Enum AttestationTrustDiagnostic

java.lang.Object
java.lang.Enum<AttestationTrustDiagnostic>
io.jans.fido2.model.trust.AttestationTrustDiagnostic
All Implemented Interfaces:
Serializable, Comparable<AttestationTrustDiagnostic>, java.lang.constant.Constable

public enum AttestationTrustDiagnostic extends Enum<AttestationTrustDiagnostic>
Internal diagnostic codes for attestation rejections caused by a trust or metadata problem.

Without these, an unknown AAGUID, an authenticator blocked by an MDS status report and an untrusted root certificate are indistinguishable from each other — and from any other registration failure — once they reach the metrics store as free-text exception messages.

A code is written to Fido2MetricsEntry.errorReason, with CATEGORY as the error category, so rejections can be counted by cause. These are strictly internal: the public FIDO response envelope is unchanged and a code never reaches the client body.

Author:
Janssen Project
  • Enum Constant Details

    • JFS_AAGUID_NOT_IN_MDS

      public static final AttestationTrustDiagnostic JFS_AAGUID_NOT_IN_MDS
      The authenticator's AAGUID is not present in the loaded TOC entries.
    • JFS_MDS_METADATA_EXPIRED

      public static final AttestationTrustDiagnostic JFS_MDS_METADATA_EXPIRED
      The loaded TOC blob was past its nextUpdate when the authenticator was validated.
    • JFS_MDS_UNAVAILABLE

      public static final AttestationTrustDiagnostic JFS_MDS_UNAVAILABLE
      Metadata was required by the effective attestation mode, but none could be obtained.
    • JFS_ATTESTATION_FORMAT_NOT_PERMITTED

      public static final AttestationTrustDiagnostic JFS_ATTESTATION_FORMAT_NOT_PERMITTED
      The attestation statement format is not one the effective mode permits.
    • JFS_ROOT_CERT_NOT_TRUSTED

      public static final AttestationTrustDiagnostic JFS_ROOT_CERT_NOT_TRUSTED
      The attestation certificate chain did not verify to a trusted root.
    • JFS_APPLE_ROOT_CA_MISSING

      public static final AttestationTrustDiagnostic JFS_APPLE_ROOT_CA_MISSING
      Apple attestation was attempted while the Apple WebAuthn root CA is absent.
    • JFS_AUTHENTICATOR_STATUS_UNACCEPTABLE

      public static final AttestationTrustDiagnostic JFS_AUTHENTICATOR_STATUS_UNACCEPTABLE
      The authenticator is blocked by an MDS status report (revoked, compromised, and so on).
  • Field Details

    • CATEGORY

      public static final String CATEGORY
      Value written to Fido2MetricsEntry.errorCategory for every code in this enum.
      See Also:
    • CODE_PREFIX

      public static final String CODE_PREFIX
      Shared prefix for internal diagnostic codes, of which these are the attestation-trust subset.
      See Also:
  • Method Details

    • values

      public static AttestationTrustDiagnostic[] values()
      Returns an array containing the constants of this enum type, in the order they are declared.
      Returns:
      an array containing the constants of this enum type, in the order they are declared
    • valueOf

      public static AttestationTrustDiagnostic valueOf(String name)
      Returns the enum constant of this type with the specified name. The string must match exactly an identifier used to declare an enum constant in this type. (Extraneous whitespace characters are not permitted.)
      Parameters:
      name - the name of the enum constant to be returned.
      Returns:
      the enum constant with the specified name
      Throws:
      IllegalArgumentException - if this enum type has no constant with the specified name
      NullPointerException - if the argument is null
    • isDiagnosticCode

      public static boolean isDiagnosticCode(String errorReason)
      Whether a recorded errorReason is one of these diagnostic codes.

      Deliberately matched against the enum values rather than the shared CODE_PREFIX: the native-metrics work writes its own JFS_ codes into the same errorReason field, and a prefix test would file those under CATEGORY too — quietly inflating the attestation-rejection analytics with rejections that have nothing to do with attestation trust.

      Parameters:
      errorReason - the recorded reason; may be null
      Returns:
      true when the reason is an attestation-trust diagnostic code