[Webkit-unassigned] [Bug 243656] New: Safari WebAuthn sends Attestation as None when requested as Direct

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Aug 8 01:52:31 PDT 2022


https://bugs.webkit.org/show_bug.cgi?id=243656

            Bug ID: 243656
           Summary: Safari WebAuthn sends Attestation as None when
                    requested as Direct
           Product: WebKit
           Version: Safari 15
          Hardware: Mac (Intel)
                OS: Other
            Status: NEW
          Severity: Major
          Priority: P2
         Component: New Bugs
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: writetomansa at gmail.com

In Safari 15.6, if you set attestation as direct in navigator.credentials.create it sends backs attestation as none and aaguids as all zeroed out.
Since we mandate attestation in our enterprise services, It has become a blocker for new enrolments.


All works fine till 15.4. (Didn't check on 15.5)
MacOS - 12.5

Easily reproducible at https://webauthn.me/debugger

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20220808/83d31a88/attachment-0001.htm>


More information about the webkit-unassigned mailing list