git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Multi Factor Authentication for GIT software

From
Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Date
Jun 18, 2024, 13:41 UTC
Message-ID
<20240618-grinning-kagu-of-examination-bb4e1f@meerkat>
In-Reply-To
<CWXP265MB3013B13F4BC4D7574E6E86E281CE2@CWXP265MB3013.GBRP265.PROD.OUTLOOK.COM>
On Tue, Jun 18, 2024 at 12:19:19PM GMT, ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT) wrote:
Show 7 quoted lines
> Dear Git
> 
> I am writing to enquire about multi factor authentication on cloud hosted
> software. As part of our ongoing efforts to enhance cybersecurity and
> protect sensitive data, we are seeking information related to the NHS
> England Multi-Factor Authentication (MFA) Policy with regards to software
> products which we have from your company.

There is no company, so this questionnaire is not relevant. Git is an open-source project without any one particular entity "owning" it.

To answer your question specifically, git does not have a builtin authentication layer -- it relies on the underlying network protocol for this purpose. Any MFA implementation and enforcement would be dependent on the protocol used to access git repositories.

I recommend using ssh pre-shared keys on FIDO2-capable tokens -- it's the most robust and least user-hostile option in my experience.

-K
Previous: ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT)Next: Konstantin Khomoutov
Message 2 of 4 in “Multi Factor Authentication for GIT software”
  1. ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT)Jun 18, 2024
  2. Konstantin RyabitsevJun 18, 2024
  3. Konstantin KhomoutovJun 18, 2024
  4. ELFORD, Richard (NHS SOUTH, CENTRAL AND WEST COMMISSIONING SUPPORT UNIT)Jun 18, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.