Skip to content

[v13] Record and verify WebAuthn RPIDs#25282

Merged
zmb3 merged 8 commits intobranch/v13from
bot/backport-25238-branch/v13
Apr 28, 2023
Merged

[v13] Record and verify WebAuthn RPIDs#25282
zmb3 merged 8 commits intobranch/v13from
bot/backport-25238-branch/v13

Conversation

@codingllama
Copy link
Copy Markdown
Contributor

Record and verify the credential RPID in WebauthnDevice, so we can detect and warn against accidental RPID changes.

RPID changes are not allowed by WebAuthn, so there's little Teleport can do to mitigate them.

Users that have only "invalid" WebAuthn devices will get "invalid credentials" errors on login. While a bit opaque, this is likely to lead to an user reset, which is the correct fix if only a few users are affected.

Backport #25238 to branch/v13

@zmb3 zmb3 added this pull request to the merge queue Apr 28, 2023
Merged via the queue into branch/v13 with commit 44b3be1 Apr 28, 2023
@zmb3 zmb3 deleted the bot/backport-25238-branch/v13 branch April 28, 2023 14:11
@r0mant r0mant mentioned this pull request Jul 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants