Bug#951184: RFP: libfido2 -- communicate with a FIDO device over USB

2020-02-12 Thread nicoo
Control: retitle -1 ITP: libfido2 -- communicate with a FIDO device over USB

On Tue, Feb 11, 2020 at 10:42:49PM +, Colin Watson wrote:
> libfido2 provides library functionality and command-line tools to
> communicate with a FIDO device over USB, and to verify attestation and
> assertion signatures.
> [...]
> This is going to be an optional dependency of OpenSSH 8.2 (optional at
> build time, I think, though it seems sufficiently useful that I'd be
> inclined to link against it by default if it doesn't impose an
> unreasonable run-time footprint), needed for U2F/FIDO support which is
> the principal new feature in that release.  As such I'd like to be able
> to enable it.

Colin and I discussed this in #debian-uk, and agreed to collaborate on this:

> cjwatson> Anyone fancy packaging libfido2 so I don't have to?
> nicooo> cjwatson: I'd be happy to (co)maintain that, I maintain a bunch
> of the Yubico tooling anyhow (unfortunately)
> nicooo> [...] I'm pretty keen on U2F support in OpenSSH  <3
> cjwatson> nicooo: I'd appreciate it very much, thank you
> nicooo> cjwatson: Would you want to be listed as a co-maintainer?
> cjwatson> nicooo: Happy to if it's helpful


signature.asc
Description: PGP signature


Bug#951184: RFP: libfido2 -- communicate with a FIDO device over USB

2020-02-11 Thread Colin Watson
Package: wnpp
Severity: wishlist

* Package name: libfido2
  Version : 1.3.0
  Upstream Author : Yubico AB
* URL : https://github.com/Yubico/libfido2
* License : BSD-2-clause
  Programming Lang: C
  Description : communicate with a FIDO device over USB

libfido2 provides library functionality and command-line tools to
communicate with a FIDO device over USB, and to verify attestation and
assertion signatures.

libfido2 supports the FIDO U2F (CTAP 1) and FIDO 2.0 (CTAP 2) protocols.


This is going to be an optional dependency of OpenSSH 8.2 (optional at
build time, I think, though it seems sufficiently useful that I'd be
inclined to link against it by default if it doesn't impose an
unreasonable run-time footprint), needed for U2F/FIDO support which is
the principal new feature in that release.  As such I'd like to be able
to enable it.

I do have a Yubikey 5 NFC which would be suitable for testing this with,
and in principle I'd probably be able to maintain this package
reasonably well, but I also have a lot to do and would rather give
somebody else the chance to take it on first.  I expect I'll start work
on it in a week or two if nobody else picks this up.

-- 
Colin Watson   [cjwat...@debian.org]