Hi Marek,
I think the differentiation between “Strong WebAuthn policy” and just “WebAuthn policy” is not very clear.
“Passwordless WebAuthn policy” more clearly conveys what this is used for (or is there a case where this would be combined with password login?).
Maybe the standard “WebAuthn policy” could even be called “Second factor WebAuthn policy” or “Additional Factor WebAuthn policy”.
On the other hand, the alternatives might be a little long in the UI…
Best regards,
Sebastian
Mit freundlichen Grüßen / Best regards
Dr.-Ing. Sebastian Schuster
Open Source Services (INST-CSS/BSV-OS2)
Bosch Software Innovations GmbH | Ullsteinstr. 128 | 12109 Berlin |
GERMANY | www.bosch-si.com
Tel. +49 30 726112-485 | Mobil +49 152 02177668 | Telefax +49 30 726112-100 |
Sebastian...@bosch-si.com
Sitz: Berlin, Registergericht: Amtsgericht Charlottenburg; HRB 148411 B
Aufsichtsratsvorsitzender: Dr.-Ing. Thorsten Lücke; Geschäftsführung: Dr. Stefan Ferber, Michael Hahn, Dr. Aleksandar Mitrovic
--
You received this message because you are subscribed to the Google Groups "Keycloak Dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
keycloak-dev...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/keycloak-dev/e8ba395a-b0c8-422c-8dd1-c941944046b4%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-dev/a8d8456861c0425293a5cf07a2a5b74d%40bosch-si.com.
I'd got with "WebAuthn Passwordless" and "WebAuthn Second Factor" - "Strong" doesn't really describe anything and can be confusing
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-dev/CAJgngAfuvXJEhaZhGZ98s7PzvphKhNh5LZrpwBR5gQXFn50Vcw%40mail.gmail.com.
+1On Thu, 9 Jan 2020 at 11:11, Marek Posolda <mpos...@redhat.com> wrote:Yes, fact is that it will be nice to avoid migration.
So we can keep the current "WebAuthn policy" (and authenticator and requiredAction) as is and just introduce new stuff for passwordless. So introduce something like this:
Policy: WebAuthn Passwordless Policy
Required action: WebAuthn Register PasswordlessAuthenticator: WebAuthn Passwordless Authenticator
We may just need to document that "WebAuthn Policy" is primarily useful for two-factor authentication and "WebAuthn Passwordless Policy" is primarily used for passwordless /1st factor authentication.
Sounds ok?
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-dev/CAJgngAenPn4%3D9AzZ--T46-ymSfBYfZtpP5DnDrvmGN98Erz8_Q%40mail.gmail.com.
Hello,
I’ll try to review these code PR and docs PR.
Regards,
Takashi Norimatsu
Hitachi, Ltd.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-dev/a49cb1d0-f7cf-0ea7-27ad-29f5eeed9460%40redhat.com.
Sounds good to me.
Best regards,
Sebastian
Mit freundlichen Grüßen / Best regards
Dr.-Ing. Sebastian Schuster
Open Source Services (INST-CSS/BSV-OS2)
Bosch Software Innovations GmbH | Ullsteinstr. 128 | 12109 Berlin |
GERMANY | www.bosch-si.com
Tel. +49 30 726112-485 | Mobil +49 152 02177668 | Telefax +49 30 726112-100 |
Sebastian...@bosch-si.com
Sitz: Berlin, Registergericht: Amtsgericht Charlottenburg; HRB 148411 B
Aufsichtsratsvorsitzender: Dr.-Ing. Thorsten Lücke; Geschäftsführung: Dr. Stefan Ferber, Michael Hahn, Dr. Aleksandar Mitrovic
Hello,
I’ll try to review these code PR and docs PR.
Regards,
Takashi Norimatsu
Hitachi, Ltd.
From: keyclo...@googlegroups.com <keyclo...@googlegroups.com> On Behalf Of Marek Posolda
Sent: Friday, January 10, 2020 3:07 AM
To: Jan Lieskovsky <jlie...@redhat.com>; Stian Thorgersen <st...@redhat.com>
Cc: Schuster Sebastian (INST-CSS/BSV-OS2) <Sebastian...@bosch-si.com>; Keycloak Dev <keyclo...@googlegroups.com>
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-dev/a49cb1d0-f7cf-0ea7-27ad-29f5eeed9460%40redhat.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-dev/CAPr-%2BaEFKQJr%3DM21SX6TNiKSra_e%3DD2RP8H4SjeO3qiWtoNggA%40mail.gmail.com.