3 ms·
They mention Yubikey a lot by name in the post. Has anyone tried a U2F device from a different manufacturer?
by mimming 8y ago
They mention Yubikey a lot by name in the post. Has anyone tried a U2F device from a different manufacturer?
- robbiet480 8y agoThey specifically only support YubiCo at the moment, to the point that Chrome asked me if AWS could read my Security Key manufacturer and model when I pressed the button on my 4C Nano.
- pg_bot 8y agoThe manufacturer is irrelevant to the protocol, they may have asked you for these details but they do not matter. You can even emulate the key in software if you wanted.
- robbiet480 8y agoYeah I knew that it didn't matter to the protocol, I only made my comment because I could've absolutely sworn I read in docs or their UI that literally _only_ YubiCo was supported, as in no other U2F would work. Can't find it now, so my bad!
- jiveturkey 8y agoIt does matter. You need an attested cert which only yubico can provide.
- pg_bot 8y agoIncorrect - everything related to the protocol, including becoming a compatible vendor, is managed by the fido alliance which Yubico is a member of. The U2F specification requires you to parse the certificate, and verify the response message against the cert's public key when registering the device with your application. You can choose to only accept certificates whose public key comes from a certain manufacturer, but that is up to the discretion of the implementer and is not required. If you want to read a full overview of the specification you can read the following document https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/fido-u2f-overview-v1.2-ps-20170411.pdf https://fidoalliance.org/specs/fido-u2f-v1.2-ps-20170411/fid...
- Buge 8y agoJust because the protocol allows websites to accept all manufacturers doesn't mean AWS accepts all manufacturers.
- rthille 8y agoIt's not the manufacturer that AWS wants to read, it wants the attestation certificate, and Yubico's are signed with their Root CA, so it's not something you can emulate. https://developers.yubico.com/U2F/Attestation_and_Metadata/ https://developers.yubico.com/U2F/Attestation_and_Metadata/ I tried setting up my AWS account with a Tomu setup with U2F firmware and AWS rejected it.
- ecesena 8y agoWe just tried with a self-signed attestation certificate and it doesn't work.
- rendaw 8y agoI tried a Trezor 1. It prompts me to press the button, but then the browser prompts me to give permission for AWS to see the manufacturer/version of the device and then gives me the error "Attestation Certificate is not valid." The link to "see information about supported configurations" is 404: https://docs.aws.amazon.com/iam/mfa-u2f-config https://docs.aws.amazon.com/iam/mfa-u2f-config
- mimming 8y agoAw, that's a bummer. First Vanguard and now AWS support only Yubikey brand U2F devices. I wonder why that's happening? Hopefully this practice remains limited. I really don't want haul a bag of different security keys around with me to access all of my services.