Skip to main content

SID-AUTH-01 — FIDO2/WebAuthn Passwordless Authentication

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupAuthentication Controls

Description

All user authentication via FIDO2/WebAuthn (registration + login). Password-based authentication completely removed. Supports discoverable credentials (passkeys), platform authenticators, and roaming authenticators. Implements challenge-response with RP ID validation.

Components

  • Wallet Frontend
  • Wallet Backend (Go)

Source References

Audit Findings

FindingSeverityStatus
EN-S-4 — Partial wallet unit security and lifecyclemediumin progress
EN-P-5 — Partial user authentication and session controlshighin progress