From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id AF7C76C299 for ; Mon, 22 Feb 2021 10:43:04 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 9B6B22D313 for ; Mon, 22 Feb 2021 10:43:04 +0100 (CET) Received: from proxmox-new.maurer-it.com (proxmox-new.maurer-it.com [212.186.127.180]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS id 05C3A2D2EE for ; Mon, 22 Feb 2021 10:43:03 +0100 (CET) Received: from proxmox-new.maurer-it.com (localhost.localdomain [127.0.0.1]) by proxmox-new.maurer-it.com (Proxmox) with ESMTP id BBA20447F3 for ; Mon, 22 Feb 2021 10:43:02 +0100 (CET) From: Dominik Csapak To: pbs-devel@lists.proxmox.com Date: Mon, 22 Feb 2021 10:42:58 +0100 Message-Id: <20210222094301.13858-1-d.csapak@proxmox.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL 0.212 Adjusted score from AWL reputation of From: address KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Subject: [pbs-devel] [PATCH proxmox-backup 0/3] improving webauthn handling X-BeenThere: pbs-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox Backup Server development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 22 Feb 2021 09:43:04 -0000 it seems my gui patch for setting the userverification was a bit hasty, since the rust crate has some options for that this series reverts the gui part, and sets the backend to 'discourage' userVerification, since 'Preferred' is not more secure and makes logging in harder (on some devices) in the future (when [0] is solved), we could expose a server setting (either per instance or per user) that sets either always 'Discouraged' or 'Required' 0: https://github.com/kanidm/webauthn-rs/pull/49 Dominik Csapak (3): config/tfa: set UserVerificationPolicy to Discouraged Revert "ui: window/Settings / WebAuthn: add browser setting for userVerificationo" config/tfa: webauthn: disallow registering a token twice src/config/tfa.rs | 19 ++++++++++++++++--- www/LoginView.js | 5 ----- www/window/AddWebauthn.js | 14 +++++++------- www/window/Settings.js | 30 +----------------------------- 4 files changed, 24 insertions(+), 44 deletions(-) -- 2.20.1