odoo/odoo · error · InvalidRegistrationResponse
Certificate missing extension {ext_1_2_840_113635_100_8_2_oi
Error message
Certificate missing extension {ext_1_2_840_113635_100_8_2_oid} (Apple) What it means
Error "Certificate missing extension {ext_1_2_840_113635_100_8_2_oid} (Apple)" thrown in odoo/odoo.
Source
Thrown at addons/auth_passkey/_vendor/webauthn/registration/formats/apple.py:89
# Perform SHA-256 hash of nonceToHash to produce nonce.
nonce = hashlib.sha256()
nonce.update(nonce_to_hash)
nonce_bytes = nonce.digest()
# Verify that nonce equals the value of the extension with
# OID 1.2.840.113635.100.8.2 in credCert.
attestation_cert_bytes = attestation_statement.x5c[0]
attestation_cert = x509.load_der_x509_certificate(attestation_cert_bytes, default_backend())
cert_extensions = attestation_cert.extensions
# Still no documented name for this OID...
ext_1_2_840_113635_100_8_2_oid = "1.2.840.113635.100.8.2"
try:
ext_1_2_840_113635_100_8_2: Extension = cert_extensions.get_extension_for_oid(
ObjectIdentifier(ext_1_2_840_113635_100_8_2_oid)
)
except ExtensionNotFound:
raise InvalidRegistrationResponse(
f"Certificate missing extension {ext_1_2_840_113635_100_8_2_oid} (Apple)"
)
# Peel apart the Extension into an UnrecognizedExtension, then the bytes we actually
# want
ext_value_wrapper: UnrecognizedExtension = ext_1_2_840_113635_100_8_2.value
# Ignore the first six ASN.1 structure bytes that define the nonce as an
# OCTET STRING. Should trim off '0$\xa1"\x04'
ext_value: bytes = ext_value_wrapper.value[6:]
if ext_value != nonce_bytes:
raise InvalidRegistrationResponse("Certificate nonce was not expected value (Apple)")
# Verify that the credential public key equals the Subject Public Key of credCert.
attestation_cert_pub_key = attestation_cert.public_key()
attestation_cert_pub_key_bytes = attestation_cert_pub_key.public_bytes(
Encoding.DER,
PublicFormat.SubjectPublicKeyInfo,View on GitHub (pinned to 1e661df964)
Solutions
- The attestation certificate lacks the required Apple extension. Use an authentic Apple device for registration, or relax attestation requirements.
When it happens
Trigger: Thrown at addons/auth_passkey/_vendor/webauthn/registration/formats/apple.py:89 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
AI-assisted analysis of odoo/odoo@1e661df964 (2026-08-15).
Data as JSON: /api/errors/e919860bc589682d.
Report an issue: GitHub.