Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rollout plan for critical projects 2FA requirement #12308

Closed
4 tasks
di opened this issue Oct 3, 2022 · 0 comments · Fixed by #13832
Closed
4 tasks

Rollout plan for critical projects 2FA requirement #12308

di opened this issue Oct 3, 2022 · 0 comments · Fixed by #13832
Labels
2FA meta Meta issues (rollouts, etc) security Security-related issues and pull requests

Comments

@di
Copy link
Member

di commented Oct 3, 2022

Breaking this out from #11625. The following steps should be followed to roll out the critical projects 2FA requirement:

  • Resolve Mandatory 2FA with existing users without 2FA vulnerable to account takeover #11850
  • Evaluate how many critical project maintainers will be affected by enabling the mandate.
    • Ideally this is non-zero, but likely that some projects/maintainers may be unresponsive
    • Depending on the size, potentially do some manual comms to affected maintainers
  • Set TWOFACTORMANDATE_ENABLED to True
    • This makes 2FA required for critical projects and completes the rollout
  • Tweets/announcements about this milestone
@di di added the meta Meta issues (rollouts, etc) label Oct 3, 2022
@miketheman miketheman added the security Security-related issues and pull requests label Mar 30, 2023
@dstufft dstufft added the 2FA label May 26, 2023
@di di closed this as completed in #13832 Jun 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2FA meta Meta issues (rollouts, etc) security Security-related issues and pull requests
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants