Package io.jans.fido2.model.trust
Class AttestationTrustConfig
java.lang.Object
io.jans.fido2.model.trust.AttestationTrustConfig
Read-only view of the attestation policy the server is actually enforcing. Lets an administrator see
whether a strict mode is the reason certain authenticators are being rejected, instead of that
surfacing to end users as a generic registration failure.
- Author:
- Janssen Project
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionThe configured attestation mode, verbatim.getHints()booleanWhether the Apple WebAuthn root CA was loaded at startup.booleanWhether the configured value matches one of the supported modes (disabled / monitor / enforced).booleanbooleanWhen true, MDS download and validation are switched off and attestation cannot be validated against FIDO metadata.booleanWhether an authenticator that fails attestation validation is still accepted.voidsetAppleRootCaPresent(boolean appleRootCaPresent) voidsetAttestationMode(String attestationMode) voidsetAttestationModeRecognized(boolean attestationModeRecognized) voidsetEnabledFidoAlgorithms(List<String> enabledFidoAlgorithms) voidsetEnterpriseAttestation(boolean enterpriseAttestation) voidvoidsetMetadataServiceDisabled(boolean metadataServiceDisabled) voidsetUnattestedAuthenticatorsAllowed(boolean unattestedAuthenticatorsAllowed) toString()
-
Constructor Details
-
AttestationTrustConfig
public AttestationTrustConfig()
-
-
Method Details
-
getAttestationMode
The configured attestation mode, verbatim. Reported as configured rather than normalized so an administrator can see a typo for what it is. -
setAttestationMode
-
isAttestationModeRecognized
public boolean isAttestationModeRecognized()Whether the configured value matches one of the supported modes (disabled / monitor / enforced). When false the server falls back to lenient behaviour, which is otherwise invisible. -
setAttestationModeRecognized
public void setAttestationModeRecognized(boolean attestationModeRecognized) -
isUnattestedAuthenticatorsAllowed
public boolean isUnattestedAuthenticatorsAllowed()Whether an authenticator that fails attestation validation is still accepted. True for every mode exceptenforced— only that mode applies the stricter MDS trust rules. -
setUnattestedAuthenticatorsAllowed
public void setUnattestedAuthenticatorsAllowed(boolean unattestedAuthenticatorsAllowed) -
isEnterpriseAttestation
public boolean isEnterpriseAttestation() -
setEnterpriseAttestation
public void setEnterpriseAttestation(boolean enterpriseAttestation) -
isMetadataServiceDisabled
public boolean isMetadataServiceDisabled()When true, MDS download and validation are switched off and attestation cannot be validated against FIDO metadata. -
setMetadataServiceDisabled
public void setMetadataServiceDisabled(boolean metadataServiceDisabled) -
isAppleRootCaPresent
public boolean isAppleRootCaPresent()Whether the Apple WebAuthn root CA was loaded at startup. When false, Apple anonymous attestation cannot be validated. -
setAppleRootCaPresent
public void setAppleRootCaPresent(boolean appleRootCaPresent) -
getEnabledFidoAlgorithms
-
setEnabledFidoAlgorithms
-
getHints
-
setHints
-
toString
-