See the recent discussion in https://lists.fedoraproject.org/archives/search?mlist=devel%40lists.fedoraproject.org&q=Fedora%3A+Inaccurate+and+apparently-unsupervised+actions+by+agentic+AI+system+under+your+control and also discussions about being compliant with the CRA at Flock.
Proposal: Require that members of the provenpackager group set up two-factor authentication in FAS.
provenpackager
How we would actually technically implement this is an open question. I am not yet proposing that we enable this for all packagers given the current issues with 2FA in Fedora that have already been mentioned on the devel thread. But I do think the calculus for provenpackagers is different given how much access they have.
+1 from me
Not sure if we need to create yet another mailing list thread for this since there's already an ongoing discussion .... but it might be good to post on the ML regardless just so that people are aware that this is now actually a concrete proposal.
Yeah, I meant to do that and then forgot :). I just replied to the devel thread.
+1 if the 2FA is not relaying on big tech solutions or "the latest android os" on a phone.
Do we have a self-service MFA recovery method that doesn't involve sending GPG-signed emails to @kevin yet? Otherwise, this effectively forces everyone to have working ability to do GPG-signed emails.
+1 for 2FA for proven packagers. The MFA is an OTP token right now so you can use any app doing OTP tokens.
+1 to requiring this. The first step would be to change the current policy about provenpackagers and 2FA (https://forge.fedoraproject.org/fesco/docs/pulls/90/commits/62ce446ce601d682c51d0013dcd60d221ddd3f38) from "SHOULD use" to "MUST use." I think figuring out how to enforce this can be a separate step.
There is currently not a self-service process for it, but I was told that GPG-signed emails are not the only supported mechanism for recovery. When there is no GPG key configured in FAS, it can also be recovered by proving access to SSH keys registered in FAS or some Red Hat internal thing for Red Hatters.
+1
I think we should tell people to always enroll at least two tokens, e.g. a hardware token and freeotp on the phone, or maybe even three.
I tried to enroll a Nitrokey today, and it works, but https://docs.nitrokey.com/software/nitropy/ is not packaged for Fedora. It'd be nice to add that.
Also, we should have good instructions on enrollment for Yubikeys, Nitrokeys, Freeotp, and whatever other popular stuff is out there.
I talked to various folks about this at flock and also just posted to that devel list thread the caveats that come to mind.
I also promised @gotmax23 to run the script and see how many people we are affecting here. I'll look for that script and run it and report back when I get caught up enough to do so.
Just a quick script run ( I haven't checked too closely to see if there's any bugs)
There are 114 provenpackagers. 59 of them do not have a otp enrolled.
So, about 52%
I opened https://forge.fedoraproject.org/fesco/docs/pulls/144 to change the policy.
As for enforcing it...
59 of them do not have a otp enrolled.
We can manually check for 2FA enrollment when adding any new provenpackagers as kevin pointed out, but what do we want to do about these? We don't currently have a way to block access to services like Koji based on lack of 2FA, but we can set a flag date and directly email users and remove users from provenpackager who haven't set 2FA by the flag date. That kind of stinks, though :(.
Let's put this on the meeting agenda so we can figure out how to proceed with the implementation.
Metadata Update from @zbyszek: - Issue tagged with: meeting
This topic is on the agenda for today's meeting: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/HKQ332NLB7YKBY6AM35PXZ6NRWVAMUI6/
From today's meeting:
AGREED: Two-factor authentication will be required for members of the provenpackager group. There will be 3 month grace period for existing group members, after which users that don't have 2FA set up will be removed from the group. (+7, 1, -0) (@decathorpe:fedora.im, 18:17:15)
(Meeting log at 18:17:15)
Full text of the agreed-upon proposal:
Metadata Update from @decathorpe: - Issue untagged with: meeting - Issue tagged with: document it
Subject: Two-factor authentication required for provenpackager members
Hi everyone,
FESCo has voted to require two-factor authentication (2FA) for all members of the provenpackager group. Current provenpackager members without 2FA enabled in Fedora Accounts must take action before 2026-09-22.
Please see https://docs.fedoraproject.org/en-US/fedora-accounts/user/#twofactor for more information on setting up 2FA in the Fedora Accounts System. It is recommended to maintain a backup of your 2FA tokens and/or enroll multiple devices (e.g., a hardware security device and a mobile authenticator app).
Any new users applying to the provenpackager group must have 2FA set up in Fedora Accounts.
For existing members who do not have 2FA configured, there is a three month grace period (2026-09-22) to set up 2FA in Fedora Accounts. Affected users will be emailed directly. provenpackager members who have not enabled 2FA by 2026-09-22 will be removed from the provenpackager group. provenpackager members removed during this process can be reinstated once they configure 2FA by filing a ticket with Fedora Infrastructure --- they do NOT need to re-apply with FESCo for provenpackager access.
Here's a rough draft of an announcement. Feedback welcome!
I think that looks fine.