163
edits
Viorelaioia (talk | contribs) |
Viorelaioia (talk | contribs) (Updated FAQ to include info on FXA) |
||
| Line 13: | Line 13: | ||
==== '''Q''': ''How do I login with Mozilla IAM?'' ==== | ==== '''Q''': ''How do I login with Mozilla IAM?'' ==== | ||
Mozilla IAM supports various login methods, such as "LDAP" (Staff logins), GitHub social login, Google social login and email login (which we call "passwordless"). | Mozilla IAM supports various login methods, such as "LDAP" (Staff logins), Firefox Accounts login, GitHub social login, Google social login and email login (which we call "passwordless"). | ||
Certain methods support and enforce the use of two-factor authentication (2FA) and may grant access to more sensitive services. | Certain methods support and enforce the use of two-factor authentication (2FA) and may grant access to more sensitive services. | ||
==== '''Q''': ''Why is my login failing with an error message telling me to use "GitHub/Google/LDAP/etc" instead?'' ==== | ==== '''Q''': ''Why is my login failing with an error message telling me to use "Firefox Accounts/GitHub/Google/LDAP/etc" instead?'' ==== | ||
If your login (your primary email address used by Mozilla IAM) matches an existing account which provides higher | If your login (your primary email address used by Mozilla IAM) matches an existing account which provides higher | ||
| Line 32: | Line 32: | ||
We only allow login, or authentication methods that can verifiably require two-factor authentication (2FA) in order to join any group that may grant you access to data that is not public, such as what we call [https://wiki.mozilla.org/Security/Data_Classification STAFF CONFIDENTIAL data]. | We only allow login, or authentication methods that can verifiably require two-factor authentication (2FA) in order to join any group that may grant you access to data that is not public, such as what we call [https://wiki.mozilla.org/Security/Data_Classification STAFF CONFIDENTIAL data]. | ||
At the time of writing, only LDAP, Google accounts that use our LDAP backend (i.e. '''not''' '@gmail.com' accounts) and GitHub | At the time of writing, only LDAP, Google accounts that use our LDAP backend (i.e. '''not''' '@gmail.com' accounts), Firefox accounts and GitHub accounts support this functionality. | ||
Example: you could get a GitHub account with two-factor authentication enabled. Here's some documentation on how to do this: https://help.github.com/articles/about-two-factor-authentication/ | Example: you could get a GitHub account with two-factor authentication enabled. Here's some documentation on how to do this: https://help.github.com/articles/about-two-factor-authentication/. <br> | ||
Firefox Accounts also supports two-factor-authentication: https://blog.mozilla.org/services/2018/05/22/two-step-authentication-in-firefox-accounts/. | |||
If more authentication methods add support for this in the future and seem to be otherwise safe, we'll gladly allow them as well. | If more authentication methods add support for this in the future and seem to be otherwise safe, we'll gladly allow them as well. | ||
| Line 91: | Line 92: | ||
[[File:Mozillians_-_add_identity.png|450px]] | [[File:Mozillians_-_add_identity.png|450px]] | ||
5. Select “Log in with Github” option in next page. | 5. Select “Log in with Github” option in next page. | ||
[[File: | [[File:1_-_nlx.png|280px]] | ||
6. Click Authorize mozilla. If you’re logged in to github in the same browser, you can skip the next 2 steps. | 6. Click Authorize mozilla. If you’re logged in to github in the same browser, you can skip the next 2 steps. | ||
[[File:Mozillians_-_authorize_mozilla.png|300px]] | [[File:Mozillians_-_authorize_mozilla.png|300px]] | ||
| Line 103: | Line 104: | ||
[[File:Mozillians_-_github_login_identity.png|400px]] | [[File:Mozillians_-_github_login_identity.png|400px]] | ||
11. Trying to login with email to mozillians will return an error page, asking to login with github. | 11. Trying to login with email to mozillians will return an error page, asking to login with github. | ||
[[File: | [[File:2-_error.png|350px]] | ||
==== '''Q''': ''The email address I use to login to my mozillians account matches the primary email of my github account. How can I upgrade my mozillians account from passwordless to github?'' ==== | ==== '''Q''': ''The email address I use to login to my mozillians account matches the primary email of my github account. How can I upgrade my mozillians account from passwordless to github?'' ==== | ||
| Line 109: | Line 110: | ||
1. In the following steps we assume you have 2FA set for your github account. If not, see the steps from [https://wiki.mozilla.org/IAM/Frequently_asked_questions#Q:_How_can_I_set_up_two-factor_authentication_.282FA.29_for_my_github_account.3F here].<br> | 1. In the following steps we assume you have 2FA set for your github account. If not, see the steps from [https://wiki.mozilla.org/IAM/Frequently_asked_questions#Q:_How_can_I_set_up_two-factor_authentication_.282FA.29_for_my_github_account.3F here].<br> | ||
2. Navigate to mozillians page and click Log In/Sign Up button. <br> | 2. Navigate to mozillians page and click Log In/Sign Up button. <br> | ||
3. Select | 3. Select “Continue with Github” method from mozillians login page. <br> | ||
[[File: | [[File:3_-_moz_login.png|350px]] | ||
4. Enter Github credentials. | 4. Enter Github credentials. | ||
