{"id":2646,"date":"2025-04-09T18:53:11","date_gmt":"2025-04-10T01:53:11","guid":{"rendered":"https:\/\/self-issued.info\/?p=2646"},"modified":"2025-04-09T18:53:11","modified_gmt":"2025-04-10T01:53:11","slug":"finishing-the-openid-connect-eap-acr-values-specification","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2646","title":{"rendered":"Finishing the OpenID Connect EAP ACR Values specification"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" src=\"https:\/\/self-issued.info\/images\/openid-logo.png\" alt=\"OpenID logo\" \/><\/span>The <a href=\"https:\/\/openid.net\/specs\/openid-connect-eap-acr-values-1_0-03.html\">OpenID Connect Extended Authentication Profile (EAP) ACR Values 1.0<\/a> specification has started its <a href=\"https:\/\/openid.net\/public-review-period-for-proposed-final-eap-acr-values-specification\/\">60-day review<\/a> to become an OpenID Final Specification.  Recent steps leading up to this were:<\/p>\n<ul>\n<li>I added Context Class definitions to the Authentication Context Class Reference Values (&#8220;<code>acr<\/code>&#8221; values) defined by the specification, which enabled me to finally register them in the <a href=\"https:\/\/www.iana.org\/assignments\/loa-profiles\/loa-profiles.xhtml\">IANA &#8220;Level of Assurance (LoA) Profiles&#8221;<\/a> registry.  Doing so required me to create two XML Schema Description (XSD) files &#8211; something I never thought I&#8217;d have to do!  Thanks to <a href=\"https:\/\/www.linkedin.com\/in\/leifjohansson\/\">Leif Johansson<\/a> for explaining to me how to do that.<\/li>\n<li>A two-week Working Group Last Call (WGLC) for the specification was held in the <a href=\"http:\/\/openid.net\/wg\/eap\/\">OpenID Enhanced Authentication Profile (EAP) working group<\/a>.<\/li>\n<li>I added Security Considerations suggested by <a href=\"https:\/\/www.linkedin.com\/in\/adeinega\/\">Andrii Deinega<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/bcampbell\/\">Brian Campbell<\/a> during the WGLC.<\/li>\n<\/ul>\n<p>The specification is glue that ties together <a href=\"http:\/\/openid.net\/connect\/\">OpenID Connect<\/a>, <a href=\"https:\/\/www.w3.org\/TR\/2021\/REC-webauthn-2-20210408\/\">W3C Web Authentication<\/a>, and <a href=\"https:\/\/fidoalliance.org\/specs\/fido-v2.2-ps-20250228\/fido-client-to-authenticator-protocol-v2.2-ps-20250228.html\">FIDO Authenticators<\/a>, enabling them to be seamlessly used together.<\/p>\n<p>The two ACR values defined by the specification are:<\/p>\n<ul>\n<li><code>phr<\/code>:<br \/>\nPhishing-Resistant. An authentication mechanism where a party potentially under the control of the Relying Party cannot gain sufficient information to be able to successfully authenticate to the End User&#8217;s OpenID Provider as if that party were the End User. (Note that the potentially malicious Relying Party controls where the User-Agent is redirected to and thus may not send it to the End User&#8217;s actual OpenID Provider). NOTE: These semantics are the same as those specified in [<a href=\"https:\/\/openid.net\/specs\/openid-provider-authentication-policy-extension-1_0.html\">OpenID.PAPE<\/a>].<\/li>\n<li><code>phrh<\/code>:<br \/>\nPhishing-Resistant Hardware-Protected. An authentication mechanism meeting the requirements for phishing-resistant authentication above in which additionally information needed to be able to successfully authenticate to the End User&#8217;s OpenID Provider as if that party were the End User is held in a hardware-protected device or component.<\/li>\n<\/ul>\n<p>The Phishing-Resistant definition dates back 2008!<\/p>\n<p>For the record, the two XSD files that I wrote to get us here are:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.iana.org\/assignments\/loa-profiles\/phishing-resistant\/phishing-resistant.xsd\">phishing-resistant.xsd<\/a><\/li>\n<li><a href=\"https:\/\/www.iana.org\/assignments\/loa-profiles\/phishing-resistant-hardware\/phishing-resistant-hardware.xsd\">phishing-resistant-hardware.xsd<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The OpenID Connect Extended Authentication Profile (EAP) ACR Values 1.0 specification has started its 60-day review to become an OpenID Final Specification. Recent steps leading up to this were: I added Context Class definitions to the Authentication Context Class Reference Values (&#8220;acr&#8221; values) defined by the specification, which enabled me to finally register them in [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,19,25],"tags":[],"class_list":["post-2646","post","type-post","status-publish","format-standard","hentry","category-openid","category-phishing-resistance","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2646"}],"version-history":[{"count":2,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2646\/revisions"}],"predecessor-version":[{"id":2648,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2646\/revisions\/2648"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}