f1-b9bd-b2c42885134cn%40fidoalliance.org.
Hi All,
Please get in touch with [email protected] for more information on in-development certification programs related to Passkey Providers.
Thank you,
Paul
Paul Heim | Certification Director | FIDO Alliance
Hi All,
Please get in touch with [email protected] for more information on in-development certification programs related to Passkey Providers.
Thank you,
Paul
Paul Heim | Certification Director | FIDO Alliance
From: 'Tim Cappalli' via FIDO Dev (fido-dev) <[email protected]>
Sent: Wednesday, May 14, 2025 8:15 AM
To: Aravinth Vj <[email protected]>; FIDO Dev (fido-dev) <[email protected]>
Subject: Re: [FIDO-DEV] Steps to get fido certify my software-based passkey authenticator
There is no current certification for passkey providers. Platforms do not restrict passkey providers. If you’re having issues, there is likely an issue with your provider.
You do not have to be certified to be listed in MDS; follow the instructions here: https://fidoalliance.org/metadata/
From: [email protected] <[email protected]> on behalf of Aravinth Vj <[email protected]>
Date: Wednesday, May 14, 2025 at 11:09
To: FIDO Dev (fido-dev) <[email protected]>
Subject: [FIDO-DEV] Steps to get fido certify my software-based passkey authenticatorHi Everyone,
I'm new to passkeys and have been developing a software-based passkey authenticator to get integrated into our solution. I was able to make it work on some test websites and a few other websites which accepts self-attestation certificates and still struggling to make it work on major platforms like google. so can anyone explain the steps in obtaining a proper attestation certificate and make my solution a fido trusted(MDS.) if anyone has already been through the process. Thanks in advance
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
Further to add to Arshad's answer, I have been working on developing malicious security keys that can exfiltrate your cryptographic secrets when used. (Just a PoC for a research project but it works). https://github.com/AdityaMitra5102/Evil-FIDO-Key
And there are cases where the RP does not validate the attestation. Google being the biggest example. And I have been able to compromise test users using the same.
Telling from the experience of a red teamer, verifying attestation is very very important.
Aditya
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/f95968ca-9fe4-4041-9015-529737dab633%40strongkey.com.
You're right, there is no current certification requirement for passkey providers to be listed in the FIDO Alliance's Metadata Service (MDS). Providers can follow the instructions on the FIDO Alliance website to get listed. If issues arise, it's likely related to the provider's implementation.
To get a FIDO attestation certificate for your passkey authenticator:
1. Choose a trusted Certification Authority (CA) like Google, Apple, or Microsoft.
2. Meet FIDO conformance requirements and pass testing/certification.
3. Request an attestation certificate from the CA.
4. Create and submit a Metadata Statement (MDS) to the FIDO Alliance.
5. Integrate with major platforms and test for compatibility.Collaborate with experts and utilize FIDO Alliance resources for guidance.
On Thu, May 15, 2025, 10:48 AM Aravinth Vj <[email protected]> wrote:
so, I guess all I need to do now is to get listed in mds with my aaguid(my solution works fine in many websites which accepts none or self-signed certificates for attestation like accounts@microsoft,github,discord... just not the ones that validates the authenticity with mds like google) Am i right? . and also do i need to have my certificate signed by a CA.
On Wednesday, May 14, 2025 at 11:50:06 PM UTC+5:30 Paul Heim wrote:
Hi All,
Please get in touch with [email protected] for more information on in-development certification programs related to Passkey Providers.
Thank you,
Paul
Paul Heim | Certification Director | FIDO Alliance
From: 'Tim Cappalli' via FIDO Dev (fido-dev) <[email protected]>
Sent: Wednesday, May 14, 2025 8:15 AM
To: Aravinth Vj <[email protected]>; FIDO Dev (fido-dev) <[email protected]>
Subject: Re: [FIDO-DEV] Steps to get fido certify my software-based passkey authenticator
There is no current certification for passkey providers. Platforms do not restrict passkey providers. If you’re having issues, there is likely an issue with your provider.
