We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

Enabling FIDO2/WebAuthn support for remotely managed users

Formal Metadata

Title
Enabling FIDO2/WebAuthn support for remotely managed users
Title of Series
Number of Parts
542
Author
Contributors
License
CC Attribution 2.0 Belgium:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
Passwordless and multi-factor authentication (MFA) are becoming a trend and their usage will increase in the near future. However, most of the solutions target the web/online pattern, or the local users, thus leaving centralized identity management for console and POSIX system applications lacking those capabilities. For the last year FreeIPA and SSSD have been working on enabling FIDO2/WebAuthn support for remotely managed users. One part of it is enabling a user stored in a LDAP server to locally authenticate in a system using a FIDO2 key. Another part is to use FIDO2 authentication to obtain a Kerberos ticket. This opens a new world to organizations to tighten their security, while maintaining strict control as to who access their systems. This talk will focus on the progress in FIDO2/WebAuthn authentication in SSSD by providing the implementation state, the solution details and a demo. Additional information on the possible expansion of the solution will also be provided.