[go: up one dir, main page]

Page MenuHomePhabricator

LDAPTag
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Recent Activity

Mon, Oct 7

SLyngshede-WMF closed T359820: Developer Account Blocking: Migrate the one-stop Developer (un)Blocking from Wikitech to Bitu, a subtask of T367287: Update Wikitech's LDAP credentials to be read-only, as Resolved.
Mon, Oct 7, 9:26 AM · Patch-For-Review, Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org

Wed, Oct 2

gerritbot added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Change #1077444 merged by jenkins-bot:

[labs/striker@master] auth: Properly remove 2FA support

https://gerrit.wikimedia.org/r/1077444

Wed, Oct 2, 8:24 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a project to T373461: Striker: use idm for 2fa validation instead of wikitech: Patch-For-Review.
Wed, Oct 2, 5:06 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Change #1077444 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] auth: Properly remove OATHAuth support

https://gerrit.wikimedia.org/r/1077444

Wed, Oct 2, 5:06 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Tue, Oct 1

bd808 merged task T359551: Replace wikitech as source of two-factor auth protection for developer accounts into T359552: Enable self-service IDP two-factor authentication management.
Tue, Oct 1, 11:20 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373462: Horizon: use idm for 2fa validation instead of wikitech as Declined.

We are probably skipping ahead to idp auth.

Tue, Oct 1, 11:17 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373461: Striker: use idm for 2fa validation instead of wikitech as Declined.

See T359554: Use IDP for authentication in Striker as a replacement.

Tue, Oct 1, 11:17 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373461: Striker: use idm for 2fa validation instead of wikitech, a subtask of T359551: Replace wikitech as source of two-factor auth protection for developer accounts, as Declined.
Tue, Oct 1, 11:16 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373462: Horizon: use idm for 2fa validation instead of wikitech, a subtask of T359551: Replace wikitech as source of two-factor auth protection for developer accounts, as Declined.
Tue, Oct 1, 11:15 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
taavi added a comment to T359551: Replace wikitech as source of two-factor auth protection for developer accounts.

Striker still has some code that needs to be cleaned up so T373461: Striker: use idm for 2fa validation instead of wikitech probably needs to be re-purposed to that, but otherwise probably not. T372892 is for replacing 2FA functionality in IDP.

Tue, Oct 1, 3:28 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Bugreporter added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Still relevant?

Tue, Oct 1, 3:26 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Bugreporter added a comment to T359551: Replace wikitech as source of two-factor auth protection for developer accounts.

Still relevant?

Tue, Oct 1, 3:24 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Bugreporter added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Still relevant?

Tue, Oct 1, 3:24 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
taavi merged task T367287: Update Wikitech's LDAP credentials to be read-only into T371378: Cleanup: Wikitech code leftovers .
Tue, Oct 1, 3:21 PM · Patch-For-Review, Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org
Bugreporter changed the status of T367287: Update Wikitech's LDAP credentials to be read-only from Stalled to Open.

Since LdapAuthentication is gone these LDAP credentials should be removed completely instead.

Tue, Oct 1, 3:16 PM · Patch-For-Review, Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org
Bugreporter removed a project from T237602: Request to change shell name of 1997kB's wikitech account: wikitech.wikimedia.org.
Tue, Oct 1, 3:09 PM · LDAP

Mon, Sep 30

gerritbot added a comment to T148048: Store Wikimedia unified account name (SUL) in LDAP directory.

Change #1076816 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] labsauth: Write SUL details to LDAP when updating linkage

https://gerrit.wikimedia.org/r/1076816

Mon, Sep 30, 5:43 PM · Patch-For-Review, User-bd808, Infrastructure-Foundations, LDAP, Striker
gerritbot added a comment to T148048: Store Wikimedia unified account name (SUL) in LDAP directory.

Change #1076815 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] labsauth: Write SUL account details to LDAP on registration

https://gerrit.wikimedia.org/r/1076815

Mon, Sep 30, 5:43 PM · Patch-For-Review, User-bd808, Infrastructure-Foundations, LDAP, Striker
gerritbot added a comment to T148048: Store Wikimedia unified account name (SUL) in LDAP directory.

