[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Page MenuHomePhabricator

LDAPTag
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Recent Activity

Sun, Dec 1

gerritbot added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Change #1064480 abandoned by Andrew Bogott:

[operations/puppet@production] openstack keystone: add a new auth plugin to validate totp tokens against idm

https://gerrit.wikimedia.org/r/1064480

Sun, Dec 1, 6:52 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Change #1064481 abandoned by Andrew Bogott:

[operations/puppet@production] openstack keystone: switch to idmtotp for 2fa

Reason:

no longer needed

https://gerrit.wikimedia.org/r/1064481

Sun, Dec 1, 6:52 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Nov 11 2024

fnegri triaged T339909: LDAP: review domain and TLS setup as Medium priority.
Nov 11 2024, 11:49 AM · cloud-services-team, LDAP, Cloud-VPS
fnegri triaged T378847: novaadmin LDAP user is a member of nonexistent LDAP groups as Low priority.
Nov 11 2024, 11:22 AM · Cloud-VPS, LDAP, cloud-services-team

Nov 9 2024

Maintenance_bot removed a project from T367287: Update Wikitech's LDAP credentials to be read-only: Patch-For-Review.
Nov 9 2024, 9:30 AM · Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org
gerritbot added a comment to T367287: Update Wikitech's LDAP credentials to be read-only.

Change #1042267 abandoned by Majavah:

[operations/puppet@production] openstack: wikitech: Stop setting writable LDAP credentials

https://gerrit.wikimedia.org/r/1042267

Nov 9 2024, 9:29 AM · Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org

Nov 6 2024

taavi added a project to T339909: LDAP: review domain and TLS setup: LDAP.
Nov 6 2024, 5:01 PM · cloud-services-team, LDAP, Cloud-VPS

Nov 1 2024

taavi edited projects for T378847: novaadmin LDAP user is a member of nonexistent LDAP groups, added: LDAP, Cloud-VPS; removed Tool-ldap.

That's an issue in the underlying data in LDAP, which the tool is showing correctly enough.

Nov 1 2024, 7:15 PM · Cloud-VPS, LDAP, cloud-services-team
taavi added a comment to T378847: novaadmin LDAP user is a member of nonexistent LDAP groups.
taavi@tools-bastion-12:~ $ ldapsearch -x cn=novaadmin memberOf | grep wikinewsie
memberOf: cn=wikinewsie,ou=projects,dc=wikimedia,dc=org
Nov 1 2024, 7:13 PM · Cloud-VPS, LDAP, cloud-services-team
taavi renamed T378847: novaadmin LDAP user is a member of nonexistent LDAP groups from LDAP tool list groups that do not exist to novaadmin LDAP user is a member of nonexistent LDAP groups.
Nov 1 2024, 7:13 PM · Cloud-VPS, LDAP, cloud-services-team

Oct 26 2024

taavi removed a project from T198960: Delete/Rename my Wikitech account: wikitech.wikimedia.org.
Oct 26 2024, 11:30 AM · LDAP
taavi removed projects from T171417: Request rename of "Alangi derick" to "Alangi Derick" on wikitech/LDAP/Gerrit: cloud-services-team, wikitech.wikimedia.org.
Oct 26 2024, 11:29 AM · Release-Engineering-Team (Priority Backlog 📥), LDAP

Oct 7 2024

SLyngshede-WMF closed T359820: Developer Account Blocking: Migrate the one-stop Developer (un)Blocking from Wikitech to Bitu, a subtask of T367287: Update Wikitech's LDAP credentials to be read-only, as Resolved.
Oct 7 2024, 9:26 AM · Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org

Oct 2 2024

gerritbot added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Change #1077444 merged by jenkins-bot:

[labs/striker@master] auth: Properly remove 2FA support

https://gerrit.wikimedia.org/r/1077444

Oct 2 2024, 8:24 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a project to T373461: Striker: use idm for 2fa validation instead of wikitech: Patch-For-Review.
Oct 2 2024, 5:06 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Change #1077444 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] auth: Properly remove OATHAuth support

https://gerrit.wikimedia.org/r/1077444

Oct 2 2024, 5:06 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Oct 1 2024

bd808 merged task T359551: Replace wikitech as source of two-factor auth protection for developer accounts into T359552: Enable self-service IDP two-factor authentication management.
Oct 1 2024, 11:20 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373462: Horizon: use idm for 2fa validation instead of wikitech as Declined.

