CollectedClientData and rpId are currently hashed using SHA-256. This is static with no agility.
SHA-256 is not approved for general hashing use in CNSA 2.0.
Potential options:
- Request a formal exception in CNSA 2.X for WebAuthn's use of SHA-256 for clientData and rpId
- @ve7jtb is proposing a signed extension that can carry one or more hashes (SHA-384, SHA-512, etc)
- Others?
CollectedClientDataandrpIdare currently hashed using SHA-256. This is static with no agility.SHA-256 is not approved for general hashing use in CNSA 2.0.
Potential options: