View Source Wax.Metadata (wax_ v0.6.5)

Link to this section Summary

Types

A metadata statement

Functions

Returns a specification to start this module under a supervisor.

Returns the metadata associated to an AAGUID

Returns the metadata associated to an attestation certificate key identifier (ACKI)

Forces reload of metadata statements from configured directory

Link to this section Types

@type statement() :: %{optional(String.t()) => any()}

A metadata statement

For instance:

%{
  "aaguid" => "2c0df832-92de-4be1-8412-88a8f074df4a",
  "attachmentHint" => ["external", "wireless", "nfc"],
  "attestationRootCertificates" => ["MIIB2DCCAX6gAwIBAgIQGBUrQbdDrm20FZnDsX2CBTAKBggqhkjOPQQDAjBLMQswCQYDVQQGEwJVUzEdMBsGA1UECgwURmVpdGlhbiBUZWNobm9sb2dpZXMxHTAbBgNVBAMMFEZlaXRpYW4gRklETyBSb290IENBMCAXDTE4MDQwMTAwMDAwMFoYDzIwNDgwMzMxMjM1OTU5WjBLMQswCQYDVQQGEwJVUzEdMBsGA1UECgwURmVpdGlhbiBUZWNobm9sb2dpZXMxHTAbBgNVBAMMFEZlaXRpYW4gRklETyBSb290IENBMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEsFYEEhiJuqqnMgQjSiivBjV7DGCTf4XBBH/B7uvZsKxXShF0L8uDISWUvcExixRs6gB3oldSrjox6L8T94NOzqNCMEAwHQYDVR0OBBYEFEu9hyYRrRyJzwRYvnDSCIxrFiO3MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMAoGCCqGSM49BAMCA0gAMEUCIDHSb2mbNDAUNXvpPU0oWKeNye0fQ2l9D01AR2+sLZdhAiEAo3wz684IFMVsCCRmuJqxH6FQRESNqezuo1E+KkGxWuM=",
   "MIIBfjCCASWgAwIBAgIBATAKBggqhkjOPQQDAjAXMRUwEwYDVQQDDAxGVCBGSURPIDAyMDAwIBcNMTYwNTAxMDAwMDAwWhgPMjA1MDA1MDEwMDAwMDBaMBcxFTATBgNVBAMMDEZUIEZJRE8gMDIwMDBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABNBmrRqVOxztTJVN19vtdqcL7tKQeol2nnM2/yYgvksZnr50SKbVgIEkzHQVOu80LVEE3lVheO1HjggxAlT6o4WjYDBeMB0GA1UdDgQWBBRJFWQt1bvG3jM6XgmV/IcjNtO/CzAfBgNVHSMEGDAWgBRJFWQt1bvG3jM6XgmV/IcjNtO/CzAMBgNVHRMEBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAKBggqhkjOPQQDAgNHADBEAiAwfPqgIWIUB+QBBaVGsdHy0s5RMxlkzpSX/zSyTZmUpQIgB2wJ6nZRM8oX/nA43Rh6SJovM2XwCCH//+LirBAbB0M=",
   "MIIB2DCCAX6gAwIBAgIQFZ97ws2JGPEoa5NI+p8z1jAKBggqhkjOPQQDAjBLMQswCQYDVQQGEwJDTjEdMBsGA1UECgwURmVpdGlhbiBUZWNobm9sb2dpZXMxHTAbBgNVBAMMFEZlaXRpYW4gRklETyBSb290IENBMCAXDTE4MDQwMTAwMDAwMFoYDzIwNDgwMzMxMjM1OTU5WjBLMQswCQYDVQQGEwJDTjEdMBsGA1UECgwURmVpdGlhbiBUZWNobm9sb2dpZXMxHTAbBgNVBAMMFEZlaXRpYW4gRklETyBSb290IENBMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEnfAKbjvMX1Ey1b6k+WQQdNVMt9JgGWyJ3PvM4BSK5XqTfo++0oAj/4tnwyIL0HFBR9St+ktjqSXDfjiXAurs86NCMEAwHQYDVR0OBBYEFNGhmE2Bf8O5a/YHZ71QEv6QRfFUMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMAoGCCqGSM49BAMCA0gAMEUCIQC3sT1lBjGeF+xKTpzV1KYU2ckahTd4mLJyzYOhaHv4igIgD2JYkfyH5Q4Bpo8rroO0It7oYjF2kgy/eSZ3U9Glaqw="],
  "attestationTypes" => ["basic_full"],
  "authenticationAlgorithms" => ["secp256r1_ecdsa_sha256_raw"],
  "authenticatorGetInfo" => %{
    "aaguid" => "2c0df83292de4be1841288a8f074df4a",
    "algorithms" => [%{"alg" => -7, "type" => "public-key"}],
    "extensions" => ["credProtect", "hmac-secret"],
    "maxCredentialCountInList" => 6,
    "maxCredentialIdLength" => 96,
    ...
  },
  "authenticatorVersion" => 1,
  "cryptoStrength" => 128,
  "description" => "Feitian FIDO Smart Card",
  "icon" => "",
  "keyProtection" => [...],
  # ...
}

Link to this section Functions

Returns a specification to start this module under a supervisor.

See Supervisor.

Link to this function

get_by_aaguid(aaguid_bin, challenge \\ nil)

View Source
@spec get_by_aaguid(binary(), Wax.Challenge.t() | nil) ::
  {:ok, statement()} | {:error, Exception.t()}

Returns the metadata associated to an AAGUID

The aaguid parameter is the raw form of the AAGUID, for example <<44, 13, 248, 50, 146, 222, 75, 225, 132, 18, 136, 168, 240, 116, 223, 74>> and not the base-16 encoded form such as "2c0df832-92de-4be1-8412-88a8f074df4a".

If the metadata is not found, {:error, %Wax.MetadataStatementNotFoundError{}} is returned.

If a challenge is passed as the second parameter, this function verifies that the status of the authenticator is accepted (by default, non-certified and revoked authenticator are refused). If the authenticator status is not accepted, {:error, %Wax.AuthenticatorStatusNotAcceptableError{}} is returned.

Link to this function

get_by_acki(acki_bin, challenge \\ nil)

View Source
@spec get_by_acki(binary(), Wax.Challenge.t() | nil) ::
  {:ok, statement()} | {:error, Exception.t()}

Returns the metadata associated to an attestation certificate key identifier (ACKI)

The acki parameter is the raw form of the ACKI, for example <<138, 39, 205, 218, 234, 197, 118, 90, 141, 238, 146, 165, 237, 73, 131, 217, 56, 165, 234, 105>> and not the base-16 encoded form such as "8a27cddaeac5765a8dee92a5ed4983d938a5ea69".

If the metadata is not found, {:error, %Wax.MetadataStatementNotFoundError{}} is returned.

If a challenge is passed as the second parameter, this function verifies that the status of the authenticator is accepted (by default, non-certified and revoked authenticator are refused). If the authenticator status is not accepted, {:error, %Wax.AuthenticatorStatusNotAcceptableError{}} is returned.

@spec load_from_dir() :: [statement()]

Forces reload of metadata statements from configured directory