{"thread":{"id":"56257","subject":"[QUESTION]Is it possible that git would support two-factor authentication?","startedAt":"2021-08-11T11:01:21Z","lastAt":"2021-08-17T10:20:27Z","messageCount":8,"participants":["lilinchao@oschina.cn","Konstantin Ryabitsev","Derrick Stolee","Theodore Ts'o","brian m. carlson","Johannes Schindelin","Matthew Cheetham"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"432477","messageId":"66e42438fa9311ebaeb60026b95c99cc@oschina.cn","threadId":"56257","inReplyTo":null,"subject":"[QUESTION]Is it possible that git would support two-factor authentication?","fromName":"lilinchao@oschina.cn","fromEmail":"lilinchao@oschina.cn","sentAt":"2021-08-11T11:00:50Z","receivedAt":"2021-08-11T11:01:21Z","isPatch":false,"sender":{"key":"lilinchao@oschina.cn","avatar":null},"body":"Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.\nWhen client clone something, they need  input username and password, it is like a website login process. For security, we can\nenable  2FA during this process.\n\n"},{"id":"432482","messageId":"20210811135055.tqdblurgk3vw5lgm@nitro.local","threadId":"56257","inReplyTo":"66e42438fa9311ebaeb60026b95c99cc@oschina.cn","subject":"Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2021-08-11T13:50:55Z","receivedAt":"2021-08-11T13:51:00Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Wed, Aug 11, 2021 at 07:00:50PM +0800, lilinchao@oschina.cn wrote:\n> Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.\n> When client clone something, they need  input username and password, it is like a website login process. For security, we can\n> enable  2FA during this process.\n\nAs you well know, \"cloning\" a repository can be done via any number of\nmechanisms:\n\n1. locally from another repository on disk\n2. locally, from a git bundle file\n3. remotely, using the anonymous git:// protocol\n4. remotely, using ssh or http(s) protocols\n\n2-factor authentication does not make sense in the first three cases (you\nalready have access to all the objects with 1 and 2, and the git:// protocol\nis public and anonymous by design). For the ssh/https scheme, 2fa is already\nsupported by the underlying protocol, so it does not make sense for git to\nimplement it again on the application level.\n\nHope this helps.\n\n-K\n"},{"id":"432483","messageId":"7c5df686-79ad-1cd8-6f14-d97e1b88bbfb@gmail.com","threadId":"56257","inReplyTo":"66e42438fa9311ebaeb60026b95c99cc@oschina.cn","subject":"Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"Derrick Stolee","fromEmail":"stolee@gmail.com","sentAt":"2021-08-11T13:54:03Z","receivedAt":"2021-08-11T13:54:08Z","isPatch":false,"sender":{"key":"stolee@gmail.com","avatar":"https://avatars.githubusercontent.com/u/570044?v=4"},"body":"On 8/11/2021 7:00 AM, lilinchao@oschina.cn wrote:\n> Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.\n> When client clone something, they need  input username and password, it is like a website login process. For security, we can\n> enable  2FA during this process.\n\nTypically, this is handled at the credential helper layer, which\nis a tool outside of the Git codebase that can more closely work\nwith such 2FA/MFA requirements. For example, GCM Core [1] supports\n2FA with GitHub, Azure DevOps, and BitBucket.\n\n[1] https://github.com/microsoft/Git-Credential-Manager-Core\n\nThe mechanism is that Git attempts an operation and gets an error\ncode, so it asks for a credential from the helper. The helper\nthen communicates with the server to do whatever authentication\nis required, including possibly performing multi-factor auth.\nAll of these details are hidden from Git, which is good.\n\nI've CC'd Matthew Cheetham who is the maintainer of GCM Core to\ncorrect me if I misstated anything here.\n\nThanks,\n-Stolee\n"},{"id":"432488","messageId":"YRPrWSj2TbshKTor@mit.edu","threadId":"56257","inReplyTo":"20210811135055.tqdblurgk3vw5lgm@nitro.local","subject":"Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"Theodore Ts'o","fromEmail":"tytso@mit.edu","sentAt":"2021-08-11T15:23:05Z","receivedAt":"2021-08-11T15:23:45Z","isPatch":false,"sender":{"key":"tytso@mit.edu","avatar":"https://avatars.githubusercontent.com/u/51416?v=4"},"body":"On Wed, Aug 11, 2021 at 09:50:55AM -0400, Konstantin Ryabitsev wrote:\n> On Wed, Aug 11, 2021 at 07:00:50PM +0800, lilinchao@oschina.cn wrote:\n> > Many websites support two-factor authentication(2FA) to log in,\n> > like Github, I wander if we can support it in application layer.\n> > When client clone something, they need  input username and\n> > password, it is like a website login process. For security, we can\n> > enable  2FA during this process.\n> \n> As you well know, \"cloning\" a repository can be done via any number of\n> mechanisms:\n> \n> 1. locally from another repository on disk\n> 2. locally, from a git bundle file\n> 3. remotely, using the anonymous git:// protocol\n> 4. remotely, using ssh or http(s) protocols\n> \n> 2-factor authentication does not make sense in the first three cases (you\n> already have access to all the objects with 1 and 2, and the git:// protocol\n> is public and anonymous by design). For the ssh/https scheme, 2fa is already\n> supported by the underlying protocol, so it does not make sense for git to\n> implement it again on the application level.