Closed Bug 828726 Opened 13 years ago Closed 13 years ago

request to share SSL cert private key with developers

Categories

(Security Assurance :: General, task)

x86_64
Linux
task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: gene, Assigned: jstevensen)

References

Details

In Bug 827601, we're tracking the name change of an AWS system named notoriousb2g.personatest.org to native-persona.org. This is in advance of the b2g launch. This system hasn't yet been productionized and is owned and administered by engineering. https://github.com/mozilla-b2g/gaia/pull/7365 In order to get this system working with it's new name, we've had a cert issued for it in Bug 828486. I'd like to confirm that the private key for the SSL cert can be installed on this dev owned box. I imagine that when this service gets moved into production we'll want to change the cert in order to keep it secure?
Blocks: 827601
Assignee: nobody → jstevensen
So, we're moving the developer system in AWS to a production?
blocking-basecamp: --- → ?
michal` jedp and I chatted in IRC and jedp is going to enable ssh access to opsec on the box.
We will not block on this. Please try to get it done in time, if not, we will deliver the right url as a release note/follow-on patch.
blocking-basecamp: ? → -
I don't know the background or the context of this request, but we should not install the private ssl keys on dev boxes. I suspect this can be worked around?
(In reply to Joe Stevensen [:joes] from comment #4) > I don't know the background or the context of this request, but we should > not install the private ssl keys on dev boxes. I suspect this can be worked > around? Just the public keys - so they can ssh in
(In reply to Gene Wood [:gene] from comment #2) > michal` jedp and I chatted in IRC and jedp is going to enable ssh access to > opsec on the box. Just waiting for michal` to email me public keys of anyone who needs ssh access to the box. I'll install them as soon as I have them.
I've installed the infrasec_gen_1 key into the ec2-user on the machine. Connect with : ssh ec2-user@native-persona.org
Joes, I've put the key on the dev box. I can take it off if need be.
Who setup/owns this host? I'd like to chat with them this morning. Also, what AWS account is this under?
jparsons owns the host. I'm happy to join the conversation for technical consultation. Propose a time and I'll be there.
Met with Gene and Jed. We are ok with moving ahead on this. We'll work directly with Jed to secure this host in the meantime.
Nothing left to do here.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Component: Operations Security (OpSec): General → General
Product: mozilla.org → Enterprise Information Security
You need to log in before you can comment on or make changes to this bug.