Yubico Forum
https://forum.yubico.com/

[SOLVED] What do I do with this certificate?
https://forum.yubico.com/viewtopic.php?f=33&t=1662
Page 1 of 1

Author:  tlockley [ Tue Dec 16, 2014 6:36 pm ]
Post subject:  [SOLVED] What do I do with this certificate?

Been playing with a U2F NEO and so far everything is making sense except for this certificate I get back when I complete a registration. Is that the attestation certificate for my device or something else?

I ask because I am unsure where it gets used, if at all and why I would want to keep it.

Author:  darco [ Tue Dec 16, 2014 7:24 pm ]
Post subject:  Re: [QUESTION] What do I do with this certificate?

Short answer: Ignore it.

Long answer: It is used to verify the service that a device was manufactured by a specific manufacturer in a specific batch. It is generally only interesting to very paranoid companies. It is not really useful information for end users, and most non-debug implementations should hide it from view. All consumer U2F tokens do not use the attestation certificate to uniquely identify the device (for privacy reasons), so the private key for the attestation certificate (not to be confused with the "device master secret", which is unique to each device) is shared by batches of tokens.

Author:  tlockley [ Tue Dec 16, 2014 8:13 pm ]
Post subject:  Re: [QUESTION] What do I do with this certificate?

Thanks for the info. I was figuring that was the case with the "extra" certificate, but I could never find a solid explanation in the spec documents.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/