...
Step | Description | Responsible | Task | Deadline | Status | Documents and notes | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1) Set up internal routines | The respective TSP or Bank will require to have in place internal routines for move or merger of RA's. | TSP or Bank | Decide the following:
Note that the TSP/Bank is responsible for handling the end user certificates through the whole process, including revoke of old certificates. |
| Bank ønsker: | |||||||||||
2) BITS Approval | The respective TSP or Bank will require BITS approval for the following move or merger before ordering an RA ceremony. | TSP or Bank |
|
| Information from BITS about the process:
Ny kontaktperson når Andreas slutter? | |||||||||||
3) Formal order to Vipps | The respective TSP or Bank have to create and send a formal order to Vipps as an electronically signed document, signed by TSP or Bank. | TSP or Bank | This order should contain: New RA:
Move or merger of RA:
Sign it electronically and send it by email to marita.gustavsen@vipps.no with cc lise.aas@vipps.no and lam.van.ngo@vipps.no |
| ||||||||||||
4) Send order forms to Vipps | The respective TSP or Bank have to fill out required order forms and send it to Vipps signed before or during the RA ceremony. A copy must be sent before the RA ceremony. | TSP or Bank |
|
| Order form templates can be found here: Order forms and information Skjema for RA Naming legges her | |||||||||||
5) Make sure that the prerequisites are in order | Primary CAO token "Dongle" is normally stored in a safe at the respective TSP (CA responsible). The respective Key Custodian for the TSP is responsible to carry and bring the RA XML request and the Primary CAO token "dongle" to the RA ceremony. | Key custodian for TSP |
|
| ||||||||||||
6) RA ceremony coordination | Vipps will ensure that everything is in place and coordinate the ceremony and switchover with all stakeholders. | Vipps | Check that the following is in place:
If all is in place, all stakeholders align and agree on date and time for the following:
Normally step 2, 3 and 4 happens within the same 24h. |
| ||||||||||||
7) Invitations | Vipps will send out a meeting invite for the ceremony and the switchover. | Vipps | Create and send out the invitation to all stakeholders. The invitation should contain, but not limited to:
|
|
...
Step | Description | Responsible | Task | Deadline | Status | Documents and notes | ||||
---|---|---|---|---|---|---|---|---|---|---|
8) Pre RA ceremony check | Vipps will greet the participants and check that all is OK for moving on with the ceremony. | Vipps |
|
| ||||||
9) Perform RA ceremony | Vipps is to perform the RA ceremony | Vipps | Issue New Vipps will guide the key custodian through issuing of the new RA XML/SSL certificate(s) on New the new CA. Key custodian will need to oversee that the changes made are according to the documentation. |
|
...
Step | Description | Responsible | Task | Deadline | Status | Documents and notes | |||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
10) Request activation | TSP/Bank need to send a request to Vipps | TSP and Bank |
|
| Mal for bestillingen vil bli laget | ||||||||
11) Activation and switchover coordination | Vipps will coordinate the switchover with all stakeholders. | Vipps | Vipps will coordinate with the required resources. If not already set, agree on the date and time for:
Normally happens within the same 24h. |
| |||||||||
12) Activation | Vipps is to activate the new certificates. This is normally done during the same day as the Switchover. | Vipps | Activate the new RA XML Sign certificate(s) in BankID COI. Performed by AO with PKI involved. |
| Fra bank: Her kunne det stått noe om oppbevaring av XML sertifikatet (for eksempel avtale mellom bank og RA leverandør/service provider) og at TSP skal sikre sine hemmeligheter ved retur (?) Har spurt Rune Hagen. | ||||||||
13) ?Certificate check | Check that the certificate is working | TSP and Bank | TSP/Bank needs to check that the new activated certificate is working towards ODS. Check that the new certificate have access to display the existing certificates on the old CA. |
| |||||||||
14) Switchover and revoke | Plan and implement the switchover and revoke. | TSP, Bank and Vipps |
|
| Mal for bestillingen vil bli laget Skjema for revokering legges her | ||||||||
15) Renewals | Renewals of end users, merchants etc. As decided in step 1. | TSP and Bank |
|
|
...