Closed
Bug 1311471
Opened 9 years ago
Closed 9 years ago
RCA 2016-10-19 SSL Certificate for people
Categories
(Infrastructure & Operations :: MOC: Root Cause Analysis, task)
Infrastructure & Operations
MOC: Root Cause Analysis
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: sal, Assigned: Atoll)
Details
(Whiteboard: [waiting on action items] [team:webops])
Please see https://bugzilla.mozilla.org/show_bug.cgi?id=1310484
Please complete the following form to the best of your ability for RCA
https://docs.google.com/document/d/1dc2LiuHWPs5MLBF3tHbgK5FvIytxqafio9nks-9v8S0/edit
Updated•9 years ago
|
Whiteboard: [not filled]
Updated•9 years ago
|
Assignee: nobody → rsoderberg
Updated•9 years ago
|
Whiteboard: [not filled] → [ready for cab]
Updated•9 years ago
|
Whiteboard: [ready for cab] → [partly filled]
Updated•9 years ago
|
Status: NEW → ASSIGNED
Component: MOC: Problems → MOC: Root Cause Analysis
Comment 1•9 years ago
|
||
:atoll are there any actions to take to try and prevent this kind of problem happening in the future?
Updated•9 years ago
|
Whiteboard: [partly filled] → [partly filled] [team:webops]
(In reply to Salvador Espinoza [:sal] from comment #0)
> Please see https://bugzilla.mozilla.org/show_bug.cgi?id=1310484
>
> Please complete the following form to the best of your ability for RCA
> https://docs.google.com/document/d/1dc2LiuHWPs5MLBF3tHbgK5FvIytxqafio9nks-
> 9v8S0/edit
I've completed this form, but I think the form is months out of date, and is missing key fields that other RCA forms contain.
(In reply to Peter Radcliffe [:pir] from comment #1)
> :atoll are there any actions to take to try and prevent this kind of problem
> happening in the future?
Yes.
1) We're patching the scripts on ssl1.private.phx1 to explicitly inform users when a private key is generated, so that they understand that no existing key was found.
2) We documented how to verify the modulus of the private key and the signed certificate, and trained the team on why it's important to do so.
Other steps are being taken to simplify the SSL process, but those steps are not applicable to this particular incident.
Flags: needinfo?(rsoderberg)
Comment 3•9 years ago
|
||
Thanks :atoll, I think there's enough here. Are there bugs for those followup actions we could link to this bug?
Whiteboard: [partly filled] [team:webops] → [ready for cab] [team:webops]
Updated•9 years ago
|
Whiteboard: [ready for cab] [team:webops] → [waiting on action items] [team:webops]
Updated•9 years ago
|
Flags: needinfo?(rsoderberg)
Updated•9 years ago
|
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
You need to log in
before you can comment on or make changes to this bug.
Description
•