Project

General

Profile

Actions

Support #384

open

Support #311: OAM - Security Hardening Auditing and Compliance

OAM: 2FA (SSH/Cockpit/Webmin)

Support #384: OAM: 2FA (SSH/Cockpit/Webmin)

Added by Charles N 1 day ago. Updated 1 day ago.

Status:
Feedback
Priority:
Normal
Assignee:
Target version:
-
Start date:
08/06/2026
Due date:
% Done:

0%

Estimated time:

Description

Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).

Lock down the localuser account with mandatory 2FA (TOTP) across all entry points: SSH, Cockpit, Webmin.

Scope

  • Finish/verify security_2fa KNELIAC role (TOTP for SSH/Cockpit/Webmin - partially done)
  • Enforce mandatory 2FA on localuser across all systems
  • Validate in sectestbed-* before prod

Context

  • Partial work done: 2FA (TOTP for SSH/Cockpit/Webmin) via security_2fa role.
  • Roles executed via tsys-awx (AWX).

Dependencies

Depends on #379 (test lab). Blocks #385 (SSH certificates).


Related issues 2 (2 open0 closed)

Blocks Known Element Enterprises - Technology & Facility Services - Support #385: OAM: SSH certificates (replace static keys)FeedbackCharles N08/06/2026

Actions
Blocked by Known Element Enterprises - Technology & Facility Services - Support #379: OAM: Compliance test lab (sectestbed-* vms)FeedbackCharles N08/06/2026

Actions
Actions

Also available in: PDF Atom