Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Ceremony description

RA Ceremony

(Key Change Over)

RA Merger

RA Move

Date and time for the ceremony

Status for the ceremony

Status
titlePlanning

Date and time for the activation, switchover and revoke

Status for the activation, switchover and revoke

Status
titlePlanning

References

Comments

Resources bank and TSP:

Role

Name

Contact information

Key custodian

Other

Resources BankID:

Role

Name

Contact information

Coordinator

PKI

App

Definitions:

What

Description

Ceremony

The physical meeting with all necessary participants.
This is when the new RA certificate is created in red zone.

Activation

When the new certificate is activated on BankID side.
This is usually done at another time than the ceremony.

Switchover

When the traffic is switched from the old CA to the new CA.

This is usually done within 24 hours from the activation, but can also be done separately

Only applicable when moving from one CA to another.

Before the ceremony:

Step

Description

Responsible

Task

Deadline

Status

Documents and notes

1) Set up internal routines

The respective TSP or Bank will require to have in place internal routines for move or merger of RA's.

TSP or Bank

Decide the following:

  • How to deal with the OTP tokens

  • End user impact

  • Information to end users

  • How to deal with logs and how/who to archive (admin logs for certificates)

Note that the TSP/Bank is responsible for handling the end user certificates through the whole process, including revoke of old certificates.


Status
titlePlanning


2) BITS Approval

The respective TSP or Bank will require BITS approval for the following move or merger before ordering an RA ceremony.

TSP or Bank

  • The TSP/Bank describes the change

  • Send email to

Lise.Arneberg@bits.no and


Status
titlePlanning

Information from BITS about the process:

View file
nameBankID - Migrering - Prosess for migrering av bank til ny CA.pdf

height

150

3)

Formal

Send order forms to BankID

The respective TSP or Bank have to

create

fill out required order forms and send

a formal order

it to BankID

as an electronically signed document, signed by TSP or Bank

signed before or during the RA ceremony.

A copy must be sent before the RA ceremony.

TSP or Bank

This order should contain

TSP/bank creates a ticket here including the following:

New
  • RA

:
  • Detailed information about the CA
    • order form

    • Approval from BITS (from step 2)

    Move or merger of RA:

    • The purpose of the move or merger of the mentioned RA
    • Detailed move or merger from and to what CA
    • Approval from BITS (from step 2)

    Sign it electronically and create a ticket here with the signed document attached.

    • Revoke RA XML Request (Optional)

    Status
    titlePlanning

    Order form templates can be found here: Misc forms for BankID Support

    4) Send

    order forms

    change request to BankID

    The respective TSP or Bank have to fill out required order forms and send it to BankID signed before or during the RA ceremony.

    A copy must be sent before the RA ceremony.

    BankID needs information from TSP/bank to make sure all internal systems are updated after the change.

    TSP or Bank

    TSP/

    Bank fills out the required order form.Send a copy before the RA ceremony by creating a ticket here

    bank creates a ticket here with all the relevant information.

    Will be done after the activation/ switchover.

    Status
    titlePlanning

    Order form templates can be found here: Misc forms for BankID SupportIf all is in place, all

    Examples:
    Splunk Partnerinnsikt
    BankID App
    Biometri Backoffice
    etc.

    5) Make sure that the prerequisites are in order

    Primary CAO token "Dongle" is normally stored in a safe at the respective TSP (CA responsible).

    The respective Key Custodian for the TSP is responsible to carry and bring the RA XML request and the Primary CAO token "dongle" to the RA ceremony.

    Key custodian for TSP

    • Create an RA XML request on the TSP system, for example through HAT tool.

    • Make sure that the USB stick is new and unused

    • Make sure that the Key Custodian have approved identification such as a passport or driver license (if the Key Custodian is a non-Norwegian citizen, they must bring their passport)


    Status
    titlePlanning


    6) RA ceremony coordination

    BankID will ensure that everything is in place and coordinate the ceremony and switchover with all stakeholders.

    BankID

    Check that the following is in place:

    •  BITS approval - If not provided by the TSP or Bank, contact BITS and verify
    •  Formal order received
    •  Signed order forms
      •  Signed - Naming of RA (Required)
      •  Signed - Revoke RA XML Request (Optional)
    •  TSPs Primary CAO token
    •  TSPs/Bank RA XML Request
    BankID Primary.jpgImage Added

    All stakeholders align and agree on date and time for the following:

    •  1. RA ceremony
    •  2.
    Activation of New RA XML Sign Certificate
    • Switchover
    •  3.
    Switchover  4.
    • Revoke the old RA
    XML
    • Certificate (Optional)
    Normally step 2, 3 and 4 happens within the same 24h.


    Status
    titlePlanning


    7) Invitations

    BankID will send out a meeting invite for the ceremony and the switchover.

    BankID
    BankID Primary.jpgImage Added

    Create and send out the invitation to all stakeholders.