\n\nIt might be helpful to be explicit about what *kind* of two-factor\nauthentication you are interested in.  There are multiple different\nkinds of 2FA systems, including ssh keys stored on a hardware token\nsuch as a smartcard or a Yuibikey, U2F Fido systems using a security\nkey, TOTP or HOTP otp systems, etc.\n\nEach of these systems have different tradeoffs in terms of ease of use\nfrom the user perspective (both from the point of view of initial\nsetup and day-to-day use after getting set up), security against MITM\nattacks, and ease of integration/deployment from the system\nadministrator's perspective.\n\nCheers,\n\n\t\t\t\t\t\t- Ted\n"},{"id":"432629","messageId":"0d301aeafc0b11ebb27d0024e87935e7@oschina.cn","threadId":"56257","inReplyTo":"9b199de2faab11eba548a4badb2c2b1195555@gmail.com","subject":"Re: Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"lilinchao@oschina.cn","fromEmail":"lilinchao@oschina.cn","sentAt":"2021-08-13T07:49:52Z","receivedAt":"2021-08-13T07:50:22Z","isPatch":false,"sender":{"key":"lilinchao@oschina.cn","avatar":null},"body":">On 8/11/2021 7:00 AM, lilinchao@oschina.cn wrote:\n>> Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.\n>> When client clone something, they need  input username and password, it is like a website login process. For security, we can\n>> enable  2FA during this process.\n>\n>Typically, this is handled at the credential helper layer, which\n>is a tool outside of the Git codebase that can more closely work\n>with such 2FA/MFA requirements. For example, GCM Core [1] supports\n>2FA with GitHub, Azure DevOps, and BitBucket.\n>\n>[1] https://github.com/microsoft/Git-Credential-Manager-Core\n>\n>The mechanism is that Git attempts an operation and gets an error\n>code, so it asks for a credential from the helper. The helper\n>then communicates with the server to do whatever authentication\n>is required, including possibly performing multi-factor auth.\n>All of these details are hidden from Git, which is good.\n>\nIndeed, this is good, I've experienced this tool these days at WSL and Windows,\nbut finally I hope these features can be supported by Git itself, and then the user end can easily configure it.\n\n>I've CC'd Matthew Cheetham who is the maintainer of GCM Core to\n>correct me if I misstated anything here.\n\nThanks.\n\n"},{"id":"432719","messageId":"YRb4tkINrABgaHGu@camp.crustytoothpaste.net","threadId":"56257","inReplyTo":"20210811135055.tqdblurgk3vw5lgm@nitro.local","subject":"Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2021-08-13T22:56:54Z","receivedAt":"2021-08-13T22:57:30Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2021-08-11 at 13:50:55, Konstantin Ryabitsev wrote:\n> 2-factor authentication does not make sense in the first three cases (you\n> already have access to all the objects with 1 and 2, and the git:// protocol\n> is public and anonymous by design). For the ssh/https scheme, 2fa is already\n> supported by the underlying protocol, so it does not make sense for git to\n> implement it again on the application level.\n\nTo expand on this a little bit, you can absolutely set up a Git server\nwith OpenSSH and require 2FA with OpenSSH.  That should work just fine.\nYou could also leverage a custom credential helper for HTTPS to require\na 2FA code, send it to a server, which would issue a one-time token for\nBasic auth.  All of this is achievable with existing tooling that we\nhave today or tooling that can be easily built.\n\nOne note here is that as a practical matter, many people require\nautomated cloning of repositories, such as to use their CI systems.\nThose systems generally cannot practically use 2FA and the security\nwould not be improved if they did, so some solution that allows for that\nto work is going to be required.\n\nAlso, in workflows that require many repositories to be cloned, it can\nbe kind of a hassle to wait for one clone to complete, enter the 2FA\ncode (or touch the YubiKey) for the second clone, wait for it to\ncomplete, do 2FA for the third clone, and so on.  So while you can do\nthis, it's important to keep in mind that there are some user experience\ntradeoffs here that need to be considered as well.\n-- \nbrian m. carlson (he/him or they/them)\nToronto, Ontario, CA\n"},{"id":"432751","messageId":"nycvar.QRO.7.76.6.2108150001480.59@tvgsbejvaqbjf.bet","threadId":"56257","inReplyTo":"0d301aeafc0b11ebb27d0024e87935e7@oschina.cn","subject":"Re: Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2021-08-14T22:02:48Z","receivedAt":"2021-08-14T22:03:08Z","isPatch":false,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Fri, 13 Aug 2021, lilinchao@oschina.cn wrote:\n\n> >On 8/11/2021 7:00 AM, lilinchao@oschina.cn wrote:\n> >> Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.