We are probably skipping ahead to idp auth.

Oct 1 2024, 11:17 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373461: Striker: use idm for 2fa validation instead of wikitech as Declined.

See T359554: Use IDP for authentication in Striker as a replacement.

Oct 1 2024, 11:17 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373461: Striker: use idm for 2fa validation instead of wikitech, a subtask of T359551: Replace wikitech as source of two-factor auth protection for developer accounts, as Declined.
Oct 1 2024, 11:16 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
bd808 closed T373462: Horizon: use idm for 2fa validation instead of wikitech, a subtask of T359551: Replace wikitech as source of two-factor auth protection for developer accounts, as Declined.
Oct 1 2024, 11:15 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
taavi added a comment to T359551: Replace wikitech as source of two-factor auth protection for developer accounts.

Striker still has some code that needs to be cleaned up so T373461: Striker: use idm for 2fa validation instead of wikitech probably needs to be re-purposed to that, but otherwise probably not. T372892 is for replacing 2FA functionality in IDP.

Oct 1 2024, 3:28 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Bugreporter added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Still relevant?

Oct 1 2024, 3:26 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Bugreporter added a comment to T359551: Replace wikitech as source of two-factor auth protection for developer accounts.

Still relevant?

Oct 1 2024, 3:24 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Bugreporter added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Still relevant?

Oct 1 2024, 3:24 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
taavi merged task T367287: Update Wikitech's LDAP credentials to be read-only into T371378: Cleanup: Wikitech code leftovers .
Oct 1 2024, 3:21 PM · Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org
Bugreporter changed the status of T367287: Update Wikitech's LDAP credentials to be read-only from Stalled to Open.

Since LdapAuthentication is gone these LDAP credentials should be removed completely instead.

Oct 1 2024, 3:16 PM · Infrastructure-Foundations, cloud-services-team, LDAP, wikitech.wikimedia.org
Bugreporter removed a project from T237602: Request to change shell name of 1997kB's wikitech account: wikitech.wikimedia.org.
Oct 1 2024, 3:09 PM · LDAP

Sep 30 2024

gerritbot added a comment to T148048: Store Wikimedia unified account name (SUL) in LDAP directory.

Change #1076816 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] labsauth: Write SUL details to LDAP when updating linkage

https://gerrit.wikimedia.org/r/1076816

Sep 30 2024, 5:43 PM · Patch-For-Review, User-bd808, Infrastructure-Foundations, LDAP, Striker
gerritbot added a comment to T148048: Store Wikimedia unified account name (SUL) in LDAP directory.

Change #1076815 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] labsauth: Write SUL account details to LDAP on registration

https://gerrit.wikimedia.org/r/1076815

Sep 30 2024, 5:43 PM · Patch-For-Review, User-bd808, Infrastructure-Foundations, LDAP, Striker
gerritbot added a comment to T148048: Store Wikimedia unified account name (SUL) in LDAP directory.

Change #1076814 had a related patch set uploaded (by Majavah; author: Majavah):

[labs/striker@master] dev(docker): Add wmf-user custom LDAP schema

https://gerrit.wikimedia.org/r/1076814

Sep 30 2024, 5:43 PM · Patch-For-Review, User-bd808, Infrastructure-Foundations, LDAP, Striker

Sep 29 2024

taavi added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

This is probably obsolete now that Horizon does IDP authentication via Keystone?

Sep 29 2024, 2:11 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Sep 24 2024

Kizule added a comment to T260647: Rename account Zoranzoki21 to Kizule on Gerrit.

Renaming shell/idm/gerrit accounts is out of the scope of wikitech SULification so I'm not sure reopening this ticket makes sense. But for your wikitech account, we can rename "Kizule" to "Kizule (usurped)" and then rename "Zoranzoki21" to "Kizule". For that, request a rename in https://wikitech.wikimedia.org/wiki/Wikitech:Rename_requests

We are not going to run reassign script nor in any way delete accounts. If you want, we can lock one of the accounts you don't want.

Regardless, out of scope of this ticket.

Sep 24 2024, 10:58 PM · Gerrit, wikitech.wikimedia.org, LDAP
Bugreporter updated the task description for T374700: Wikimedia Developer Account to Wikimedia Unified Login Requests.
Sep 24 2024, 1:32 PM · LDAP
Ladsgroup closed T260647: Rename account Zoranzoki21 to Kizule on Gerrit as Declined.

