Skip to content

Add GlobalSign Root R46 to FIDO MDS default root certs - #789

Merged
MasterKale merged 2 commits into
masterfrom
fix/787-fido-mds-globalsign-root-r46
Aug 26, 2026
Merged

Add GlobalSign Root R46 to FIDO MDS default root certs#789
MasterKale merged 2 commits into
masterfrom
fix/787-fido-mds-globalsign-root-r46

Conversation

@MasterKale

@MasterKale MasterKale commented Aug 26, 2026

Copy link
Copy Markdown
Owner

The FIDO Metadata Service updated today to chain its metadata blob x5c certs to the GlobalSign Root 46 certificate:

Screenshot 2026-08-25 at 5 31 52 PM

This PR pulls that trust anchor into @simplewebauthn/server and registers it with SettingsService as a default certificate for FIDO MDS certificate chain verification.

Fixes #787.

@MasterKale MasterKale added the package:server @simplewebauthn/server label Aug 26, 2026
@MasterKale
MasterKale merged commit 05db595 into master Aug 26, 2026
4 checks passed
@MasterKale
MasterKale deleted the fix/787-fido-mds-globalsign-root-r46 branch August 26, 2026 00:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

package:server @simplewebauthn/server

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bundled GlobalSign Root CA - R3 no longer matches FIDO's MDS3 cert chain (now GlobalSign Root R46)

1 participant