1 |
On Mon, 2020-05-18 at 18:42 -0700, Alec Warner wrote: |
2 |
> TL;DR: What if we launched id.gentoo.org, an identity provider that |
3 |
> provides authentication for Gentoo properties? Basically, 1 username / |
4 |
> password for wiki, bugs, email, forums, and any other http service[0][1]. |
5 |
> |
6 |
> Today Gentoo has numerous systems that mostly work in a segmented way. |
7 |
> |
8 |
> - To connect to hosts, we use ssh keys. |
9 |
> - Git is authenticated via ssh keys. |
10 |
> - Email uses LDAP passwords. |
11 |
> - Bugzilla has its own identities, with their own passwords. |
12 |
> - Wiki is separate, with its own passwords. |
13 |
> - Forums are separate. |
14 |
> - Infra has an additional 4 systems that use separate credentials. |
15 |
> |
16 |
> Some applications support 2FA (such as wiki.) |
17 |
> Some applications do not support 2FA. |
18 |
> Applications that require 2FA have a configuration for each app, so you |
19 |
> have N configurations. |
20 |
> |
21 |
> If we configured id.gentoo.org you would have 1 identity across all gentoo |
22 |
> properties. |
23 |
> |
24 |
> Is this a thing people are interested in? |
25 |
> |
26 |
|
27 |
What a coincidence I've just archived our old identity.gentoo.org [1] |
28 |
project. And yes, we almost had this back in 2013 but Infra failed to |
29 |
deploy, and it was claimed obsolete by the time I joined Infra. |
30 |
|
31 |
Do you have any specific solution in mind? |
32 |
|
33 |
[1] https://gitweb.gentoo.org/archive/proj/identity.gentoo.org.git/ |
34 |
|
35 |
|
36 |
-- |
37 |
Best regards, |
38 |
Michał Górny |