v16: 2FA access-review evidence via admin users API #79

Stängd
öppnade 2026-07-17 11:52:21 +00:00 av supernaut · 0 kommentarer
Ägare

Tier 2 v16 follow-up (gated on #73 landing). v16's GET /api/v1/admin/users can list which users have 2FA enabled (PR 12091).

Small script (or reconciler-adjacent read) surfacing 2FA status per user as access-review evidence for the ISO 27001 roadmap (access-control review control). Output should land somewhere auditable (e.g. a dated report kept internally).

Note: web login is SSO-only via Kanidm, so Kanidm's credential policy is the primary control — this evidence mainly covers API/git-credential hygiene and any residual local accounts.

**Tier 2 v16 follow-up** (gated on #73 landing). v16's `GET /api/v1/admin/users` can list which users have 2FA enabled (PR 12091). Small script (or reconciler-adjacent read) surfacing 2FA status per user as **access-review evidence** for the ISO 27001 roadmap (access-control review control). Output should land somewhere auditable (e.g. a dated report kept internally). Note: web login is SSO-only via Kanidm, so Kanidm's credential policy is the primary control — this evidence mainly covers API/git-credential hygiene and any residual local accounts.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#79
Ingen beskrivning angiven.