Closed Bug 930119 Opened 12 years ago Closed 12 years ago

Configure Marketplace HSM boxes for stage use

Categories

(Security Assurance :: General, task)

x86
macOS
task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: jlaz, Assigned: kang)

References

Details

We have 2 Marketplace HSM boxes racked in PHX that are ready to be configured (Security world, etc). Inventory: https://inventory.mozilla.org/en-US/systems/show/10916/ https://inventory.mozilla.org/en-US/systems/show/10917/ The HSM devices from Emagined were shipped to MTV, and will be sent to PHX1 to be initialized with the servers above. OpSec will coordinate with Svcops to configure the box remotely. Tentative date for PHX trip is 10/29. This bug is to track progress for the work.
Blocks: 877531
we have HSM configuration training next week with :jlaz to prepare for this mainly the cards have to import the correct world. our documentation is at https://mana.mozilla.org/wiki/display/SECURITY/HSM+Operational+Procedures
Assignee: nobody → jstevensen
Assignee: jstevensen → gdestuynder
we went through a quick training session with jlaz and i will help set the stage boxes up as well at your convenience
verified with jlaz that the HSMs were installed and had a security world in the datacenter. jlaz, let me know when you want to go through the key generation and signing
Flags: needinfo?(jlaz)
Scheduled a block of time tomorrow for the stage key generation process
Flags: needinfo?(jlaz)
keys and certs where generated with jlaz yesterday the generation scripts are stored in git-internal at svcops/hsm. I also used that space to store the prod generation scripts, which were only stored on mana before (suboptimal) jlaz, is everything good? (if so, lets close this:)
Flags: needinfo?(jlaz)
I believe we are good now. Thanks again for the help everyone!
Flags: needinfo?(jlaz)
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
Component: Operations Security (OpSec): General → General
Product: mozilla.org → Enterprise Information Security
You need to log in before you can comment on or make changes to this bug.