{"thread":{"id":"61646","subject":"Multi Factor Authentication for GIT software","startedAt":"2024-06-18T12:38:37Z","lastAt":"2024-06-18T15:41:48Z","messageCount":4,"participants":["ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT)","Konstantin Ryabitsev","Konstantin Khomoutov"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"497284","messageId":"CWXP265MB3013B13F4BC4D7574E6E86E281CE2@CWXP265MB3013.GBRP265.PROD.OUTLOOK.COM","threadId":"61646","inReplyTo":null,"subject":"Multi Factor Authentication for GIT software","fromName":"ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT)","fromEmail":"richard.elford@nhs.net","sentAt":"2024-06-18T12:19:19Z","receivedAt":"2024-06-18T12:38:37Z","isPatch":false,"sender":{"key":"richard.elford@nhs.net","avatar":null},"body":"Dear Git\n\nI am writing to enquire about multi factor authentication on cloud hosted software. As part of our ongoing efforts to enhance cybersecurity and protect sensitive data, we are seeking information related to the NHS England Multi-Factor Authentication (MFA) Policy with regards to software products which we have from your company.\n\nCould you please provide us with the following information:\n\n•       Software Name\n•       Name of supplier\n•       Account Manager name\n•       Account Manager email\n•       Account Manager Telephone number\n•       Name of the person completing the survey\n•       Job title of the person completing the survey\n•       Contact number of the person completing the survey\n•       Is the product Internet facing or HSCN facing\n•       What is the System host type\n•       What is the location of the data centre(s) used for the provision of the system\n•       If the solution has 3rd party elements, what are the geographic locations of the 3rd party data centre(s) used for the provision of the system\n•       MFA Status\n•       Date of last status check\n•       Planned date for implementation of MFA\n•       Actual date of MFA functionality deployment\n•       Do you have any alternative security mitigation functionality/plans available to address MFA gaps?  (Example: Conditional access)\n•       Date mitigation option available\n•       Does this system have Admin/Privileged access available for 3rd or 4th parties?\n•       How is the system provided?  (Directly from your Organisation / Partly provided by our Org, but has 3rd party elements / 3rd party provided)\n•       What is the data classification stored on the system? (Use GDPR examples)\n•       Does your organisation hold cyber accreditation directly relevant to the provision of the service (Examples: Cyber Essentials plus, ISO27001, SOC2, DSPT, DTAC, NIST)\n•       When is the contract expiry date with SCWCSU\n•       Number of users / accounts / licenses supplied\n•       When was the last time your product was part of a business continuity and disaster exercise?\n\nWe appreciate your prompt response and any relevant documentation you can share. If you have any additional insights or best practices related to MFA, we would be grateful to hear them.\n\nThank you for your cooperation.\n\n\nRichard Elford\nBusiness Services Manager | Digital, Data and Technology\nNHS South, Central and West\nThird Floor - 360 Bristol – Three Six Zero, Marlborough Street, Bristol, BS1 3NX\n\n\n\nThe information in this email may be confidential and is intended solely for the named addressee(s). If you are not the intended recipient, any disclosure, copying or distribution is prohibited and may be unlawful. Please note that the information contained in this email /attachment(s) may be subject to Public disclosure under the Freedom of Information Act 2000.\n\n\n\n\n************************************************************************************** ******************************\n\nThis message may contain confidential information. If you are not the intended recipient please:\ni) inform the sender that you have received the message in error before deleting it; and\nii) do not disclose, copy or distribute information in this e-mail or take any action in relation to its content (to do so is strictly prohibited and may be unlawful).\nThank you for your co-operation.\n\nNHSmail is the secure email, collaboration and directory service available for all NHS staff in England. NHSmail is approved for exchanging patient data and other sensitive information with NHSmail and other accredited email services.\n\nFor more information and to find out how you can switch visit Joining NHSmail – NHSmail Support<https://support.nhs.net/article-categories/joining-nhsmail/>\n\n"},{"id":"497285","messageId":"20240618-grinning-kagu-of-examination-bb4e1f@meerkat","threadId":"61646","inReplyTo":"CWXP265MB3013B13F4BC4D7574E6E86E281CE2@CWXP265MB3013.GBRP265.PROD.OUTLOOK.COM","subject":"Re: Multi Factor Authentication for GIT software","fromName":"Konstantin Ryabitsev","fromEmail":"konstantin@linuxfoundation.org","sentAt":"2024-06-18T13:41:05Z","receivedAt":"2024-06-18T13:41:10Z","isPatch":false,"sender":{"key":"konstantin@linuxfoundation.org","avatar":"https://gravatar.com/avatar/7cb8827c6de56e1bd2dea16508c6708aa43feed3bf3813bcdacecdf96ceadd79?d=mp&s=160"},"body":"On Tue, Jun 18, 2024 at 12:19:19PM GMT, ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT) wrote:\n> Dear Git\n> \n> I am writing to enquire about multi factor authentication on cloud hosted\n> software. As part of our ongoing efforts to enhance cybersecurity and\n> protect sensitive data, we are seeking information related to the NHS\n> England Multi-Factor Authentication (MFA) Policy with regards to software\n> products which we have from your company.\n\nThere is no company, so this questionnaire is not relevant. Git is an\nopen-source project without any one particular entity \"owning\" it.