Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

RoleNameContact information
Coordinator

PKI

App

Definitions:

WhatDescription
Switchover


Before the ceremony:

StepDescriptionResponsibleTaskDeadlineStatusDocuments and notes
1) BITS ApprovalThe respective TSP or Bank will require BITS approval for the following move or merger before ordering an RA ceremony.

TSP or Bank

Need to be describe from
  • The TSP/Bank
side
  • describes the change
  • Send it to
: as@bits

Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted


2)
Internal steps
Set up internal routines

The respective TSP or Bank will require to have in place internal routines for move or merger of RA's.

Such as

TSP or Bank

Decide the following:

  • How to deal with the OTP tokens
  • End user impact
  • Information to end users
  • How to deal with logs and how/who to archive (admin logs for certificates)
TSP or Bank

Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted


3) Formal order to Vipps

The respective TSP or Bank have to create and send a formal order to Vipps

. Either on a signed or

as an electronically signed document, signed by TSP or Bank.

TSP or Bank

This order should contain:

  • The purpose of the move or merger of the mention RA
  • Detailed move or merger from and to what CA
TSP or Bank
  • Approval from Bits

Sign it electronically and send it to ??


Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted


4)
Order
Send order forms to Vipps

The respective TSP or Bank have to fill out required order forms and send it to Vipps signed before or during the RA ceremony.

A copy must be sent before the RA ceremony.

Order forms templates can be found here: Order forms and information
TSP or Bank
  • TSP
or Bank
  • /Bank fills out the required order form.
  • Send a copy to ?? before the RA ceremony

Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

Order form templates can be found here: Order forms and information
5) Make sure that the prerequisites are in order

RA XML request and Primary CAO token "Dongle"

The RA XML request must be created on the TSP system, for example through HAT tool. Primary CAO token is normally stored in a safe at the respective TSP (CA responsible). 

The respective Key Custodian for the TSP is responsible to carry and bring the RA XML request and the Primary CAO token "dongle" to the RA ceremony.

USB stick and Identification

Vipps recommend that Key Custodian always bring a new and unused USB stick and approved identification such as passport or driver license. If the Key Custodian is a non-Norwegian citizen, they must bring their passport. 

Key custodian for TSP


Make sure that the USB stick is new and unused



Status
titlePlanning

Status
colourYellow
titleIn progress

Status
colourGreen
titlecompleted

TODO
6) RA ceremony coordination

Vipps will ensure that everything is in place and coordinate the ceremony and switchover with all stakeholders.

Vipps

Check that the

following 

following is in place

, before going further

:

  •  BITS approval - If not provided by the TSP or Bank, contact BITS and verify
  •  Formal
Order
  • order received
  •  
Order
  • Signed order forms
    •  Signed - Naming of RA (Required)
    •  Signed - Revoke RA XML Request (Optional)
  •  TSPs Primary CAO token
  •  TSPs/Bank RA XML Request

If all is in place

:

, all stakeholders align and agree on date and time for the following:

  • RA ceremony
    •  1. RA ceremony
    •  2. Activation of New RA XML Sign Certificate
  • Switchover 
    •  3. Switchover 
    •  4. Revoke RA XML (Optional)

    Normally step 2, 3 and 4 happens within the same 24h.

    Vipps


    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted


    7) Invitations

    Vipps

    are to

    will send out an meeting invite for

    RA

    the ceremony and the

    Switchover. These

    switchover.

    Vipps

    Create and send out the invitation to all stakeholders.

    The invitation should contain, but not limited to:

    • Purpose and description
    • Date
    • Time
    • Duration
    • Virtual Meeting Link or Address
    • Attendees and contact points
    • Information on what to bring
    Vipps

    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted


    Ceremony:

    The Key Custodian for the respective TSPs is on-site with their Primary CAO token and the RA XML sign request.

    StepDescriptionResponsibleTaskDeadlineStatusDocuments and notes
    8) Pre RA ceremony checkVipps will greet the participants and check that all is OK for moving on with the ceremony.

    Vipps

    • Key Custodian ID check
    • USB virus scan (USB stick that contains the RA XML Sign request)
    • All required documentation is in place
      • Note that RA naming order forms are to be stored in the BankID High secure room
    Important that it is the original document (not scan or copies) If the
      • . When the documentation is signed
    with electronic signing
      • electronically,
    then
      • a copy of
    that
      • the document are to be stored
    in the BankID high secure roomVipps

    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted


    9) Perform RA ceremony

    Vipps is to perform the RA ceremony

    Vipps

    Issue New RA XML/SSL certificate(s) on New CA

    Vipps


    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted


    After the ceremony:

    StepDescriptionResponsibleTaskDeadlineStatusDocuments and notes
    10) Request activation
    Request activation

    TSP/Bank need to send a request to Vipps

    TSP and Bank
    • Write a request for activation of New RA XML Sign certificate(s) in BankID COI.
    TSP and Bank
    • The request needs to contain:
      • ??
    • Send it to ??

    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted


    11) Activation
    Activation of New RA XML Sign certificate(s) in BankID COI

    Vipps is to activate the new certificates.

    This is normally done during the same day as the Switchover.

    VippsActivate the new RA XML Sign certificate(s) in BankID COI.

    Status
    titlePlanning

    Status
    colourYellow
    titleIn progress

    Status
    colourGreen
    titlecompleted


    12) Switchover
    Order

    Plan and implement the switchover.

    This is normally done at midnight 00:00.

    TSP, Bank and Vipps

    TSP/Bank:

    1. Send an order for switchover issuing CA in BankID COI from old to New CA
    Run 
      • Send it to ??

    Vipps:

    1. Do the switchover
    2. Inform the TSP/Bank

    TSP/Bank:

    1. Run test case sets
     to
    1.  to verify
      1. If successful, move to the next step
      2. If unsuccessful, investigate and resolve then move to next step
      3. if unsuccessful, not possible to fix, do a rollback
        • When rollback is done,
    run 
     to
        •  to verify
    Order
    1. Send an order for revoke of old RA XML Sign certificate in BankID COI (optional)

      This is normally done at midnight 00:00.

        • Send it to ??

      Vipps:

      1. Revoke the old certificate
      TSP, Bank and Vipps

      Status
      titlePlanning

      Status
      colourYellow
      titleIn progress

      Status
      colourGreen
      titlecompleted

      Må utfylles mer
      13) Renewals Renewals
      (End
      of end users, merchants etc
      )
      .TSP and Bank
      1. Bank renew end user BankID certificates
      2. Bank asks merchants to renew merchant BankID's using HAT
      3. Possible change of OTP Service by adding new and then removing old for each Banklagret BankID
      TSP and Bank

      Status
      titlePlanning

      Status
      colourYellow
      titleIn progress

      Status
      colourGreen
      titlecompleted

      Input fra Knut Erik?