Ceremony description | RA |
---|
renewal | |||||
Date and time for the ceremony | |||||
---|---|---|---|---|---|
Status for the ceremony |
| ||||
Date and time for the activation, switchover and revoke | |||||
Status for the activation, switchover and revoke |
| ||||
References | |||||
Comments |
Resources bank and TSP:
Role | Name | Contact information |
---|---|---|
Key custodian | ||
Other |
Resources
...
BankID:
Role | Name | Contact information |
---|---|---|
Coordinator | ||
PKI | ||
App |
Definitions:
What | Description |
---|---|
Ceremony | The physical meeting with all necessary participants. |
Activation | When the new certificate is activated on BankID side. |
Before the ceremony:
Step | Description | Responsible | Task | Deadline | Status | Documents and notes |
---|---|---|---|---|---|---|
1) Send order forms to BankID | The respective TSP or Bank have to fill out required order forms and send it to BankID signed before or during the RA ceremony. A copy must be sent before the RA ceremony. | TSP or Bank |
|
|
|
| Order form templates can be found here: Misc forms for BankID Support | ||||||||
2) Make sure that the prerequisites are in order | Primary CAO token "Dongle" is normally stored in a safe at the respective TSP (CA responsible). The respective Key Custodian for the TSP is responsible to carry and bring the RA XML request and the Primary CAO token "dongle" to the RA ceremony. | Key custodian for TSP |
|
| ||||||
3) RA ceremony coordination | BankID will |
coordinate the ceremony and |
activation with all stakeholders. | BankID |
Check that the following is in place:
- Formal order received
- Signed order forms
- Signed - Naming of RA (Required)
- Signed - Revoke RA XML Request (Optional)
- TSPs Primary CAO token
- TSPs/Bank RA XML Request
All stakeholders align and agree on date and time for the following:
|
|
| ||||||
4) Invitations | BankID will send out a meeting invite for the ceremony |
BankID | Create and send out the invitation to all stakeholders. The invitation should contain, but not limited to:
|
|
|
Ceremony:
The Key Custodian for the respective TSPs is on-site with their Primary CAO token and the RA XML sign request.
Step | Description | Responsible | Task | Deadline | Status | Documents and notes |
---|---|---|---|---|---|---|
5) Pre RA ceremony check | BankID will greet the participants and check that all is OK for moving on with the ceremony. | BankID |
|
|
|
| ||||||
6) Perform RA ceremony | BankID is to perform the RA ceremony | BankID | BankID will guide the key custodian through issuing of the |
new RA XML/SSL certificate(s). Key custodian will need to oversee that everything is according to the documentation. |
|
After the ceremony:
Step | Description | Responsible | Task | Deadline | Status | Documents and notes |
---|---|---|---|---|---|---|
7) |
TSP/Bank need to send a request to BankID
- Write a request for activation of New RA XML Sign certificate(s) in BankID COI.
- The request needs to contain the following:
- Time for the activation
- Which originator(s) to activate
- Which CA it concerns
- Send it by email to marita.gustavsen@bidbax.no with cc lise.aas@bidbax.no and lam.van.ngo@bidbax.no
Status | ||
---|---|---|
|
BankID will coordinate with the required resources.
If not already set, agree on the date and time for:
- 1. Activation of New RA XML Sign Certificate
- 2. Revoke RA XML (Optional)
Normally happens within the same 24h.
Status | ||
---|---|---|
|
Activation/ Revocation (optional) | BankID is to activate the new certificates. | BankID | Activate the new RA |
certificate(s) in BankID |
. Normally done within 24 hours after the ceremony. Optional: Revoke the old certificate. Date aggreed upon in step 3. Performed by AO with PKI involved. BankID will inform the TSP/Bank when this has been done. |
|
8) Certificate check | Check that the certificate is working | TSP and Bank | TSP/Bank needs to check that the new activated certificate is working towards ODS. |
Status | ||
---|---|---|
|
Plan and implement the revoke.
- BankID:
- Do the switchover
- Those who perform the switchover will inform the TSP/Bank by phone when it has been done
- TSP/Bank: Run test case sets to verify
- TSP/Bank: If successful, move to the next step
- BankID: If unsuccessful, investigate and resolve then move to next step
- BankID: if unsuccessful, not possible to fix, do a rollback
- Bank/TSP: When rollback is done, run test case sets to verify
- (optional. If not done, the certificate will be active on the old CA until it expires) Bank/TSP: Send an order for revoke of old RA XML Sign certificate in BankID COI by email to marita.gustavsen@bidbax.no with cc lise.aas@bidbax.no and lam.van.ngo@bidbax.no
- (optional) BankID: Revoke the old certificate
Status | ||
---|---|---|
|
Optional: Check that the revoked certificate is no longer working towards ODS. |
|