Gentoo Archives: gentoo-dev

From: Lars Wendler <polynomial-c@g.o>
To: Alec Warner <antarus@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] RFC: Gentoo Identity Provider
Date: Tue, 19 May 2020 08:23:36
Message-Id: 20200519102319.243461c1@abudhabi.paradoxon.rec
In Reply to: [gentoo-dev] RFC: Gentoo Identity Provider by Alec Warner
1 Hi Alec,
2
3 On Mon, 18 May 2020 18:42:24 -0700 Alec Warner wrote:
4
5 >TL;DR: What if we launched id.gentoo.org, an identity provider that
6 >provides authentication for Gentoo properties? Basically, 1 username /
7 >password for wiki, bugs, email, forums, and any other http
8 >service[0][1].
9 >
10 >Today Gentoo has numerous systems that mostly work in a segmented way.
11 >
12 > - To connect to hosts, we use ssh keys.
13 > - Git is authenticated via ssh keys.
14 > - Email uses LDAP passwords.
15 > - Bugzilla has its own identities, with their own passwords.
16 > - Wiki is separate, with its own passwords.
17 > - Forums are separate.
18 > - Infra has an additional 4 systems that use separate credentials.
19 >
20 >Some applications support 2FA (such as wiki.)
21 >Some applications do not support 2FA.
22 >Applications that require 2FA have a configuration for each app, so you
23 >have N configurations.
24 >
25 >If we configured id.gentoo.org you would have 1 identity across all
26 >gentoo properties.
27 >
28 >Is this a thing people are interested in?
29 >
30 >[0] It's unlikely operations for git via ssh would change in this
31 >rollout. [1] Its unclear if the scope is "gentoo developers" or "any
32 >community member." The former have LDAP accounts and @gentoo.org email
33 >addresses and so we can manage them easily; managing 1000s of other
34 >accounts in the IDP remains to be seem.
35
36 In case 2FA won't be mandatory I find this a good idea.
37
38 Kind regards
39 --
40 Lars Wendler
41 Gentoo package maintainer
42 GPG: 21CC CF02 4586 0A07 ED93 9F68 498F E765 960E 9B39

Replies

Subject Author
Re: [gentoo-dev] RFC: Gentoo Identity Provider Alec Warner <antarus@g.o>