    The invitation should contain, but not limited to:

    • Purpose and description

    • Date

    • Time

    • Duration

    Virtual Meeting Link or
    • Address

    • Attendees and contact points

    • Information on what to bring


    Status
    titlePlanning


    Ceremony:

    The Key Custodian for the respective TSPs is on-site with their Primary CAO token and the RA XML sign request.

    Step

    Description

    Responsible

    Task

    Deadline

    Status

    Documents and notes

    8) Pre RA ceremony check

    BankID will greet the participants and check that all is OK for moving on with the ceremony.

    BankID
    BankID Primary.jpgImage Added

    • Participants need to sign in and out

    • All necessary resources are in place

      • Key Custodian

      • PKI

  • App
    • Key Custodian ID check is done by the SO

    • USB virus scan is done manually before High secure room (USB stick that contains the RA XML Sign request)

    • All required documentation is in place

      • Note that RA naming order forms are to be stored in the BankID High secure room. When the documentation is signed electronically, a copy of the document is to be stored


    Status
    titlePlanning


    9) Perform RA ceremony

    BankID is to perform the RA ceremony

    BankID
    BankID Primary.jpgImage Added

    BankID will guide the key custodian through issuing of the

    new

    new RA XML/SSL certificate(s) on the new CA.

    Key custodian will need to oversee that the changes made are according to the documentation.


    Status
    titlePlanning


    After the ceremony:

    Step

    Description

    Responsible

    Task

    Deadline

    Status

    Documents and notes

    10

    ) Request activation

    TSP/Bank need to send a request to BankID

    TSP and BankWrite a request for activation of New RA XML Sign certificate(s

    )

    in BankID.
  • The request needs to contain the following:
    • Time for the activation
    • Which originator(s) to activate
    • Which CA it concerns
  • Create a ticket here
  • Status
    titlePlanning

    11)

    Activation

    and switchover coordination

    BankID

    will coordinate the switchover with all stakeholders.BankID

    BankID will coordinate with the required resources.

    If not already set, agree on the date and time for:

    •  1. Activation of New RA XML Sign Certificate
    •  2. Switchover 
    •  3. Revoke RA XML (Optional)

    Normally happens within the same 24h.

    Status
    titlePlanning

    12) ActivationBankID BankID

    is to activate the new certificates.

    This is normally done during the same day as the Switchover.

    BankID Primary.jpgImage Added

    Activate the new RA

    XML Sign

    certificate(s) in BankID. Normally done within 24 hours after the ceremony.

    Performed by AO with PKI involved.


    Status
    titlePlanning

    13


    11) Certificate check

    Check that the certificate is working

    TSP and Bank

    TSP/Bank needs to check that the new activated certificate is working towards ODS. 

    When moving from one CA to another:
    Check that the new certificate have access to display the existing certificates on the old CA.


    Status
    titlePlanning

    14


    12) Switchover

    and revoke

    Plan and implement the switchover

    and revoke

    .

    TSP, Bank and

    BankIDTSP/Bank: Write a request for switchover issuing CA in BankID from old to New CA. Include the time wanted for this. Create a ticket here

    BankID Primary.jpgImage Added

    1. BankID:

      1. Do the switchover

      2. Those who perform the switchover will inform the TSP/Bank by phone or email when it has been done

    2. TSP/Bank: Run test case sets to verify

      1. TSP/Bank: If successful, move to the next step

      2. BankID: If unsuccessful, investigate and resolve then move to next step

      3. BankID: if unsuccessful, not possible to fix, do a rollback

  • (optional. If not done, the certificate will be active on the old CA until it expires) Bank/TSP: Send an order for revoke of old RA XML Sign certificate in BankID by creating a ticket here
  • (optional) BankID15


    Status
    titlePlanning

    Order form templates can be found here: Misc forms for BankID Support

    13) Revoke (optional)

    Revoke the old certificate

    BankID

    BankID: Revoke the old certificate as decided in step 6.

    Status
    titlePlanning

    Order form templates can be found here: Misc forms for BankID Support

    14) Renewals 

    Renewals of end users, merchants etc.

    As decided in step 1.

    TSP and Bank

    When moving from one CA to another:

    1. Bank renew end user BankID certificates

    2. Bank asks merchants to renew merchant BankID's using HAT

    3. Possible change of OTP Service by adding a new and then removing the old

    This is best done outside of peak hours to reduce the risk of latencies.

    Status
    titlePlanning


    15) Other changes

    Name changes etc.

    BankID Primary.jpgImage Added

    BankID will follow up on activites internally, as ordered in step 4:

    •  BankID App
    •  Biometri
    •  BASS
    •  Splunk Partnerinnsikt
    •  Antisvindel
    •  Database
    •  Tilgangspakker
    •  Bestillingsportalen

    Status
    titleplanning