What's new on Cloudsmith

Cloudsmith is your friendly neighbourhood Package Management SaaS; for secure delivery of the world's software. For DevOps-y people.

Improvement
September 30, 2022

Locked Out: Improved Enforcement of 2FA and SAML/SSO

To further strengthen the controls Cloudsmith offers organizations around user access, we've improved how we enforce 2-Factor Authentication (2FA) and SAML/SSO.

Previously, both were only enforced when a user logged into the application and was not required to access the Cloudsmith API or for interactions in the same session beyond login.

What Changed?

The following changes are designed to improve the limitations above:

  • 2-Factor Authentication: For organizations with 2-factor authentication (2FA) enabled, users must have a 2FA device associated with their user account to access that organization in any context via the web UI or the Cloudsmith API.
  • SAML Single Sign-On: For organizations that enforce SAML-only authentication, users must sign in with SAML to access that organization in any context via the web UI. API interactions are not affected.

Things to Note (FAQ)

My repositories are no longer visible; why?

If you log in and your repositories have "disappeared," likely, you don't have 2FA/SAML setup in an organization that requires them. You can enable 2FA (see the supporting docs) within your user account or use the SAML login for your organization to get access back.

I'm an organization owner, but I'm now locked out; why?

If you're an owner of an organization that enforces 2FA/SAML, you'll now find a more significant restriction on enforcement of 2FA and SAML, so it is possible that if you didn't have these enabled before, you'd need to do so now to re-access the org.

My old-style "bot" user can no longer download/upload packages; why?

If you haven't yet adopted our new Service Accounts for automation, you may have standard user "bot" accounts that interact with the Cloudsmith platform programmatically.

If the organization has 2FA enforced, those "bot" users will need to have 2FA set up. Alternatively, we recommend migrating these "bot" users to Service accounts, which are more suited for the purpose!

I'm not sure what to do; can you help me?

Absolutely! If you need any help or want clarity on any of the above, please contact us anytime.

We are ⚡by Beamer