{"id":2726,"date":"2025-06-17T08:22:58","date_gmt":"2025-06-17T15:22:58","guid":{"rendered":"https:\/\/self-issued.info\/?p=2726"},"modified":"2025-06-17T08:22:58","modified_gmt":"2025-06-17T15:22:58","slug":"final-openid-connect-eap-acr-values-specification","status":"publish","type":"post","link":"https:\/\/self-issued.info\/?p=2726","title":{"rendered":"Final OpenID Connect EAP ACR Values Specification"},"content":{"rendered":"<p><span class=\"plain\"><img decoding=\"async\" align=\"right\" src=\"https:\/\/self-issued.info\/images\/openid-logo.png\" alt=\"OpenID logo\" \/><\/span>The <a href=\"https:\/\/openid.net\/specs\/openid-connect-eap-acr-values-1_0.html\">OpenID Connect Extended Authentication Profile (EAP) ACR Values 1.0<\/a> specification has been <a href=\"https:\/\/openid.net\/eap-acr-values-final-specification-approved\/\">approved as a Final Specification<\/a> by the OpenID Foundation membership.<\/p>\n<p>As <a href=\"https:\/\/self-issued.info\/?p=2646\">I wrote at the start of the review period<\/a>, the specification is glue that ties together <a href=\"http:\/\/openid.net\/connect\/\">OpenID Connect<\/a>, <a href=\"https:\/\/www.w3.org\/TR\/2021\/REC-webauthn-2-20210408\/\">W3C Web Authentication<\/a>, and <a href=\"https:\/\/fidoalliance.org\/specs\/fido-v2.2-ps-20250228\/fido-client-to-authenticator-protocol-v2.2-ps-20250228.html\">FIDO Authenticators<\/a>, enabling them to be seamlessly used together.<\/p>\n<p>There are three useful normative definitions in the spec &#8211; two ACR values and one AMR value, all used in <a href=\"https:\/\/openid.net\/specs\/openid-connect-core-1_0.html#IDToken\">ID Token claims<\/a>.<\/p>\n<p>The two <a href=\"https:\/\/www.iana.org\/assignments\/loa-profiles\/loa-profiles.xhtml\">ACR values<\/a> defined by the specification are:<\/p>\n<ul>\n<li><code>phr<\/code>:<br \/>\nPhishing-Resistant. An authentication mechanism where a party potentially under the control of the Relying Party cannot gain sufficient information to be able to successfully authenticate to the End User&#8217;s OpenID Provider as if that party were the End User. (Note that the potentially malicious Relying Party controls where the User-Agent is redirected to and thus may not send it to the End User&#8217;s actual OpenID Provider). NOTE: These semantics are the same as those specified in [<a href=\"https:\/\/openid.net\/specs\/openid-provider-authentication-policy-extension-1_0.html\">OpenID.PAPE<\/a>].<\/li>\n<li><code>phrh<\/code>:<br \/>\nPhishing-Resistant Hardware-Protected. An authentication mechanism meeting the requirements for phishing-resistant authentication above in which additionally information needed to be able to successfully authenticate to the End User&#8217;s OpenID Provider as if that party were the End User is held in a hardware-protected device or component.<\/li>\n<\/ul>\n<p>The <a href=\"https:\/\/www.iana.org\/assignments\/authentication-method-reference-values\/authentication-method-reference-values.xhtml\">AMR value<\/a> defined by the specification is:<\/p>\n<ul>\n<li><code>pop<\/code>:<br \/>\nProof-of-possession of a key. Unlike the existing <code>hwk<\/code> and <code>swk<\/code> methods, it is unspecified whether the proof-of-possession key is hardware-secured or software-secured.<\/li>\n<\/ul>\n<p>I believe this approval completes the work of the <a href=\"http:\/\/openid.net\/wg\/eap\/\">EAP working group<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The OpenID Connect Extended Authentication Profile (EAP) ACR Values 1.0 specification has been approved as a Final Specification by the OpenID Foundation membership. As I wrote at the start of the review period, the specification is glue that ties together OpenID Connect, W3C Web Authentication, and FIDO Authenticators, enabling them to be seamlessly used together. [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,19,25],"tags":[],"class_list":["post-2726","post","type-post","status-publish","format-standard","hentry","category-openid","category-phishing-resistance","category-specifications"],"_links":{"self":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2726"}],"version-history":[{"count":2,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2726\/revisions"}],"predecessor-version":[{"id":2728,"href":"https:\/\/self-issued.info\/index.php?rest_route=\/wp\/v2\/posts\/2726\/revisions\/2728"}],"wp:attachment":[{"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2726"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2726"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/self-issued.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}