Should we require 2FA for provenpackagers? #3618
Labels
No labels
Closed As
Accepted
Closed As
Duplicate
Closed As
Insufficient data
Closed As
Invalid
Closed As
Rejected
document it
fast track
meeting
next release
nonresponsive maintainer
packager revocation
pending announcement
provenpackager
python 2 exception
self contained change
stalled
system wide change
updates policy exception
vote-in-progress
No milestone
No project
No assignees
8 participants
Notifications
Due date
Dependencies
No dependencies set.
Reference
fesco/tickets#3618
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
See the recent discussion in https://lists.fedoraproject.org/archives/search?mlist=devel%40lists.fedoraproject.org&q=Fedora%3A+Inaccurate+and+apparently-unsupervised+actions+by+agentic+AI+system+under+your+control and also discussions about being compliant with the CRA at Flock.
Proposal: Require that members of the
provenpackagergroup set up two-factor authentication in FAS.How we would actually technically implement this is an open question. I am not yet proposing that we enable this for all packagers given the current issues with 2FA in Fedora that have already been mentioned on the devel thread. But I do think the calculus for provenpackagers is different given how much access they have.
+1 from me
Not sure if we need to create yet another mailing list thread for this since there's already an ongoing discussion .... but it might be good to post on the ML regardless just so that people are aware that this is now actually a concrete proposal.
Yeah, I meant to do that and then forgot :). I just replied to the devel thread.
+1 if the 2FA is not relaying on big tech solutions or "the latest android os" on a phone.
Do we have a self-service MFA recovery method that doesn't involve sending GPG-signed emails to @kevin yet? Otherwise, this effectively forces everyone to have working ability to do GPG-signed emails.
+1 for 2FA for proven packagers. The MFA is an OTP token right now so you can use any app doing OTP tokens.
+1 to requiring this. The first step would be to change the current policy about provenpackagers and 2FA (fesco/docs@!90 (commit
62ce446ce6)) from "SHOULD use" to "MUST use." I think figuring out how to enforce this can be a separate step.There is currently not a self-service process for it, but I was told that GPG-signed emails are not the only supported mechanism for recovery. When there is no GPG key configured in FAS, it can also be recovered by proving access to SSH keys registered in FAS or some Red Hat internal thing for Red Hatters.
+1
I think we should tell people to always enroll at least two tokens, e.g. a hardware token and freeotp on the phone, or maybe even three.
I tried to enroll a Nitrokey today, and it works, but https://docs.nitrokey.com/software/nitropy/ is not packaged for Fedora. It'd be nice to add that.
Also, we should have good instructions on enrollment for Yubikeys, Nitrokeys, Freeotp, and whatever other popular stuff is out there.
I talked to various folks about this at flock and also just posted to that devel list thread the caveats that come to mind.
I also promised @gotmax23 to run the script and see how many people we are affecting here. I'll look for that script and run it and report back when I get caught up enough to do so.
Just a quick script run ( I haven't checked too closely to see if there's any bugs)
There are 114 provenpackagers.
59 of them do not have a otp enrolled.
So, about 52%
I opened fesco/docs#144 to change the policy.
As for enforcing it...
We can manually check for 2FA enrollment when adding any new provenpackagers as kevin pointed out, but what do we want to do about these? We don't currently have a way to block access to services like Koji based on lack of 2FA, but we can set a flag date and directly email users and remove users from provenpackager who haven't set 2FA by the flag date. That kind of stinks, though :(.
Let's put this on the meeting agenda so we can figure out how to proceed with the implementation.
Metadata Update from @zbyszek:
This topic is on the agenda for today's meeting:
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/HKQ332NLB7YKBY6AM35PXZ6NRWVAMUI6/
From today's meeting:
(Meeting log at 18:17:15)
Full text of the agreed-upon proposal:
Metadata Update from @decathorpe:
Announcement proposal
Subject: Two-factor authentication required for provenpackager members
Hi everyone,
FESCo has voted to require two-factor authentication (2FA) for all members of the provenpackager group. Current provenpackager members without 2FA enabled in Fedora Accounts must take action before 2026-09-22.
Please see https://docs.fedoraproject.org/en-US/fedora-accounts/user/#twofactor for more information on setting up 2FA in the Fedora Accounts System. It is recommended to maintain a backup of your 2FA tokens and/or enroll multiple devices (e.g., a hardware security device and a mobile authenticator app).
