Closed
Bug 828726
Opened 13 years ago
Closed 13 years ago
request to share SSL cert private key with developers
Categories
(Security Assurance :: General, task)
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: gene, Assigned: jstevensen)
References
Details
In Bug 827601, we're tracking the name change of an AWS system named notoriousb2g.personatest.org to native-persona.org. This is in advance of the b2g launch. This system hasn't yet been productionized and is owned and administered by engineering.
https://github.com/mozilla-b2g/gaia/pull/7365
In order to get this system working with it's new name, we've had a cert issued for it in Bug 828486.
I'd like to confirm that the private key for the SSL cert can be installed on this dev owned box. I imagine that when this service gets moved into production we'll want to change the cert in order to keep it secure?
Assignee: nobody → jstevensen
Comment 1•13 years ago
|
||
So, we're moving the developer system in AWS to a production?
Updated•13 years ago
|
blocking-basecamp: --- → ?
| Reporter | ||
Comment 2•13 years ago
|
||
michal` jedp and I chatted in IRC and jedp is going to enable ssh access to opsec on the box.
Comment 3•13 years ago
|
||
We will not block on this. Please try to get it done in time, if not, we will deliver the right url as a release note/follow-on patch.
blocking-basecamp: ? → -
| Assignee | ||
Comment 4•13 years ago
|
||
I don't know the background or the context of this request, but we should not install the private ssl keys on dev boxes. I suspect this can be worked around?
Comment 5•13 years ago
|
||
(In reply to Joe Stevensen [:joes] from comment #4)
> I don't know the background or the context of this request, but we should
> not install the private ssl keys on dev boxes. I suspect this can be worked
> around?
Just the public keys - so they can ssh in
Comment 6•13 years ago
|
||
(In reply to Gene Wood [:gene] from comment #2)
> michal` jedp and I chatted in IRC and jedp is going to enable ssh access to
> opsec on the box.
Just waiting for michal` to email me public keys of anyone who needs ssh access to the box. I'll install them as soon as I have them.
| Reporter | ||
Comment 7•13 years ago
|
||
I've installed the infrasec_gen_1 key into the ec2-user on the machine. Connect with :
ssh ec2-user@native-persona.org
| Reporter | ||
Comment 8•13 years ago
|
||
Joes, I've put the key on the dev box. I can take it off if need be.
| Assignee | ||
Comment 9•13 years ago
|
||
Who setup/owns this host? I'd like to chat with them this morning.
Also, what AWS account is this under?
| Reporter | ||
Comment 10•13 years ago
|
||
jparsons owns the host. I'm happy to join the conversation for technical consultation. Propose a time and I'll be there.
| Assignee | ||
Comment 11•13 years ago
|
||
Met with Gene and Jed. We are ok with moving ahead on this. We'll work directly with Jed to secure this host in the meantime.
| Assignee | ||
Comment 12•13 years ago
|
||
Nothing left to do here.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Updated•10 years ago
|
Component: Operations Security (OpSec): General → General
Product: mozilla.org → Enterprise Information Security
You need to log in
before you can comment on or make changes to this bug.
Description
•