[saag] Review requested - draft-linuxgemini-otpauth-uri-02

İlteriş Yağıztegin Eroğlu <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hello everyone,

The otpauth:// URI format for TOTP and HOTP authenticators has been in circulation* for quite a while now. But there hasn't been any effort to standardize a uniform specification for it, thus creating various "flavors" that loosely follows what Google had defined for their then-open-source Authenticator app (https://github.com/google/google-authenticator/wiki/Key-Uri-Format).

Although the core components (Identity and secret) are the same, these flavors vary on:

- Supported algorithms for the token
- Supported amount of digits for the OTP
- Supported time period for the OTP

Terence Eden has written about even more differences in his blog: https://shkspr.mobi/blog/2022/05/why-is-there-no-formal-specification-for-otpauth-urls/

I believe we can at least formalize the format such that future OTP authenticator designs can have core feature-parity. Hence why I've (rather silently) been writing an I-D for it for some time now.

(Not going to lie, I am quite surprised when I learned that people actually started referencing it in their own projects and I-Ds! (https://mailarchive.ietf.org/arch/msg/saag/HNkCoj3ihoGlu9cxfcEXCFxz4J4/))

The Datatracker is here: https://datatracker.ietf.org/doc/draft-linuxgemini-otpauth-uri/

Source of the I-D and its issue tracker is at GitHub: https://github.com/linuxgemini/otpauth-spec-draft

Looking forward for your reviews.

Kind regards,
ilteris e.

*: for the lack of a better word for me where English is my second language.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.