Requiring Launchpad 2FA from Ubuntu uploaders

Colin Watson cjwatson at ubuntu.com
Tue Aug 14 19:38:44 UTC 2018


On Tue, Aug 14, 2018 at 01:35:00PM -0500, Simon Quigley wrote:
> On 08/14/2018 11:34 AM, Colin Watson wrote:
> > How would this work, even conceptually?  Some kind of extra challenge
> > when doing SFTP uploads or git/bzr pushes to ask for 2FA (and some
> > timeout arrangement so that it isn't hopelessly annoying)?  What about
> > FTP uploads?
> 
> In my opinion, SFTP should be the default for uploads to Ubuntu*, and we
> should phase out FTP. My local /etc/dput.cf has been patched to do this
> for a while now, and it works fine.

The reason we haven't done this is that there's no good way to make it
the default in everyone's dput configuration.

> If this is done, we should be able to use PAM with google-authenticator.

Not an option; Launchpad's SSH endpoints are custom servers, not
OpenSSH, and don't use PAM.

-- 
Colin Watson                                       [cjwatson at ubuntu.com]



More information about the ubuntu-devel mailing list