From Fedora Project Wiki

Support FIDO Device Onboarding

Summary

FIDO Device Onboarding is an open standard for Zero Touch Onboarding of IoT and Edge devices.

Owner

Current status

  • Targeted release: Fedora 37
  • Last updated: 2022-03-28
  • devel thread
  • FESCo issue:
  • Tracker bug:
  • Release Notes tracker:

Detailed Description

The ability for an IoT or Edge device to be plugged in and automatically onboard itself with zero user interaction is critical to be able to scale IoT/Edge to millions of devices. To do this in a secure way with open standards across the industry is even more critical. The FIDO IoT working group has worked with leaders in the silicon industry such as Intel and Arm to produce the FIDO Device onboarding spec which allows a device credential, a root and chain of trust to ensure the secure onboarding of a device without the need of stored credentials.

Benefit to Fedora

The benefit to Fedora is to allow the IoT Edition to demonstrate the use of leading edge open industry protocols for onboarding IoT and Edge devices.

Scope

  • Proposal owners:
    • Package the rust implementation of the FIDO device onboarding stack including client, rendezvous service, owner onboarding service and prototype manufacturing service.
    • Enable the client service by default for IoT Edition
    • Add the client service to the IoT Edition deliverables
  • Other developers:
    • No impact
  • Policies and guidelines: N/A (not a System Wide Change)
  • Trademark approval: N/A (not needed for this Change)

Upgrade/compatibility impact

There is no upgrade impact.

How To Test

  • Test with FDO all-in-one services

User Experience

No impact to non IoT Edition users.

Dependencies

N/A (not a System Wide Change)

Contingency Plan

  • Contingency mechanism: Not shipping FDO as a package in Fedora or including it in the IoT Edition
  • Contingency deadline: GA
  • Blocks release? No.
  • Blocks product? No.

Documentation

N/A (not a System Wide Change)

Release Notes

Fedora IoT Edition supports the FIDO Device Onboarding 1.1 specification for zero touch onboarding of IoT and Edge devices.