Any new users applying to the provenpackager group must have 2FA set up in Fedora Accounts.
For existing members who do not have 2FA configured, there is a three month grace period (2026-09-22) to set up 2FA in Fedora Accounts. Affected users will be emailed directly. provenpackager members who have not enabled 2FA by 2026-09-22 will be removed from the provenpackager group. provenpackager members removed during this process can be reinstated once they configure 2FA by filing a ticket with Fedora Infrastructure --- they do NOT need to re-apply with FESCo for provenpackager access.
Here's a rough draft of an announcement. Feedback welcome!
I think that looks fine.
+1
@gotmax23 the only feedback I'd have is that I understand the timeline to be:
I think number 3 could be mentioned in the last paragraph of the email?
FESCo has voted to require two-factor authentication (2FA) for all members of the provenpackager group (SHOULD is now upgraded to MUST). Please enable 2FA if you haven't yet. In the three-month grace period existing provenpackager accounts without 2FA can continue to be used, but 2FA is required for any new accounts. After the end of the grace period, remaining provenpackager accounts will be temporarily downgraded until 2FA is enabled.
2FA is also strongly recommended for non-provenpackager accounts.
For members who currently do not have 2FA configured, a three month grace period (until 2026-09-24) is provided to set up 2FA in Fedora Accounts. Affected users will be emailed directly. provenpackager members who have not enabled 2FA by 2026-09-24 will be removed from the provenpackager group. Those members can be reinstated once they configure 2FA by filing a ticket with Fedora Infrastructure — they do NOT need to re-apply to FESCo for provenpackager access.
Let's make the three month period start at the time when the email is sent. Shaving off one or two days doesn't change much but it could be an extra annoyance to people receiving the notice.
I applied @zbyszek's suggestion and made one other fix.
Hi everyone,
FESCo has voted to require two-factor authentication (2FA) for all members of the provenpackager group (SHOULD is now upgraded to MUST). Please enable 2FA if you haven't yet. In the three-month grace period, existing provenpackager accounts without 2FA can continue to be used, but 2FA is required for any new accounts. After the end of the grace period, remaining provenpackager accounts will be temporarily downgraded until 2FA is enabled.
2FA is also strongly recommended for non-provenpackager accounts.
Please see https://docs.fedoraproject.org/en-US/fedora-accounts/user/#twofactor for more information on setting up 2FA in the Fedora Accounts System. It is recommended to maintain a backup of your 2FA tokens and/or enroll multiple devices (e.g., a hardware security device and a mobile authenticator app).
Any new users applying to the provenpackager group must have 2FA set up in Fedora Accounts.
For provenpackager members who currently do not have 2FA configured, a three month grace period (until 2026-09-24) is provided to set up 2FA in Fedora Accounts. Affected users will be emailed directly. Members who have not enabled 2FA by 2026-09-24 will be removed from the provenpackager group. Those members can be reinstated once they configure 2FA by filing a ticket with Fedora Infrastructure — they do NOT need to re-apply to FESCo for provenpackager access.
If there are any further tweaks, feel free to directly edit the above post. I can send the announcement to devel-announce and Discussion once we're agreed on the announcement text. For the direct emails, I don't have the list of affected provenpackagers.
@supakeen wrote in #3618 (comment):
I was thinking we'd send the announcement and directly contact affected users at the same time. The announcement text does say, "affected users will be emailed directly." Are you proposing doing this differently?
@zbyszek who proposed it (and anyone else), is this something that we for sure want to keep in the announcement even though the proposal here only applies to provenpackager? I don't think it's a controversial statement, but I don't want to rub people the wrong way.
[I sent the reply by mail first, but I don't see it here. Sorry if this gets posted twice.]
Yeah, I think we should aim for having 2FA for all packager accounts.
Mentioning this here gives a heads-up for everybody else.
see also #3625
I have posted the devel-announce and Discussion announcements.
We still need to contact individual maintainers. @kevin, would you like to handle this? Or I can if you send me a list of users.
I can get you the list... matrix dm?
The announcements have been posted, and I have individually emailed each affected user. Marking this as stalled for now. Maybe we can send a second set of reminders after waiting some time (say, a month and a half?) as @supakeen suggested.
Quoting #3625 (comment):
I think we should send out another reminder. We don't want to end up with two dozen accounts to freeze at the deadline.
@kevin If you could send the new list to @gotmax23?
I'll unset
document it, because AFAICS, we have updated the docs successfully.List sent. (and down to 21... )