Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Ceremony description

RA Ceremony

CA Ceremony

Key Change Over

RA Merger

RA Move

Date and time for the ceremony

Status for the ceremony

Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

StatuscolourRedtitlefailed

Date and time for the activation, switchover and revoke

Status for the activation, switchover and revoke

Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

Status
colourRed
titlefailed

References

References

Comments

Resources bank and TSP:

Role

Name

Contact information

Key custodian

Other

Resources

...

BankID:

Role

Name

Contact information

Coordinator

PKI

App

...

Definitions:

Step

What

Description

ResponsibleTaskDeadlineStatusDocuments and notes1) BITS ApprovalThe respective TSP or Bank will require BITS approval for the following move or merger before ordering an RA ceremony.

TSP or Bank

  1. Need to be describe from TSP/Bank side
  2. Send it to: as@bits.no

Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

2) Internal steps

Ceremony

The physical meeting with all necessary participants.
This is when the new RA certificate is created in red zone.

Activation

When the new certificate is activated on BankID side.
This is usually done at another time than the ceremony.

Switchover

When the traffic is switched from the old CA to the new CA.
Only applicable when moving from one CA to another.

Before the ceremony:

Step

Description

Responsible

Task

Deadline

Status

Documents and notes

1) Set up internal routines

The respective TSP or Bank will require to have in place internal routines for move or merger of RA's.

Such as

TSP or Bank

Decide the following:

  • How to deal with the OTP tokens

  • End user impact

  • Information to end users

  • How to deal with logs and how/who to archive (admin logs for certificates)

Note that the TSP

or Bank

/Bank is responsible for handling the end user certificates through the whole process, including revoke of old certificates.


Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

3) Formal order to Vipps


2) BITS Approval

The respective TSP or Bank

have to create and send a formal order to Vipps. Either on a signed or electronically signed document by TSP or Bank.

This order should contain:

  • The purpose of the move or merger of the mention RA
  • Detailed move or merger from and to what CA
TSP or Bank

will require BITS approval for the following move or merger before ordering an RA ceremony.

TSP or Bank


Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

4) Order forms to Vipps

Information from BITS about the process:

View file
nameBankID - Migrering - Prosess for migrering av bank til ny CA.pdf

3) Send order forms to BankID

The respective TSP or Bank have to fill out required order forms and send it to

Vipps

BankID signed before or during the RA ceremony.

A copy must be sent before the RA ceremony.

TSP or Bank

TSP/bank creates a ticket here including the following:

  • RA order form

Order forms
  • Approval from BITS (from step 2)

  • Revoke RA XML Request (Optional)

Status
titlePlanning

Order form templates can be found here:

 Order forms and information

Misc forms for BankID Support

4) Send change request to BankID

BankID needs information from TSP/bank to make sure all internal systems are updated after the change.

TSP or Bank

Status
titlePlanning

Status
colourYellow
titleIn progress

StatuscolourGreentitlecompleted

TSP/bank creates a ticket here with all the relevant information.

Will be done after the activation/ switchover.

Status
titlePlanning

Examples:
Splunk Partnerinnsikt
BankID App
Biometri Backoffice
etc.

5) Make sure that the prerequisites are in order

RA XML request and

Primary CAO token "Dongle"

The RA XML request must be created on the TSP system, for example through HAT tool. Primary CAO token

is normally stored in a safe at the respective TSP (CA responsible).

 

The respective Key Custodian for the TSP is responsible to carry and bring the RA XML request and the Primary CAO token "dongle" to the RA ceremony.

Key custodian for TSP

  • Create an RA XML request on the TSP system, for example through HAT tool.

  • Make sure that the USB stick is new and

Identification
  • unused

Vipps recommend
  • Make sure that the Key Custodian

always bring a new and unused USB stick and
  • have approved identification such as a passport or driver license

. If
  • (if the Key Custodian is a non-Norwegian citizen, they must bring their passport

Key custodian for TSP
  • )


Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted


6) RA ceremony coordination

Vipps

BankID will ensure that

the following 

everything is in place

, before going further:
  •  BITS approval - If not provided by the TSP or Bank, contact BITS and verify
  •  Formal Order received
  •  Order forms
    •  Signed - Naming of RA (Required)
    •  Signed - Revoke RA XML Request (Optional)
  •  TSPs Primary CAO token
  •  TSPs/Bank RA XML Request
If all is in place: all Vipps

and coordinate the ceremony and switchover with all stakeholders.

BankID Primary.jpgImage Added

All stakeholders align and agree on date and time for the following:

  1. RA ceremony
  2. Activation of New RA XML Sign Certificate
  3. Switchover 
  4. Revoke RA XML (Optional)

Normally step 2, 3 and 4 happens within the same 24h.

