关于Android FIDO U2F API中appID与facetID的技术问询
Great question—let’s break this down clearly for Android’s FIDO U2F implementation, since it has some specific behaviors that diverge a bit from the broader FIDO spec:
1. Can you use a facetID directly as an appID?
While the official FIDO U2F specification does allow facetIDs to be used directly as appIDs, Android’s implementation of the FIDO U2F API enforces a stricter rule: you cannot use a facetID directly as the appID. Instead, you must provide an HTTPS URL that points to a JSON file (typically named u2f-appid.json) which lists all valid facetIDs authorized for your application.
This isn’t just an arbitrary restriction—Android’s U2F security model ties appID validation to a trusted web host. By requiring the appID to be a URL pointing to your controlled JSON file, it ensures that only apps you explicitly whitelist can use that appID for authentication, preventing unauthorized apps from hijacking your FIDO flows.
2. Android facetID definition per the FIDO spec
As you noted, the official FIDO spec defines the facetID for Android apps in a specific format:
android:apk-key-hash:<BASE64_ENCODED_SHA256_HASH>
Let’s unpack what this means in practice:
- The
<BASE64_ENCODED_SHA256_HASH>is the SHA-256 hash of your app’s signing certificate, encoded in Base64 (with padding characters removed). - To generate this hash, you can run this command using
keytoolandopenssl(replace placeholders with your actual keystore details):keytool -exportcert -alias YOUR_KEY_ALIAS -keystore YOUR_KEYSTORE_PATH | openssl sha256 -binary | openssl base64 | tr -d '=' - This facetID is a unique identifier for your signed Android app. If you ever switch signing certificates (e.g., moving from debug to release keys), you’ll need to generate a new facetID and update your
u2f-appid.jsonfile to include it.
Quick Workflow Recap
For Android FIDO U2F integration:
- Generate your app’s facetID using your signing certificate hash.
- Host a
u2f-appid.jsonfile on an HTTPS domain you own, with atrusted_facetsarray containing your app’s facetID (example structure below):{ "trusted_facets": [ { "version": { "major": 1, "minor": 0 }, "ids": ["android:apk-key-hash:YOUR_GENERATED_HASH"] } ] } - Use the full HTTPS URL of this JSON file as the
appIDparameter in your FIDO U2F API calls.
内容的提问来源于stack exchange,提问作者Thomas Brown