\n\nTo answer your question specifically, git does not have a builtin\nauthentication layer -- it relies on the underlying network protocol for this\npurpose. Any MFA implementation and enforcement would be dependent on the\nprotocol used to access git repositories.\n\nI recommend using ssh pre-shared keys on FIDO2-capable tokens -- it's the most\nrobust and least user-hostile option in my experience.\n\n-K\n"},{"id":"497286","messageId":"20240618145729.47d34yxe7gw36jyn@carbon","threadId":"61646","inReplyTo":"20240618-grinning-kagu-of-examination-bb4e1f@meerkat","subject":"Re: Multi Factor Authentication for GIT software","fromName":"Konstantin Khomoutov","fromEmail":"kostix@bswap.ru","sentAt":"2024-06-18T14:57:29Z","receivedAt":"2024-06-18T14:57:54Z","isPatch":false,"sender":{"key":"kostix@bswap.ru","avatar":null},"body":"On Tue, Jun 18, 2024 at 09:41:05AM -0400, Konstantin Ryabitsev wrote:\n\n> On Tue, Jun 18, 2024 at 12:19:19PM GMT, ELFORD, Richard (NHS SOUTH, CENTRAL\n> AND WEST COMMISSIONING SUPPORT UNIT) wrote:\n[...]\n> > I am writing to enquire about multi factor authentication on cloud hosted\n> > software.\n> > protect sensitive data, we are seeking information related to the NHS\n> > England Multi-Factor Authentication (MFA) Policy with regards to software\n> > products which we have from your company.\n> \n> There is no company, so this questionnaire is not relevant. Git is an\n> open-source project without any one particular entity \"owning\" it.\n\nRichard, I'd like to make a remark. May be - just may be - you're confusing\nGit and Github or GitLab. Git is a free and open source (F/OSS) piece of\nsoftware, while Github and GitLab (and a plethora of others) are Git hosting\nsolutions which host Git repositories \"in the cloud\". They use Git but have\nno other relation to it.\n\nSo you might want to first check with your IT personnel to make it absolutely\nsure what really is the issue to discuss: Git-based solutions maintained by\nNHS itself or Git-based solutions provided by 3rd parties. In the latter case,\nthe questions like yours should probably be directed to these parties.\n\n"},{"id":"497288","messageId":"CWXP265MB30133DAED31B87A03D0AD53481CE2@CWXP265MB3013.GBRP265.PROD.OUTLOOK.COM","threadId":"61646","inReplyTo":"20240618145729.47d34yxe7gw36jyn@carbon","subject":"RE: Multi Factor Authentication for GIT software","fromName":"ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT)","fromEmail":"richard.elford@nhs.net","sentAt":"2024-06-18T15:41:40Z","receivedAt":"2024-06-18T15:41:48Z","isPatch":false,"sender":{"key":"richard.elford@nhs.net","avatar":null},"body":"Hi Konstantin\n\nThat is very helpful - thank you.\n\nI will pick this up with our IT people and find out what use cases we have, and then get in touch with any third parties as you say.\n\nI really, really appreciate your advice.\n\n\n\nBest regards\n\nRichard Elford\nBusiness Services Manager | Digital, Data and Technology\nNHS South, Central and West\nThird Floor - 360 Bristol – Three Six Zero, Marlborough Street, Bristol, BS1 3NX\n\nCall me on MS Teams T: 07785 601602 E: richard.elford@nhs.net\n\n\n\n-----Original Message-----\nFrom: Konstantin Khomoutov <kostix@bswap.ru>\nSent: Tuesday, June 18, 2024 3:57 PM\nTo: ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT) <richard.elford@nhs.net>\nCc: git@vger.kernel.org; Konstantin Ryabitsev <konstantin@linuxfoundation.org>\nSubject: Re: Multi Factor Authentication for GIT software\n\n[You don't often get email from kostix@bswap.ru. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]\n\nThis message originated from outside of NHSmail. Please do not click links or open attachments unless you recognise the sender and know the content is safe.\n\nOn Tue, Jun 18, 2024 at 09:41:05AM -0400, Konstantin Ryabitsev wrote:\n\n> On Tue, Jun 18, 2024 at 12:19:19PM GMT, ELFORD, Richard (NHS SOUTH,\n> CENTRAL AND WEST COMMISSIONING SUPPORT UNIT) wrote:\n[...]\n> > I am writing to enquire about multi factor authentication on cloud\n> > hosted software.\n> > protect sensitive data, we are seeking information related to the\n> > NHS England Multi-Factor Authentication (MFA) Policy with regards to\n> > software products which we have from your company.\n>\n> There is no company, so this questionnaire is not relevant. Git is an\n> open-source project without any one particular entity \"owning\" it.\n\nRichard, I'd like to make a remark. May be - just may be - you're confusing Git and Github or GitLab. Git is a free and open source (F/OSS) piece of software, while Github and GitLab (and a plethora of others) are Git hosting solutions which host Git repositories \"in the cloud\". They use Git but have no other relation to it.\n\nSo you might want to first check with your IT personnel to make it absolutely sure what really is the issue to discuss: Git-based solutions maintained by NHS itself or Git-based solutions provided by 3rd parties. In the latter case, the questions like yours should probably be directed to these parties.\n\n\n\n************************************************************************************** ******************************\n\nThis message may contain confidential information. If you are not the intended recipient please:\ni) inform the sender that you have received the message in error before deleting it; and\nii) do not disclose, copy or distribute information in this e-mail or take any action in relation to its content (to do so is strictly prohibited and may be unlawful).\nThank you for your co-operation.\n\nNHSmail is the secure email, collaboration and directory service available for all NHS staff in England. NHSmail is approved for exchanging patient data and other sensitive information with NHSmail and other accredited email services.\n\nFor more information and to find out how you can switch visit Joining NHSmail – NHSmail Support<https://support.nhs.net/article-categories/joining-nhsmail/>\n\n"}]}