Version Affected: All
Overview
After configuring a FIDO enrollment realm in the New Experience, enrolling a FIDO device can fail with the following error:
Cause
This happens when the Authenticator Type reported by the FIDO authenticator itself is not one of the Authenticator Type options selected in the FIDO enrollment realm's Advanced Settings. For example, the realm below has Cross platform and Platform (TPM) selected under Authenticator Type, which allows enrollment from authenticators such as YubiKeys and Windows Hello, but not Unspecified:
If the authenticator instead reports an Authenticator Type of Unspecified, and Unspecified is not selected in the realm configuration, enrollment fails with the error above. Identity Platform cannot influence which Authenticator Type a given authenticator reports back, and limiting the realm to only Cross platform and Platform (TPM) authenticators may be too restrictive for some deployments.
Resolution
Select the Unspecified Authenticator Type in addition to Cross platform and Platform (TPM) in the FIDO enrollment realm's Advanced Settings:
This allows enrollment to complete as expected in most cases, even when an authenticator reports an Unspecified Authenticator Type.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.