Project

General

Profile

Actions

Enhancement #485

closed

Enhancement #483: Daneel's body is willing to retire

Admin data and tools need to move away from Daneel

Added by Marc Dequènes over 8 years ago. Updated over 7 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Service :: IS / AAA / PKI
Start date:
2015-10-21
Due date:
% Done:

100%

Estimated time:
Patch Available:
Confirmed:
No
Branch:
Entity:
DuckCorp
Security:
Yes
Help Needed:
Yes

Description

This includes:
  • CA data
  • mkcert
  • ansible
  • scripts like:
    • check_certs_expiration
    • adm_publish_tlsa

mkcert could be packaged and delivered in the repositories.

All of this is security sensitive.

Do I miss anything?

Actions #1

Updated by Marc Dequènes over 8 years ago

  • Status changed from New to In Progress
  • % Done changed from 0 to 10
  • Help Needed set to Yes

An idea would be to store encrypted data on Toushirou, in a git repository for example.

I tried eCryptfs+SSHFS and it led to errors when pushing. Using LUKS+SSHFS led to corruption (mix of files/blockdev). I did not see any other encrypted fs solution and Rtp confirmed there is no such thing working.

I also looked at git-crypt, but it messes with filters in an ugly way which was explicitly banned ban git upstream. git-remote-gcrypt seems more promising, needs testing.

Actions #2

Updated by Marc Dequènes over 8 years ago

  • % Done changed from 10 to 70

I tested git-remote-gcrypt using my current and previous GPG key to simulate two users, and it worked fine.

So, I tried to gather everything needed in a single git repository. I tried to organize it clearly and made the necessary changes to allow running all scripts in-place. I also removed all reference to Daneel, as it is not meant to be managed anymore.

Access to Daneel is now restricted to only me. I'll keep the machine running for a while to be sure nothing has been missed. Then I will wipe the disk and stop the machine.

Actions #3

Updated by Marc Dequènes over 7 years ago

  • Status changed from In Progress to Resolved
  • % Done changed from 70 to 100

So this was done and no problem so far with g-r-g.

Actions

Also available in: Atom PDF