Keygen tag in HTML5

后端 未结 6 674
礼貌的吻别
礼貌的吻别 2020-12-02 10:35

So I came across this new tag in HTML5, . I can\'t quite figure out what it is for, how it is applied, and how it might affect browser behavior.

相关标签:
6条回答
  • 2020-12-02 10:46

    Deprecated

    This feature has been removed from the Web standards. Though some browsers may still support it, it is in the process of being dropped. Avoid using it and update existing code if possible. Be aware that this feature may cease to work at any time.

    Source

    0 讨论(0)
  • 2020-12-02 10:50

    If you're looking for "exactly" then I'd recommend reading the RFC.

    The keygen element is for creating a key for authentication of the user while SSL is concerned about privacy of communication and the authentication of the server. Quoting from the RFC:

    This specification does not specify how the private key generated is to be used. It is expected that after receiving the SignedPublicKeyAndChallenge (SPKAC) structure, the server will generate a client certificate and offer it back to the user for download; this certificate, once downloaded and stored in the key store along with the private key, can then be used to authenticate to services that use TLS and certificate authentication.

    0 讨论(0)
  • 2020-12-02 10:54

    You're missing some history. keygen was first supported by Netscape when it was still a relevant browser. IE, OTOH, supported the same use cases through its ActiveX APIs. Opera and WebKit (or even KHTML), unwilling to reverse-engineer the entire Win32 API, reverse-engineered keygen instead.

    It was specified in Web Forms 2.0 (which has now been merged into the HTML specification), in order to improve interoperability between the browsers that implemented it.

    Since then, the IE team has reiterated their refusal to implement keygen, and the specification (in order to avoid turning into dry science fiction) has been changed to not require an actual implementation:

    Note: This specification does not specify what key types user agents are to support — it is possible for a user agent to not support any key types at all.

    In short, this is not a new element, and unless you can ignore IE, it's probably not what you want.

    0 讨论(0)
  • 2020-12-02 11:01

    SSL is about "server identification" or "server AND client authentication (mutual authentication)".

    In most cases only the server presents its server-certificate during the SSL handshake so that you could make sure that this really is the server you expect to connect to. In some cases the server also wants to verify that you really are the person you pretend to be. For this you need a client-certificate.

    The <keygen> tag generates a public/private key pair and then creates a certificate request. This certificate request will be sent to a Certificate Authority (CA). The CA creates a certificate and sends it back to the browser. Now you are able to use this certificate for user authentication.

    0 讨论(0)
  • 2020-12-02 11:02

    The doc is useful to elaborate on what is the keygen element. Its requirement arises in WebID that maybe understood to be part of Semantic Web of Linked Data as seen at https://dvcs.w3.org/hg/WebID/raw-file/tip/spec/index-respec.html#creating-a-certificate 2.1.1

    0 讨论(0)
  • 2020-12-02 11:05

    This might be useful for websites that provide services, where people need to pay for the service, like video on demand, or news website for professionals like Bloomberg. With this keys people can only watch the content in their computer and not in simultaneous computers! You decide how data is stored and processed. you can specify a .asp or .php file that will receive the variables and your file will store that key in the user profile. This way your users will not be able to log in from a different computer if you want. You may force them to check their email to authorize that new computer, just like steam does. Basically it allows to individualize service access, if your licensing model is per machine, like Operating System.

    You can check the specs here: http://www.w3.org/TR/html-markup/keygen.html

    0 讨论(0)
提交回复
热议问题