You do not have to be certified to be listed in MDS; follow the instructions here: https://fidoalliance.org/metadata/
From: [email protected] <[email protected]> on behalf of Aravinth Vj <[email protected]>
Date: Wednesday, May 14, 2025 at 11:09
To: FIDO Dev (fido-dev) <[email protected]>
Subject: [FIDO-DEV] Steps to get fido certify my software-based passkey authenticatorHi Everyone,
I'm new to passkeys and have been developing a software-based passkey authenticator to get integrated into our solution. I was able to make it work on some test websites and a few other websites which accepts self-attestation certificates and still struggling to make it work on major platforms like google. so can anyone explain the steps in obtaining a proper attestation certificate and make my solution a fido trusted(MDS.) if anyone has already been through the process. Thanks in advance
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/e0de864b-684c-4650-8304-cb202a1abd6en%40fidoalliance.org.
To get a FIDO attestation certificate for your passkey authenticator:
1. Choose a trusted Certification Authority (CA) like Google, Apple, or Microsoft.
2. Meet FIDO conformance requirements and pass testing/certification.
3. Request an attestation certificate from the CA.
4. Create and submit a Metadata Statement (MDS) to the FIDO Alliance.
5. Integrate with major platforms and test for compatibility.
Collaborate with experts and utilize FIDO Alliance resources for guidance.
so, I guess all I need to do now is to get listed in mds with my aaguid(my solution works fine in many websites which accepts none or self-signed certificates for attestation like accounts@microsoft,github,discord... just not the ones that validates the authenticity with mds like google) Am i right? . and also do i need to have my certificate signed by a CA.
On Wednesday, May 14, 2025 at 11:50:06 PM UTC+5:30 Paul Heim wrote:
Hi All,
Please get in touch with [email protected] for more information on in-development certification programs related to Passkey Providers.
Thank you,
Paul
Paul Heim | Certification Director | FIDO Alliance
From: 'Tim Cappalli' via FIDO Dev (fido-dev) <[email protected]>
Sent: Wednesday, May 14, 2025 8:15 AM
To: Aravinth Vj <[email protected]>; FIDO Dev (fido-dev) <[email protected]>
Subject: Re: [FIDO-DEV] Steps to get fido certify my software-based passkey authenticator
There is no current certification for passkey providers. Platforms do not restrict passkey providers. If you’re having issues, there is likely an issue with your provider.
You do not have to be certified to be listed in MDS; follow the instructions here: https://fidoalliance.org/metadata/
From: [email protected] <[email protected]> on behalf of Aravinth Vj <[email protected]>
Date: Wednesday, May 14, 2025 at 11:09
To: FIDO Dev (fido-dev) <[email protected]>
Subject: [FIDO-DEV] Steps to get fido certify my software-based passkey authenticatorHi Everyone,
I'm new to passkeys and have been developing a software-based passkey authenticator to get integrated into our solution. I was able to make it work on some test websites and a few other websites which accepts self-attestation certificates and still struggling to make it work on major platforms like google. so can anyone explain the steps in obtaining a proper attestation certificate and make my solution a fido trusted(MDS.) if anyone has already been through the process. Thanks in advance
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/e0de864b-684c-4650-8304-cb202a1abd6en%40fidoalliance.org.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/CACHSkNo6Y0k2MHXeFJ86HPZXP6YmPzAUQM%3DkqwjJu_sA%3DE1kkg%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
On 19 May 2025, at 4:27 pm, Aravinth Vj <[email protected]> wrote:
As a follow up question, since I want my solution to work on RP that validate certificate for CA signing. Can anyone point me towards a CA who can actually sign my attestation certificate because I approached DigiCert and they said they can't do it (or maybe the person didn't understand my request).
--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].