WebAuthn (Passkey)

CanoKey supports the WebAuthn (passkey) authentication protocol through the CTAP specification.

CTAP Version Support

CTAP Version Firmware Requirement
CTAP 2.0 All versions
CTAP 2.1 Firmware 2.0.0 and later

Features

Supported features include:

  • Discoverable Credentials (Resident Keys)
  • HMAC extensions
  • Ed25519 algorithm

Firmware version 2.0.0 adds:

  • Discoverable Credentials management
  • PIN Protocol 2
  • credProtect, credBlob, and largeBlobKey extensions
  • Large Blob

Firmware version 3.0.0 adds:

  • SM2 algorithm

Firmware version 3.0.0 does not support U2F, WebAuthn over USB on iOS 17.4 and 18, or WebAuthn on macOS, including Safari, Firefox, and applications that rely on Apple’s CTAP stack. Firmware version 3.0.2 and later are not affected by these limitations.

Multi-Factor Authentication

CanoKey can be used for two-factor authentication on many websites.

By default, CanoKey does not set a PIN. Some websites and certain features (such as Discoverable Credentials management) require you to set a PIN. Please set it when prompted.

In This Chapter

  • PIN — PIN setup and PIN Protocol 2.
  • Credentials — Discoverable Credentials, credential management, and related extensions.
  • Reset — resetting the WebAuthn application and its consequences.
  • SSH — using FIDO keys (ecdsa-sk / ed25519-sk) for OpenSSH authentication.
  • PAM — PAM authentication with pam-u2f.
  • HMAC-secret Extension — LUKS full-disk encryption with systemd-cryptenroll.