Change #1076814 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] dev(docker): Add wmf-user custom LDAP schema

https://gerrit.wikimedia.org/r/1076814

Mon, Sep 30, 5:43 PM · Patch-For-Review, User-bd808, Infrastructure-Foundations, LDAP, Striker

Sun, Sep 29

taavi added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

This is probably obsolete now that Horizon does IDP authentication via Keystone?

Sun, Sep 29, 2:11 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Tue, Sep 24

Kizule added a comment to T260647: Rename account Zoranzoki21 to Kizule on Gerrit.

Renaming shell/idm/gerrit accounts is out of the scope of wikitech SULification so I'm not sure reopening this ticket makes sense. But for your wikitech account, we can rename "Kizule" to "Kizule (usurped)" and then rename "Zoranzoki21" to "Kizule". For that, request a rename in https://wikitech.wikimedia.org/wiki/Wikitech:Rename_requests

We are not going to run reassign script nor in any way delete accounts. If you want, we can lock one of the accounts you don't want.

Regardless, out of scope of this ticket.

Tue, Sep 24, 10:58 PM · Gerrit, wikitech.wikimedia.org, LDAP
Bugreporter updated the task description for T374700: Wikimedia Developer Account to Wikimedia Unified Login Requests.
Tue, Sep 24, 1:32 PM · LDAP
Ladsgroup closed T260647: Rename account Zoranzoki21 to Kizule on Gerrit as Declined.

Renaming shell/idm/gerrit accounts is out of the scope of wikitech SULification so I'm not sure reopening this ticket makes sense. But for your wikitech account, we can rename "Kizule" to "Kizule (usurped)" and then rename "Zoranzoki21" to "Kizule". For that, request a rename in https://wikitech.wikimedia.org/wiki/Wikitech:Rename_requests

Tue, Sep 24, 11:11 AM · Gerrit, wikitech.wikimedia.org, LDAP

Mon, Sep 23

Kizule reopened T260647: Rename account Zoranzoki21 to Kizule on Gerrit as "Open".

I'm reopening this task per https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/message/5NBCVPPOXB4O3KI7B4YJBZUEA7N3YFQK/.

Mon, Sep 23, 8:53 AM · Gerrit, wikitech.wikimedia.org, LDAP

Tue, Sep 17

MoritzMuehlenhoff closed T201779: Have a check to prevent non-existent accounts from being added to LDAP groups as Resolved.

These days we have Bitu running on idm.wikimedia.org and we're in the process of moving access requests into it (early code has already landed). When this is all properly finished, the process of requesting access to an LDAP group, the approval by the service owner and the eventual addition to the group will all happen within idm.wikimedia.org for fixed, pre-defined groups. This solves the problem reported here, marking it as resolved even though we're not fully done yet.

Tue, Sep 17, 8:18 AM · Infrastructure-Foundations, User-MoritzMuehlenhoff, Security, LDAP, SRE

Sat, Sep 14

Bugreporter added a comment to T374700: Wikimedia Developer Account to Wikimedia Unified Login Requests.

Is https://wikitech.wikimedia.org/wiki/Wikitech:Rename_requests and this task really necessary? We already have ways to connect LDAP and SUL accounts with different names (in Bitu).

Sat, Sep 14, 5:57 PM · LDAP

Fri, Sep 13

Bugreporter added a project to T374700: Wikimedia Developer Account to Wikimedia Unified Login Requests: LDAP.
Fri, Sep 13, 12:41 PM · LDAP

Aug 29 2024

Andrew lowered the priority of T373462: Horizon: use idm for 2fa validation instead of wikitech from High to Low.

We are probably skipping ahead to idp auth.

Aug 29 2024, 2:46 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew claimed T373462: Horizon: use idm for 2fa validation instead of wikitech.
Aug 29 2024, 2:45 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew triaged T373461: Striker: use idm for 2fa validation instead of wikitech as Low priority.