  •  1. RA ceremony
  •  2. Switchover
  •  3. Revoke the old RA Certificate (Optional)


Status
titlePlanning

Status
colourYellow
titleIn progress

StatuscolourGreentitlecompleted


7) Invitations

Vipps are to

BankID will send out a meeting invite for

RA

the ceremony and

the Switchover. These

the switchover.

BankID Primary.jpgImage Added

Create and send out the invitation to all stakeholders.

The invitation should contain, but not limited to:

  • Purpose and description

  • Date

  • Time

  • Duration

Virtual Meeting Link or
  • Address

  • Attendees and contact points

  • Information on what to bring

Vipps


Status
titlePlanning

Status
colourYellow
titleIn progress

StatuscolourGreentitle

completed


Ceremony:

The Key Custodian for the respective TSPs is on-site with their Primary CAO token and the RA XML sign request.

Step

Description

Responsible

Task

Deadline

Status

Documents and notes

8) Pre RA ceremony check

BankID will greet the participants and check that all is OK for moving on with the ceremony.

BankID Primary.jpgImage Added

  • Participants need to sign in and out

  • All necessary resources are in place

    • Key Custodian

    • PKI

  • Key Custodian ID check is done by the SO

  • USB virus scan is done manually before High secure room (USB stick that contains the RA XML Sign request)

  • All required documentation is in place

    • Note that RA naming order forms are to be stored in the BankID High secure room

Important that it is the original document (not scan or copies) If the
    • . When the documentation is signed

with electronic signing
    • electronically,

then
    • a copy of

that are
    • the document is to be stored

in the BankID high secure room

Vipps


Status
titlePlanning

Status
colourYellow
titleIn progress

StatuscolourGreentitle

completed


9) Perform RA ceremony

Issue New

BankID is to perform the RA ceremony

BankID Primary.jpgImage Added

BankID will guide the key custodian through issuing of the new RA XML/SSL certificate(s) on

New

the new CA

Vipps

.

Key custodian will need to oversee that the changes made are according to the documentation.


Status
titlePlanning

Status
colourYellow
titleIn progress

StatuscolourGreentitlecompleted


After the ceremony:

Step

Description

Responsible

Task

Deadline

Status

Documents and notes

10)

Request activationRequest activation of New RA XML Sign

Activation

BankID is to activate the new certificates.

BankID Primary.jpgImage Added

Activate the new RA certificate(s) in BankID

COI.TSP and Bank

. Normally done within 24 hours after the ceremony.

Performed by AO with PKI involved.


Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

11) Activation

Activation of New RA XML Sign certificate(s) in BankID COI.

This is normally done during the same day as the Switchover.

Vipps


11) Certificate check

Check that the certificate is working

TSP and Bank

TSP/Bank needs to check that the new activated certificate is working towards ODS. 

When moving from one CA to another:
Check that the new certificate have access to display the existing certificates on the old CA.


Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

12) Switchover
  • Order switchover issuing CA in BankID COI from old to New CA
  • Run test case sets to verify


    12) Switchover

    Plan and implement the switchover.

    TSP, Bank and

    BankID Primary.jpgImage Added
    1. BankID:

      1. Do the switchover

      2. Those who perform the switchover will inform the TSP/Bank by phone or email when it has been done

    2. TSP/Bank: Run test case sets to verify

      1. TSP/Bank: If successful, move to the next step

      2. BankID: If unsuccessful, investigate and resolve then move to next step

      3. BankID: if unsuccessful, not possible to fix, do a rollback

        • Bank/TSP: When rollback is done, run

     
     to verify
  • Order revoke of old RA XML Sign certificate in BankID COI (optional)
  • This is normally done at midnight 00:00.

    TSP, Bank and Vipps
        •  to verify


    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted

    13) Renewals (End users, merchants etc)

    Order form templates can be found here: Misc forms for BankID Support

    13) Revoke (optional)

    Revoke the old certificate

    BankID

    BankID: Revoke the old certificate as decided in step 6.

    Status
    titlePlanning

    14) Renewals 

    Renewals of end users, merchants etc.

    As decided in step 1.

    TSP and Bank

    When moving from one CA to another:

    1. Bank renew end user BankID certificates

    2. Bank asks merchants to renew merchant BankID's using HAT

    3. Possible change of OTP Service by adding a new and then removing the old

    for each Banklagret BankIDTSP and Bank

    This is best done outside of peak hours to reduce the risk of latencies.

    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted

    Input fra Knut Erik?


    15) Other changes

    Name changes etc.

    BankID Primary.jpgImage Added

    BankID will follow up on activites internally, as ordered in step 4:

    •  BankID App
    •  Biometri
    •  BASS
    •  Splunk Partnerinnsikt
    •  Antisvindel
    •  Database
    •  Tilgangspakker
    •  Bestillingsportalen

    Status
    titleplanning