summaryrefslogtreecommitdiff
path: root/usr.bin
diff options
context:
space:
mode:
authorDamien Miller <djm@cvs.openbsd.org>2019-12-11 22:19:48 +0000
committerDamien Miller <djm@cvs.openbsd.org>2019-12-11 22:19:48 +0000
commite5ae2c6b32314171b1f24efc0c985c8a96f991cc (patch)
tree953dd5abef4474dc29294c58c6635169435df491 /usr.bin
parentc2a5aa4d4c32a73e3c3520e103f2408f1a7adff1 (diff)
add a note about the 'extensions' field in the signed object
Diffstat (limited to 'usr.bin')
-rw-r--r--usr.bin/ssh/PROTOCOL.u2f4
1 files changed, 4 insertions, 0 deletions
diff --git a/usr.bin/ssh/PROTOCOL.u2f b/usr.bin/ssh/PROTOCOL.u2f
index 32bfa20f316..066d0995162 100644
--- a/usr.bin/ssh/PROTOCOL.u2f
+++ b/usr.bin/ssh/PROTOCOL.u2f
@@ -170,6 +170,10 @@ is signed over a blob that consists of:
byte[] extensions
byte[32] SHA256(message)
+No extensons are yet defined for SSH use. If any are defined in the future,
+it will be possible to infer their presence from the contents of the "flags"
+value.
+
The signature returned from U2F hardware takes the following format:
byte flags (including "user present")