1 |
Hi Alec, |
2 |
|
3 |
On Mon, 18 May 2020 18:42:24 -0700 Alec Warner wrote: |
4 |
|
5 |
>TL;DR: What if we launched id.gentoo.org, an identity provider that |
6 |
>provides authentication for Gentoo properties? Basically, 1 username / |
7 |
>password for wiki, bugs, email, forums, and any other http |
8 |
>service[0][1]. |
9 |
> |
10 |
>Today Gentoo has numerous systems that mostly work in a segmented way. |
11 |
> |
12 |
> - To connect to hosts, we use ssh keys. |
13 |
> - Git is authenticated via ssh keys. |
14 |
> - Email uses LDAP passwords. |
15 |
> - Bugzilla has its own identities, with their own passwords. |
16 |
> - Wiki is separate, with its own passwords. |
17 |
> - Forums are separate. |
18 |
> - Infra has an additional 4 systems that use separate credentials. |
19 |
> |
20 |
>Some applications support 2FA (such as wiki.) |
21 |
>Some applications do not support 2FA. |
22 |
>Applications that require 2FA have a configuration for each app, so you |
23 |
>have N configurations. |
24 |
> |
25 |
>If we configured id.gentoo.org you would have 1 identity across all |
26 |
>gentoo properties. |
27 |
> |
28 |
>Is this a thing people are interested in? |
29 |
> |
30 |
>[0] It's unlikely operations for git via ssh would change in this |
31 |
>rollout. [1] Its unclear if the scope is "gentoo developers" or "any |
32 |
>community member." The former have LDAP accounts and @gentoo.org email |
33 |
>addresses and so we can manage them easily; managing 1000s of other |
34 |
>accounts in the IDP remains to be seem. |
35 |
|
36 |
In case 2FA won't be mandatory I find this a good idea. |
37 |
|
38 |
Kind regards |
39 |
-- |
40 |
Lars Wendler |
41 |
Gentoo package maintainer |
42 |
GPG: 21CC CF02 4586 0A07 ED93 9F68 498F E765 960E 9B39 |