\n> >> When client clone something, they need  input username and password, it is like a website login process. For security, we can\n> >> enable  2FA during this process.\n> >\n> >Typically, this is handled at the credential helper layer, which\n> >is a tool outside of the Git codebase that can more closely work\n> >with such 2FA/MFA requirements. For example, GCM Core [1] supports\n> >2FA with GitHub, Azure DevOps, and BitBucket.\n> >\n> >[1] https://github.com/microsoft/Git-Credential-Manager-Core\n> >\n> >The mechanism is that Git attempts an operation and gets an error\n> >code, so it asks for a credential from the helper. The helper\n> >then communicates with the server to do whatever authentication\n> >is required, including possibly performing multi-factor auth.\n> >All of these details are hidden from Git, which is good.\n> >\n> Indeed, this is good, I've experienced this tool these days at WSL and Windows,\n> but finally I hope these features can be supported by Git itself, and then the user end can easily configure it.\n\nThe problem here is that 2FA is highly provider-specific. And that's why\nGit itself refuses to implement it. Hence the credential helper layer.\n\nCiao,\nJohannes\n"},{"id":"432936","messageId":"673E5460-E431-42B9-943A-E5AF47CB4508@github.com","threadId":"56257","inReplyTo":"D8CFA50F-266A-4995-8058-D29A2D490D5F@github.com","subject":"Re: [QUESTION]Is it possible that git would support two-factor authentication?","fromName":"Matthew Cheetham","fromEmail":"mjcheetham@github.com","sentAt":"2021-08-17T10:19:53Z","receivedAt":"2021-08-17T10:20:27Z","isPatch":false,"sender":{"key":"mjcheetham@github.com","avatar":null},"body":"(Re-sending, this time without HTML)\n\nHello!\n\n> On 14 Aug 2021, at 11:02 pm, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:\n> \n> Hi,\n> \n> On Fri, 13 Aug 2021, lilinchao@oschina.cn wrote:\n> \n>>> On 8/11/2021 7:00 AM, lilinchao@oschina.cn wrote:\n>>>> Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.\n>>>> When client clone something, they need  input username and password, it is like a website login process. For security, we can\n>>>> enable  2FA during this process.\n>>> \n>>> Typically, this is handled at the credential helper layer, which\n>>> is a tool outside of the Git codebase that can more closely work\n>>> with such 2FA/MFA requirements. For example, GCM Core [1] supports\n>>> 2FA with GitHub, Azure DevOps, and BitBucket.\n>>> \n>>> [1] https://github.com/microsoft/Git-Credential-Manager-Core\n>>> \n>>> The mechanism is that Git attempts an operation and gets an error\n>>> code, so it asks for a credential from the helper. The helper\n>>> then communicates with the server to do whatever authentication\n>>> is required, including possibly performing multi-factor auth.\n>>> All of these details are hidden from Git, which is good.\n>>> \n>> Indeed, this is good, I've experienced this tool these days at WSL and Windows,\n>> but finally I hope these features can be supported by Git itself, and then the user end can easily configure it.\n> \n> The problem here is that 2FA is highly provider-specific. And that's why\n> Git itself refuses to implement it. Hence the credential helper layer.\n> \n> Ciao,\n> Johannes\n\n\nJohannes and Derrick are correct. Sadly, there is no standard “modern\" authentication/authorization stack that Git could support in practice.\n\nYou may think of OAuth2.0 as being a good choice, and you’d be right for the most part! However there are several shortcomings today.\nPlenty of vendors implement OAuth2 in different ways (technically they’re not following RFC 6749 [1]), or have extensions to the specification that end up being required for most use.\n\nAt the same time there’s no standard discovery mechanism for the various required endpoints to avoid having the Git project “hardcode” this configuration for each provider - the Git project should be agnostic.\n\nOpenID Connect [2] extends OAuth2 with some useful things like endpoint discovery [3], but that is also optional to implement and still requires some server-side registration and administration (that is vendor specific).\n\nThere’s also the question of user interaction. Often this is tied to specific, opinionated choices like: user agent (browser), operating system integrations, YubiKey or custom multi-factor authentication solutions (SMS? biometrics? OTP apps?).\n\nThere may be more that Git can do to surface authN/Z challenges to a credential helper (such at Git Credential Manager [4]) that might help in making auth in a post-password world less painful. The project is open to contributions to any vendor or auth stack.\n\n[1] https://datatracker.ietf.org/doc/html/rfc6749\n[2] https://openid.net/specs/openid-connect-core-1_0.html\n[3] https://openid.net/specs/openid-connect-discovery-1_0.html\n[4] https://aka.ms/gcmcore\n\nThanks,\nMatthew\n\n\n"}]}