Authentication failure on II 2.0 with Nitrokey 3A NFC

Hi!

I’m hitting a consistent authentication failure on II 2.0 with a Nitrokey 3A NFC.

Registration succeeds, but every login attempt fails with a 500 / “Internal Error” page.

Setup

  • Hardware: Nitrokey 3A NFC (LPC55 variant)
  • AAGUID: ec99db19-cd1f-4c06-a2a9-940f17a6a30b
  • Firmware: v1.8.3 (will retry on latest)
  • OS: Ubuntu 24.04
  • Browsers tried: Edge, Brave (both reproduce)
  • FIDO2 PIN is set
  • Key has free slots

What works

  • Creating a new II 2.0 identity with the Nitrokey — succeeds
    → I see my name in the dashboard
  • Same Nitrokey works fine on webauthn.io and other WebAuthn services
  • “Test passkey support” diagnostic on id.ai creates the test credential successfully
    → Visible in nitropy fido2 list-credentials as:
    “self-service (Test passkey – safe to delete)”

What fails

  • Logging back in to id.ai or any dapp using the Nitrokey
  • Page returns 500 Internal Error

Console / network details

The /api/v4/canister/.../call request fails with HTTP 400.

Body:

Invalid delegation: Invalid public key: Algorithm Unspecified not supported: Algorithm not supported in COSE parser

Repeated several times in the trace, originating from:
Vr.fromCode → An.call in start.BtkW9xrs.js

Observation

This looks like II’s COSE parser doesn’t accept whatever algorithm the Nitrokey returns in the credential public key.

Could you check whether II 2.0 supports the algorithm Nitrokey 3 uses by default, or if there’s a missing alg field handling case?

Happy to provide more diagnostics if needed.
Thanks!

Internet Identity doesn’t implement support for signature verification itself, instead it relies on the IC network to verify the signature before it has even reached the (Internet Identity) canister(s).

From a quick glance on the NitroKey forums, it had issues with other platforms as passkey, where Discourse had to implement a fix on their backend.

It could be a similar issue on the IC or something completely different. The most helpful information to share would be registering and authenticating in the debugger here and share all details (output) in this thread.

This information would greatly help us analyze what kind of data the NitroKey generates during registration and authentication.

Thanks sir, here it is:

output of the Authenticate:

Output of the Register:

I’ve tried a lot of things on my end, and none of it changes the outcome
Any help would be really appreciated!

If you could share the CBOR download from the passkey creation output in the debugger, I should have all I need to trace where the issue occurs, see attached image where the button is located.

Оf course, here it is:

@extremist

I’ve deployed a possible fix to https://beta.id.ai, could you please try to register a new identity there and then sign-in again to it afterwards (after fully reloading the tab to sign out).

Please compare it to the experience on production (https://id.ai) and let me know if this potential fix makes any difference.

I’ve tried multiple times and the result is the same

@extremist

Please try the updated self-service tooling on beta to create a passkey and export and share the JSON with me afterwards please.

This updated self-service tool gives the exact data created at sign-up/in from II itself, compared to the webauthn.me debugger shared previously, the data from this test would match what the II implementation uses.

@sea-snake

As expected, the self-service page now correctly identifies the issue. Please export the JSON and share (it should include this error and other relevant details).

Okay sir, I sent it to your email
@sea-snake

Thanks for the input and your patience!

This narrowed down the issue and I was able to create a PR with the necessary IC changes: feat(crypto): support Ed25519/EdDSA in COSE parser for WebAuthn by sea-snake · Pull Request #10080 · dfinity/ic · GitHub

Can’t give any guarantees this will get merged or a timeline if it does at this stage. I’ll update this thread once I know more.

Thank you very much sir!

ICP on a system that isn’t full of a million spyware dependencies…

Here we go again…

Hello Sir.
Just wanted to ask if you experience the same thing or if its only on my side.
On the new internet identity website, the log-in button is being covered by the menu buttons on ios, on the bottom of the screen. So one cant click it in safari browser. Scrolling is not possible.

This is the new NNS dapp website, Internet Identity shows after clicking the login button.

I’ll forward this post the the NNS team.

Nice. When the site initially loads in its original size the menu bar blocks it and scrolling is not possible. But when i zoom in on the website i can then scroll down. But i first have to zoom in to be able to scroll. Alright nice thanks. Hopefully its just on my side. ios safari browser

@sea-snake Hello sir!
is it any news about our problem?

The fix should be merged in the next few minutes. After that you’ll need to wait for the II subnet to be updated with the latest IC release, this probably takes around a week depending on various circumstances.