[saag] Review requested - draft-linuxgemini-otpauth-uri-02
İlteriş Yağıztegin Eroğlu <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hello everyone, The otpauth:// URI format for TOTP and HOTP authenticators has been in circulation* for quite a while now. But there hasn't been any effort to standardize a uniform specification for it, thus creating various "flavors" that loosely follows what Google had defined for their then-open-source Authenticator app (https://github.com/google/google-authenticator/wiki/Key-Uri-Format). Although the core components (Identity and secret) are the same, these flavors vary on: - Supported algorithms for the token - Supported amount of digits for the OTP - Supported time period for the OTP Terence Eden has written about even more differences in his blog: https://shkspr.mobi/blog/2022/05/why-is-there-no-formal-specification-for-otpauth-urls/ I believe we can at least formalize the format such that future OTP authenticator designs can have core feature-parity. Hence why I've (rather silently) been writing an I-D for it for some time now. (Not going to lie, I am quite surprised when I learned that people actually started referencing it in their own projects and I-Ds! (https://mailarchive.ietf.org/arch/msg/saag/HNkCoj3ihoGlu9cxfcEXCFxz4J4/)) The Datatracker is here: https://datatracker.ietf.org/doc/draft-linuxgemini-otpauth-uri/ Source of the I-D and its issue tracker is at GitHub: https://github.com/linuxgemini/otpauth-spec-draft Looking forward for your reviews. Kind regards, ilteris e. *: for the lack of a better word for me where English is my second language. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]