Page MenuHomePhabricator

Replace wikitech as source of two-factor auth protection for developer accounts
Closed, DuplicatePublic

Description

Currently Striker and Horizon/Keystone rely on OATHAuth on wikitech for two-factor authentication data. This should be replaced by self-service 2FA on idm.wikimedia.org.

Event Timeline

Change #1052085 had a related patch set uploaded (by Slyngshede; author: Slyngshede):

[operations/software/bitu@master] MediaWiki: Allow Bitu to be used as a 2FA proxy.

https://gerrit.wikimedia.org/r/1052085

Change #1052085 merged by Slyngshede:

[operations/software/bitu@master] MediaWiki: Allow Bitu to be used as a 2FA proxy.

https://gerrit.wikimedia.org/r/1052085

joanna_borun triaged this task as High priority.
joanna_borun added a subscriber: Andrew.

Change #1064480 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: add a new auth plugin to validate totp tokens against idm

https://gerrit.wikimedia.org/r/1064480

Change #1064481 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: switch to idmtotp for 2fa

https://gerrit.wikimedia.org/r/1064481

Striker still has some code that needs to be cleaned up so T373461: Striker: use idm for 2fa validation instead of wikitech probably needs to be re-purposed to that, but otherwise probably not. T372892 is for replacing 2FA functionality in IDP.