4 ms·
Sorta, Client Certs but the Client generates and authenticates them, the Server only stores the fingerprint and authenticates them on it's side. And with a bet
by tscs37 8y ago
Sorta, Client Certs but the Client generates and authenticates them, the Server only stores the fingerprint and authenticates them on it's side.
And with a better UI and flow since you don't need it to establish connection.
- emlun 8y agoYeah, and a separate keypair is generated for each site.
- tmd83 8y agoLack of sleep makes it a bad time for me to read this. But if the client generates the key does it mean it's stored on the browser or something like that? It means that I will need a sync/copy procedure if I'm going to use it in another machine/browser?
- tscs37 8y agoEssentially yes. You'll need something like Firefox Sync or providers will have to implement a way of adding devices. However the WebAuthn API also leaves options for password managers and other endpoints managing the actual secrets.