Nevis Mobile Authentication SDK React Native plugin
    Preparing search index...

    Class OnlySurrogateBasicSupportedAbstract

    Only the surrogate basic attestation is supported.

    So, neither the default, the strict nor the strict-strongbox modes of full basic attestation are supported (see the nevisFIDO documentation for details regarding the different modes).

    Supporting only surrogate basic attestation implies that the certificate chain of the device could not be successfully validated (see certificateChainValidationResult). This occurs typically in old devices, and devices that do not contain a Google root certificate (like some Huawei models).

    Hierarchy (View Summary)

    Index

    Properties

    keymasterSecurityLevel: SecurityLevel

    The SecurityLevel of the environment where the FIDO UAF keys are stored. This provides information about the security of the environment where the keys are stored.

    keymasterVersion: number

    The keymaster version.

    isDeviceBootloaderLocked: boolean

    Returns true if the device's bootloader is locked, and false otherwise.

    isVerifiedBootStateValid: boolean

    Returns true if the boot state is Verified. Compromised devices (such as some root devices) do not have a valid boot state.

    certificateChainValidationResult: CertificateChainValidationResult

    The result of the certificate chain validation.

    In devices supporting full basic attestation (OnlyDefaultMode, StrictMode or StrictStrongBoxMode), when a new key is created the device must generate an associated certificate chain (or certification path) that fulfills the following criteria:

    • The root certificate is a known Google root certificate.
    • The certificate chain is valid: it does not contain a certificate in the CRL, no certificate is expired, the certificates in the chain are signed with the previous one, etc.
    So, when a device supports full basic, returns CertificateChainValidationResult.Success.
    cause?: string

    The error that occurred while checking if the full basic attestation is supported.

    Its message provides information about why the device does not support full basic attestation.

    Methods