Currently Striker and Horizon/Keystone rely on OATHAuth on wikitech for two-factor authentication data. This should be replaced by self-service 2FA on idm.wikimedia.org.
Description
Details
| Subject | Author | Repo | Branch | Lines +/- | |
|---|---|---|---|---|---|
| MediaWiki: Allow Bitu to be used as a 2FA proxy. | Slyngshede | operations/software/bitu | master | +165 -10 |
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Open | None | T189531 All Wikimedia developer services should use single sign-on | |||
| Resolved | None | T161859 Make Wikitech an SUL wiki | |||
| Duplicate | None | T359551 Replace wikitech as source of two-factor auth protection for developer accounts | |||
| Open | Feature | SLyngshede-WMF | T359552 Enable self-service IDP two-factor authentication management | ||
| Declined | None | T373461 Striker: use idm for 2fa validation instead of wikitech | |||
| Declined | Andrew | T373462 Horizon: use idm for 2fa validation instead of wikitech |
Event Timeline
Change #1052085 had a related patch set uploaded (by Slyngshede; author: Slyngshede):
[operations/software/bitu@master] MediaWiki: Allow Bitu to be used as a 2FA proxy.
Change #1052085 merged by Slyngshede:
[operations/software/bitu@master] MediaWiki: Allow Bitu to be used as a 2FA proxy.
Change #1064480 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):
[operations/puppet@production] openstack keystone: add a new auth plugin to validate totp tokens against idm
Change #1064481 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):
[operations/puppet@production] openstack keystone: switch to idmtotp for 2fa
Striker still has some code that needs to be cleaned up so T373461: Striker: use idm for 2fa validation instead of wikitech probably needs to be re-purposed to that, but otherwise probably not. T372892 is for replacing 2FA functionality in IDP.