Ceremony description | RA Ceremony CA Ceremony Key Change Over RA Merger RA Move |
---|
Date and time for the ceremony |
|
---|
Status for the ceremony | Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
---|
Date and time for the activation, switchover and revoke |
|
---|
Status for the activation, switchover and revoke | Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
---|
References |
|
---|
Resources bank and TSP:
Role | Name | Contact information |
---|
Key custodian |
|
|
Other |
|
|
Resources Vipps:
Role | Name | Contact information |
---|
Coordinator |
|
|
PKI |
|
|
App |
|
|
Before the ceremony:
Step | Description | Responsible | Deadline | Status | Documents and notes |
---|
1) Initiate steps | The respective TSP or Bank will require BITS approval for the following move or merger before ordering an RA ceremony. | TSP or Bank |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
2) Internal steps | The respective TSP or Bank will require to have in place internal routines for move or merger of RA's. Such as: - How to deal with the OTP tokens
- End user impact
- Information to end users
- How to deal with logs and how/who to archive (admin logs for certificates)
| TSP or Bank |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
3) Formal order to Vipps | The respective TSP or Bank have to create and send a formal order to Vipps. Either on a signed or electronically signed document by TSP or Bank. This order should contain: - The purpose of the move or merger of the mention RA
- Detailed move or merger from and to what CA
| TSP or Bank |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
4) Order forms to Vipps | The respective TSP or Bank have to fill out required order forms and send it to Vipps signed before or during the RA ceremony. A copy must be sent before the RA ceremony. Order forms templates can be found here: Order forms and information | TSP or Bank |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
5) Make sure that the prerequisites are in order | RA XML request and Primary CAO token "Dongle" The RA XML request must be created on the TSP system, for example through HAT tool. Primary CAO token is normally stored in a safe at the respective TSP (CA responsible). The respective Key Custodian for the TSP is responsible to carry and bring the RA XML request and the Primary CAO token "dongle" to the RA ceremony. USB stick and Identification Vipps recommend that Key Custodian always bring a new and unused USB stick and approved identification such as passport or driver license. If the Key Custodian is a non-Norwegian citizen, they must bring their passport. | Key custodian for TSP |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
6) RA ceremony coordination | Vipps will ensure that the following is in place, before going further: - BITS approval
If not provided by the
|
TPS - TSP or Bank, contact BITS (Andreas Havsberg Andreas.Havsberg@bits.no or Torgeir Sørvik torgeir.sorvik@bits.no) and verify with them
- Formal Order received
- Order forms
- Signed - Naming of RA (Required)
- Signed - Revoke RA XML Request (Optional)
- TSPs Primary CAO token
- TSPs/Bank RA XML Request
If all is in place: all stakeholders align and agree on date and time for the following: - RA ceremony
- Activation of New RA XML Sign Certificate
- Switchover
- Revoke RA XML (Optional)
Normally step 2, 3 and 4 happens within the same 24h. |
TSP, Bank and Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
| Avventer tilbakemelding om fellesmail til Bits |
7) Invitations | Vipps are to invite for RA ceremony and the Switchover. These invitation should contain, but not limited to: - Purpose and description
- Date
- Time
- Duration
- Virtual Meeting Link or Address
- Attendees and contact points
- Information on what to bring
| Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
Ceremony:
The Key Custodian for the respective TSPs is on-site with their Primary CAO token and the RA XML sign request.
Step | Description | Responsible | Deadline | Status | Documents and notes |
---|
8) Pre RA ceremony check | - Key Custodian ID check
- USB virus scan (USB stick that contains the RA XML Sign request)
- All required documentation in place
- Note that RA naming order forms are to be stored in the BankID High secure room
- Important that it is the original document (not scan or copies)
- If the documentation is signed with electronic signing, then a copy of that are to be stored in the BankID high secure room
| TSP, Bank and Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
9) Perform RA ceremony | Issue New RA XML/SSL certificate(s) on New CA | TSP, Bank and Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
After the ceremony:
Step | Description | Responsible | Deadline | Status | Documents and notes |
---|
10) Activation of the new RA XML sign | Request activation of New RA XML Sign certificate(s) in BankID COI. This is normally done during the same day as the Switchover. | TSP, Bank and Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
11) |
Switchover switchover - cutover issuing CA in BankID COI from old to New CA
- Run test case sets to verify
- If successful, move to the next step
- If unsuccessful, investigate and resolve then move to next step
- if unsuccessful, not possible to fix, do a rollback
- When rollback is done, run test case sets to verify
- Order revoke of old RA XML Sign certificate in BankID COI (optional)
This is normally done at midnight 00:00. | TSP, Bank and Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
|
|
12) Renewals (End users, merchants etc) | - Bank renew end user BankID certificates
- Bank asks merchants to renew merchant BankID's using HAT
- Possible change of OTP Service by adding new and then removing old for each Banklagret BankID
| TSP, Bank and Vipps |
| Status |
---|
colour | Yellow |
---|
title | In progress |
---|
|
Status |
---|
colour | Green |
---|
title | completed |
---|
|
| Input fra Knut Erik? |