FIDO Compliance, Certification & Interoperability 3 — Questions and Answers
Question 1: What does FIDO Authenticator Certification Level 3 (L3) add compared to Level 2?
- Self-attestation of compliance
- Penetration testing and resistance to physical attacks (Correct answer)
- Only software-based security checks
- Compliance with GDPR requirements
Correct answer: Penetration testing and resistance to physical attacks
L3 adds rigorous penetration testing and evaluation of resistance to physical attacks on top of L2's lab evaluation requirements.
Question 2: How does FIDO certification handle authenticator firmware updates that change security-relevant functionality?
- The certification remains valid indefinitely regardless of firmware changes
- The vendor must notify the FIDO Alliance and may need to undergo re-certification (Correct answer)
- Only the relying party needs to be notified
- Firmware updates void certification automatically with no recourse
Correct answer: The vendor must notify the FIDO Alliance and may need to undergo re-certification
Security-relevant firmware changes require the vendor to notify FIDO Alliance, which may trigger re-certification to maintain the certified status.
Question 3: Which body accredits the testing laboratories authorized to perform FIDO security evaluations?
- The IEEE Standards Association
- ISO/IEC through national accreditation bodies
- The FIDO Alliance directly (Correct answer)
- NIST's National Voluntary Laboratory Accreditation Program only
Correct answer: The FIDO Alliance directly
The FIDO Alliance directly accredits the Authorized Test Laboratories (ATLs) permitted to conduct FIDO certification testing.
Question 4: When an authenticator fails FIDO certification testing, what typically happens next?
- The product is permanently banned from FIDO certification
- The vendor receives a detailed test report and may remediate and retest (Correct answer)
- The failure is publicly disclosed immediately
- The vendor must switch to a different authenticator technology
Correct answer: The vendor receives a detailed test report and may remediate and retest
Failed products receive a detailed report; vendors can remediate the identified issues and submit for re-testing.
Question 5: In the context of FIDO interoperability, what does it mean for a FIDO2 authenticator to be 'backward compatible' with FIDO U2F?
- It can register and authenticate using the CTAP1/U2F protocol over USB (Correct answer)
- It supports only WebAuthn Level 2 features
- It uses the same key material for both U2F and FIDO2 operations
- It requires a U2F-specific firmware partition
Correct answer: It can register and authenticate using the CTAP1/U2F protocol over USB
CTAP1 is the FIDO2 name for the U2F protocol, so a FIDO2 authenticator supporting CTAP1 can interoperate with existing U2F deployments.
Question 6: Which FIDO certification focuses on ensuring that products from different vendors work together correctly in realistic end-to-end scenarios?
- FIDO Functional Certification
- FIDO Interoperability Certification (Correct answer)
- FIDO Security Certification
- FIDO Conformance Certification
Correct answer: FIDO Interoperability Certification
FIDO Interoperability Certification tests that products from multiple vendors can work together in end-to-end FIDO authentication flows.
Question 7: What is the significance of an authenticator's AAGUID in the context of FIDO certification?
- It encrypts the authenticator's private keys
- It uniquely identifies the authenticator model and links it to MDS metadata (Correct answer)
- It serves as the user's persistent identifier across sites
- It defines the authenticator's firmware version
Correct answer: It uniquely identifies the authenticator model and links it to MDS metadata
The AAGUID (Authenticator Attestation GUID) uniquely identifies an authenticator model, allowing relying parties to look up its certification status and capabilities in MDS.
What does FIDO Authenticator Certification Level 3 (L3) add compared to Level 2?