Class AttestationTrustConfig

java.lang.Object
io.jans.fido2.model.trust.AttestationTrustConfig

public class AttestationTrustConfig extends Object
Read-only view of the attestation policy the server is actually enforcing. Lets an administrator see whether a strict mode is the reason certain authenticators are being rejected, instead of that surfacing to end users as a generic registration failure.
Author:
Janssen Project
  • Constructor Details

    • AttestationTrustConfig

      public AttestationTrustConfig()
  • Method Details

    • getAttestationMode

      public String getAttestationMode()
      The configured attestation mode, verbatim. Reported as configured rather than normalized so an administrator can see a typo for what it is.
    • setAttestationMode

      public void setAttestationMode(String attestationMode)
    • isAttestationModeRecognized

      public boolean isAttestationModeRecognized()
      Whether the configured value matches one of the supported modes (disabled / monitor / enforced). When false the server falls back to lenient behaviour, which is otherwise invisible.
    • setAttestationModeRecognized

      public void setAttestationModeRecognized(boolean attestationModeRecognized)
    • isUnattestedAuthenticatorsAllowed

      public boolean isUnattestedAuthenticatorsAllowed()
      Whether an authenticator that fails attestation validation is still accepted. True for every mode except enforced — only that mode applies the stricter MDS trust rules.
    • setUnattestedAuthenticatorsAllowed

      public void setUnattestedAuthenticatorsAllowed(boolean unattestedAuthenticatorsAllowed)
    • isEnterpriseAttestation

      public boolean isEnterpriseAttestation()
    • setEnterpriseAttestation

      public void setEnterpriseAttestation(boolean enterpriseAttestation)
    • isMetadataServiceDisabled

      public boolean isMetadataServiceDisabled()
      When true, MDS download and validation are switched off and attestation cannot be validated against FIDO metadata.
    • setMetadataServiceDisabled

      public void setMetadataServiceDisabled(boolean metadataServiceDisabled)
    • isAppleRootCaPresent

      public boolean isAppleRootCaPresent()
      Whether the Apple WebAuthn root CA was loaded at startup. When false, Apple anonymous attestation cannot be validated.
    • setAppleRootCaPresent

      public void setAppleRootCaPresent(boolean appleRootCaPresent)
    • getEnabledFidoAlgorithms

      public List<String> getEnabledFidoAlgorithms()
    • setEnabledFidoAlgorithms

      public void setEnabledFidoAlgorithms(List<String> enabledFidoAlgorithms)
    • getHints

      public List<String> getHints()
    • setHints

      public void setHints(List<String> hints)
    • toString

      public String toString()
      Overrides:
      toString in class Object