I'm not quite ready to close this as invalid but I'm dropping the priority since we are probably not doing it!

Aug 29 2024, 2:45 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Aug 27 2024

Andrew updated subscribers of T373461: Striker: use idm for 2fa validation instead of wikitech.

I'm definitely going in circles here, but @bd808 suggests that we just skip ahead to https://phabricator.wikimedia.org/T359554 and let striker run without 2fa until 2fa is enabled in CAS. That would at least stop me being confused about what the intermediate steps are in all this.

Aug 27 2024, 5:15 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Change #1064481 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: switch to idmtotp for 2fa

https://gerrit.wikimedia.org/r/1064481

Aug 27 2024, 4:40 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a project to T373462: Horizon: use idm for 2fa validation instead of wikitech: Patch-For-Review.
Aug 27 2024, 4:40 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Change #1064480 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: add a new auth plugin to validate totp tokens against idm

https://gerrit.wikimedia.org/r/1064480

Aug 27 2024, 4:40 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Simon writes:

Aug 27 2024, 4:38 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew created T373462: Horizon: use idm for 2fa validation instead of wikitech.
Aug 27 2024, 4:38 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew created T373461: Striker: use idm for 2fa validation instead of wikitech.
Aug 27 2024, 4:36 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew removed a subtask for T359551: Replace wikitech as source of two-factor auth protection for developer accounts: T359590: Use IDP for authentication in Horizon.
Aug 27 2024, 4:34 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew removed a subtask for T359551: Replace wikitech as source of two-factor auth protection for developer accounts: T359554: Use IDP for authentication in Striker.
Aug 27 2024, 4:33 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Aug 21 2024

gerritbot added a comment to T359551: Replace wikitech as source of two-factor auth protection for developer accounts.

Change #1064481 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: switch to idmtotp for 2fa

https://gerrit.wikimedia.org/r/1064481

Aug 21 2024, 9:59 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a project to T359551: Replace wikitech as source of two-factor auth protection for developer accounts: Patch-For-Review.
Aug 21 2024, 9:59 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T359551: Replace wikitech as source of two-factor auth protection for developer accounts.

Change #1064480 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: add a new auth plugin to validate totp tokens against idm

https://gerrit.wikimedia.org/r/1064480

Aug 21 2024, 9:59 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
joanna_borun placed T359551: Replace wikitech as source of two-factor auth protection for developer accounts up for grabs.
Aug 21 2024, 2:33 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew claimed T359551: Replace wikitech as source of two-factor auth protection for developer accounts.
Aug 21 2024, 2:33 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Aug 10 2024

taavi closed T214541: python3-ldap3 mixed versions and future traps as Resolved.

Boldly closing this a few years later :-)

Aug 10 2024, 10:09 AM · cloud-services-team, LDAP, Toolforge

Aug 5 2024

SLyngshede-WMF changed the status of T359820: Developer Account Blocking: Migrate the one-stop Developer (un)Blocking from Wikitech to Bitu, a subtask of T367287: Update Wikitech's LDAP credentials to be read-only, from Open to In Progress.
Aug 5 2024, 11:38 AM · Patch-For-Review, Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org

Jul 30 2024

jijiki removed a parent task for T359551: Replace wikitech as source of two-factor auth protection for developer accounts: T363125: sustainability of wikitech.wikimedia.org.
Jul 30 2024, 10:05 AM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Jul 29 2024

jijiki added a parent task for T367287: Update Wikitech's LDAP credentials to be read-only: T189531: All Wikimedia developer services should use single sign-on.
Jul 29 2024, 10:16 PM · Patch-For-Review, Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org

Jul 24 2024

joanna_borun triaged T306623: Remove obsolete LDAP schemas as Low priority.
Jul 24 2024, 2:26 PM · cloud-services-team, Technical-Debt, Cloud-VPS, LDAP

Jul 22 2024

GTrang closed T238893: Merge developer accounts for Riley Huntley as Invalid.

Merging Wikitech accounts is not technically possible.

Jul 22 2024, 2:40 PM · wikitech.wikimedia.org, LDAP