psf / psf-tuf-runbook Goto Github PK
View Code? Open in Web Editor NEWA runbook for the PSF, for TUF key setup and initial signing operations to bootstrap signing for PyPI.
A runbook for the PSF, for TUF key setup and initial signing operations to bootstrap signing for PyPI.
nitrohsm-provision should prompt for security officer pin after starting.
this led to leaking of a single character, and later the full SO pin for one HSM during our ceremony on 2020-10-30, requiring a diceware break.
Due to COVID-19, the key generation and signing ceremonies will take place virtually, conducted by @ewdurbin and @woodruffw. To increase faith in the rigor and honesty of the ceremony, the following should be done:
A runbook for pre-ceremony items should be written. The pre-ceremony should be performed either the night before or immediately before the actual ceremony.
This ceremony needs to include:
The Raspberry Pi should be flashed with an image that's been pre-loaded with OpenSC and our provisioning binaries, to minimize build problems.
Checklist:
Instead of terminating immediately, yubihsm-provision
and nitrohsm-provision
should loop until the user provides the correct authentication key/SO pin/user pin.
This will avoid the need to generate additional backup keys and PINs during the pre-ceremony, and makes the ceremony process a bit less stressful.
The pre-ceremony needs three separate diceware processes:
The following tasks need to be accomplished before we can attempt the generation and signing ceremonies:
Purchases:
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.