mojaloop / project

Repo to track product development issues for the Mojaloop project.
Other
22 stars 15 forks source link

SPIKE: Identify an appropriate 2FA tool or technology #3892

Open PaulMakinMojaloop opened 1 month ago

PaulMakinMojaloop commented 1 month ago

Need to identify an appropriate tool, app or technology that can be adopted for Mojaloop deployments. Such a tool must be:

Common proprietary solutions might include Authy, Microsoft Authenticator and Google Authenticator. However, preference should be given to open source alternatives such as FreeOTP and 2FAS.

JulieG19 commented 3 weeks ago

We need to work under the assumption that the IAM solution is keyclock: which means that effectively there will be two sets of epics: 1. selection of appropriate 2FA tools and 2. Integration of existing IAM solution with vNext.

JulieG19 commented 3 weeks ago

Hello, as discussed the work for now on this spike is to do a comparision analysis (mentioning pros/cons of each tool based on a set of pre-defined criteria), suggest a best option and prepare an implementation approach to submit to the DA. For now, item 2 in my previous comment will be ignored. We will manage this under a seperate set of stories.

JulieG19 commented 2 weeks ago

Epic to be created for IAM swap and create a dependency on this ticket. We also need a ticket for test coverage. IAM swap needs to go through design thinking before any development happens.