[[File:Mozillians_-_login_with_github_to_upgrade_account.png|350px]] | [[File:Mozillians_-_login_with_github_to_upgrade_account.png|350px]] | ||
| Line 118: | Line 119: | ||
[[File:Mozillians_-_upgrade_to_github.png|350px]] | [[File:Mozillians_-_upgrade_to_github.png|350px]] | ||
7. Trying to login with email to mozillians will return an error page, asking to login with github. | 7. Trying to login with email to mozillians will return an error page, asking to login with github. | ||
[[File: | [[File:2-_error.png|350px]] | ||
==== '''Q''': ''The email address I use to login to my mozillians account matches the primary email of my Firefox Accounts account. How can I upgrade my mozillians account from passwordless to Firefox Accounts?'' ==== | |||
1. In the following steps we assume you have 2FA set for your Firefox Accounts account. If not, see the steps from [https://blog.mozilla.org/services/2018/05/22/two-step-authentication-in-firefox-accounts/ here].<br> | |||
2. Navigate to mozillians page and click Log In/Sign Up button. <br> | |||
3. Select “Continue with Firefox” method from mozillians login page. <br> | |||
[[File:3_-_moz_login.png|350px]] | |||
4. Enter Firefox Accounts credentials. | |||
[[File:5_-_fxa_login.png|350px]] | |||
5. Enter 2fa code from your application. | |||
[[File:9_-_fxa_2fa.png|300px]] | |||
6. Navigate to Settings -> Profile Identities section, and verify that Firefox Accounts is set as your login identity. That means this is the only account you can use from now on to login to mozillians. | |||
[[File:8_-_fxa_primary.png|350px]] | |||
7. Trying to login with email to mozillians will return an error page, asking to login with Firefox Accounts. | |||
[[File:7_-_fxa_error.png|350px]] | |||
==== '''Q''': ''How can I upgrade my mozillians account from passwordless to LDAP?'' ==== | ==== '''Q''': ''How can I upgrade my mozillians account from passwordless to LDAP?'' ==== | ||
1. Login to mozillians with your email.<br> | 1. Login to mozillians with your email.<br> | ||
2. Navigate to profile settings page. | 2. Navigate to profile settings page. | ||
[[File:Mozillians_-_go_to_settings.png|350px]] | [[File:Mozillians_-_go_to_settings.png|350px]] | ||
3. Scroll down to “Profile Identities” section and click “Add Identity” button. | 3. Scroll down to “Profile Identities” section and click “Add Identity” button. | ||
[[File:Mozillians_-_add_identity_-_ldap.png|350px]] | [[File:Mozillians_-_add_identity_-_ldap.png|350px]] | ||
4. | 4. Enter your LDAP email in the "Log in with email" field and click "Enter" button. | ||
[[File: | [[File:4_-_add_Ldap_identity.png|300px]] | ||
5. Enter your LDAP | 5. Enter your LDAP password and click "Enter" button. | ||
[[File: | [[File:5_-_add_ldap_password.png|300px]] | ||
6. Enter 2fa code from your application and click "Log In" button. | 6. Enter 2fa code from your application and click "Log In" button. | ||
[[File:Mozillians_-_ldap_-_enter_2fa_code.png|250px]] | [[File:Mozillians_-_ldap_-_enter_2fa_code.png|250px]] | ||
| Line 172: | Line 181: | ||
3. Scroll down to “Profile Identities” section and click “Add Identity” button. | 3. Scroll down to “Profile Identities” section and click “Add Identity” button. | ||
[[File:Mozillians_-_profile_page.png|350px]] | [[File:Mozillians_-_profile_page.png|350px]] | ||
4. | 4. Enter your LDAP email in the "Log in with email" field and click "Enter" button. | ||
[[File: | [[File:10_-_volunteer_LDAP.png|300px]] | ||
5. Enter your | 5. Enter your LDAP password and click "Enter" button. | ||
[[File:Mozillians_- | [[File:5_-_add_ldap_password.png|300px]] | ||
6. Enter 2fa code from your application and click "Log In" button. | |||
[[File:Mozillians_-_ldap_-_enter_2fa_code.png|250px]] | |||
7. Verify that success message is displayed, after adding the new LDAP identity. | |||
[[File:Mozillians_-_success_message.png|350px]] | [[File:Mozillians_-_success_message.png|350px]] | ||
8. Scroll down to “Profile Identities” section and verify that your volunteer LDAP account is set as your login identity. That means this is the only account you can use from now on to login to mozillians. | |||
[[File:Mozillians_-_no_mfa_ldap_added_identity.png|350px]] | [[File:Mozillians_-_no_mfa_ldap_added_identity.png|350px]] | ||
| Line 187: | Line 198: | ||
3. Scroll down to “Profile Identities” section and click “Add Identity” button. | 3. Scroll down to “Profile Identities” section and click “Add Identity” button. | ||
[[File:Mozillians_-_add_identity_google.png|350px]] | [[File:Mozillians_-_add_identity_google.png|350px]] | ||
5. Select "Log in with Google" in the next page. | 5. Select "Log in with Google" in the next page. | ||
[[File: | [[File:3_-_moz_login.png|200px]] | ||
6. Enter your google email, then click Next. | 6. Enter your google email, then click Next. | ||
[[File:Mozillians_-_enter_google_email.png|250px]] | [[File:Mozillians_-_enter_google_email.png|250px]] | ||
| Line 197: | Line 206: | ||
8. Verify that success message is displayed, after adding the new Google identity. | 8. Verify that success message is displayed, after adding the new Google identity. | ||
[[File:Mozillians_-_success_message.png|350px]] | [[File:Mozillians_-_success_message.png|350px]] | ||
9. Scroll down to “Profile Identities” section and verify that your Google account is | 9. Scroll down to “Profile Identities” section and verify that your Google account is in your Contact identities section. | ||
[[File:Mozillians_-_google_identity.png|350px]] | [[File:Mozillians_-_google_identity.png|350px]] | ||
edits