Renaming shell/idm/gerrit accounts is out of the scope of wikitech SULification so I'm not sure reopening this ticket makes sense. But for your wikitech account, we can rename "Kizule" to "Kizule (usurped)" and then rename "Zoranzoki21" to "Kizule". For that, request a rename in https://wikitech.wikimedia.org/wiki/Wikitech:Rename_requests

Sep 24 2024, 11:11 AM · Gerrit, wikitech.wikimedia.org, LDAP

Sep 23 2024

Kizule reopened T260647: Rename account Zoranzoki21 to Kizule on Gerrit as "Open".

I'm reopening this task per https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/message/5NBCVPPOXB4O3KI7B4YJBZUEA7N3YFQK/.

Sep 23 2024, 8:53 AM · Gerrit, wikitech.wikimedia.org, LDAP

Sep 17 2024

MoritzMuehlenhoff closed T201779: Have a check to prevent non-existent accounts from being added to LDAP groups as Resolved.

These days we have Bitu running on idm.wikimedia.org and we're in the process of moving access requests into it (early code has already landed). When this is all properly finished, the process of requesting access to an LDAP group, the approval by the service owner and the eventual addition to the group will all happen within idm.wikimedia.org for fixed, pre-defined groups. This solves the problem reported here, marking it as resolved even though we're not fully done yet.

Sep 17 2024, 8:18 AM · Infrastructure-Foundations, User-MoritzMuehlenhoff, Security, LDAP, SRE

Sep 14 2024

Bugreporter added a comment to T374700: Wikimedia Developer Account to Wikimedia Unified Login Requests.

Is https://wikitech.wikimedia.org/wiki/Wikitech:Rename_requests and this task really necessary? We already have ways to connect LDAP and SUL accounts with different names (in Bitu).

Sep 14 2024, 5:57 PM · LDAP

Sep 13 2024

Bugreporter added a project to T374700: Wikimedia Developer Account to Wikimedia Unified Login Requests: LDAP.
Sep 13 2024, 12:41 PM · LDAP

Aug 29 2024

Andrew lowered the priority of T373462: Horizon: use idm for 2fa validation instead of wikitech from High to Low.

We are probably skipping ahead to idp auth.

Aug 29 2024, 2:46 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew claimed T373462: Horizon: use idm for 2fa validation instead of wikitech.
Aug 29 2024, 2:45 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew triaged T373461: Striker: use idm for 2fa validation instead of wikitech as Low priority.

I'm not quite ready to close this as invalid but I'm dropping the priority since we are probably not doing it!

Aug 29 2024, 2:45 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org

Aug 27 2024

Andrew updated subscribers of T373461: Striker: use idm for 2fa validation instead of wikitech.

I'm definitely going in circles here, but @bd808 suggests that we just skip ahead to https://phabricator.wikimedia.org/T359554 and let striker run without 2fa until 2fa is enabled in CAS. That would at least stop me being confused about what the intermediate steps are in all this.

Aug 27 2024, 5:15 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Change #1064481 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: switch to idmtotp for 2fa

https://gerrit.wikimedia.org/r/1064481

Aug 27 2024, 4:40 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a project to T373462: Horizon: use idm for 2fa validation instead of wikitech: Patch-For-Review.
Aug 27 2024, 4:40 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
gerritbot added a comment to T373462: Horizon: use idm for 2fa validation instead of wikitech.

Change #1064480 had a related patch set uploaded (by Andrew Bogott; author: Andrew Bogott):

[operations/puppet@production] openstack keystone: add a new auth plugin to validate totp tokens against idm

https://gerrit.wikimedia.org/r/1064480

Aug 27 2024, 4:40 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew added a comment to T373461: Striker: use idm for 2fa validation instead of wikitech.

Simon writes:

Aug 27 2024, 4:38 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew created T373462: Horizon: use idm for 2fa validation instead of wikitech.
Aug 27 2024, 4:38 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew created T373461: Striker: use idm for 2fa validation instead of wikitech.
Aug 27 2024, 4:36 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org
Andrew removed a subtask for T359551: Replace wikitech as source of two-factor auth protection for developer accounts: T359590: Use IDP for authentication in Horizon.
Aug 27 2024, 4:34 PM · Patch-For-Review, LDAP, cloud-services-team, wikitech.wikimedia.org