IAM/Frequently asked questions: Difference between revisions

Automated sync from https://github.com/mozilla/wikimo_content
(Automated sync from https://github.com/mozilla/wikimo_content)
 
(Automated sync from https://github.com/mozilla/wikimo_content)
Line 7: Line 7:


Usually, you'd use Mozilla IAM as Mozilla Staff, or as a contributor with access to the tools and resources Mozilla uses day to day.
Usually, you'd use Mozilla IAM as Mozilla Staff, or as a contributor with access to the tools and resources Mozilla uses day to day.
An example of that would be our Discourse instance: http://discourse.mozilla-community.org/
An example of that would be our Discourse instance: http://discourse.mozilla.org/


Mozilla IAM is '''not''' Firefox Accounts, Persona or part of any Mozilla Product.
Mozilla IAM is '''not''' Firefox Accounts, Persona or part of any Mozilla Product.
Line 14: Line 14:


Mozilla IAM supports various login methods, such as "LDAP" (Staff logins), GitHub social login, Google social login and email login (which we call "passwordless").
Mozilla IAM supports various login methods, such as "LDAP" (Staff logins), GitHub social login, Google social login and email login (which we call "passwordless").
Certain methods support and enforce the use of a 2nd factor for authentication and may grant access to more sensitive services.
Certain methods support and enforce the use of two-factor authentication (2FA) and may grant access to more sensitive services.


==== '''Q''': ''Why is my login failing with an error message telling me to use "GitHub/Google/LDAP/etc" instead?'' ====
==== '''Q''': ''Why is my login failing with an error message telling me to use "GitHub/Google/LDAP/etc" instead?'' ====
Line 21: Line 21:
security, we require that you use the most secure method available to login.
security, we require that you use the most secure method available to login.


Example: LDAP uses 2 factor authentication to verify a user's identity and is safer than using email login
Example: LDAP uses two-factor authentication to verify a user's identity and is safer than using email login
("passwordless").
("passwordless").


Line 31: Line 31:
==== '''Q''': ''I would like access to specific groups, such as the NDA group, but it requires me to use a different login method, why?'' ====
==== '''Q''': ''I would like access to specific groups, such as the NDA group, but it requires me to use a different login method, why?'' ====


We only allow login, or authentication methods that can verifiably require 2 factor authentication in order to join any group that may grant you access to data that is not public, such as what we call [https://wiki.mozilla.org/Security/Data_Classification STAFF CONFIDENTIAL data].
We only allow login, or authentication methods that can verifiably require two-factor authentication (2FA) in order to join any group that may grant you access to data that is not public, such as what we call [https://wiki.mozilla.org/Security/Data_Classification STAFF CONFIDENTIAL data].
At the time of writing, only LDAP, Google accounts that use our LDAP backend (i.e. '''not''' '@gmail.com' accounts) and GitHub account support this functionality.
At the time of writing, only LDAP, Google accounts that use our LDAP backend (i.e. '''not''' '@gmail.com' accounts) and GitHub account support this functionality.


Example: you could get a GitHub account with 2nd factor authentication enabled. Here's some documentation on how to do this: https://help.github.com/articles/about-two-factor-authentication/
Example: you could get a GitHub account with two-factor authentication enabled. Here's some documentation on how to do this: https://help.github.com/articles/about-two-factor-authentication/


If more authentication methods add support for this in the future and seem to be otherwise safe, we'll gladly allow them as well.
If more authentication methods add support for this in the future and seem to be otherwise safe, we'll gladly allow them as well.
Line 41: Line 41:


We no longer allow email logins to access non-PUBLIC data (see previous FAQ item as well).
We no longer allow email logins to access non-PUBLIC data (see previous FAQ item as well).
In order to regain access, please use a login method that supports 2nd factor authentication such as GitHub (with 2nd factor enabled). Here's some documentation on how to do this: https://help.github.com/articles/about-two-factor-authentication/
In order to regain access, please use a login method that supports two-factor authentication (2FA) such as GitHub. Here's some documentation on how to do this: https://help.github.com/articles/about-two-factor-authentication/


==== '''Q''': ''Where is the source code, documentation, etc. for all Mozilla IAM Projects?'' ====
==== '''Q''': ''Where is the source code, documentation, etc. for all Mozilla IAM Projects?'' ====
Confirmed users
502

edits