cleaning up todo notes
This commit is contained in:
		
							parent
							
								
									b5562f8234
								
							
						
					
					
						commit
						d46a06af41
					
				|  | @ -26,8 +26,6 @@ The primary tamper proofing methods for the fixed location device are: | ||||||
| 
 | 
 | ||||||
|     * Both photos of vacuum sealed bag with filler and glitter on the bottom screws of laptop are required |     * Both photos of vacuum sealed bag with filler and glitter on the bottom screws of laptop are required | ||||||
| 
 | 
 | ||||||
| - [ ] TODO how is hardware token stored (for pureboot/heads) |  | ||||||
| 
 |  | ||||||
| 3. Make an entry into the access log, specifying the: | 3. Make an entry into the access log, specifying the: | ||||||
| 
 | 
 | ||||||
|     * Individuals involved |     * Individuals involved | ||||||
|  |  | ||||||
|  | @ -6,28 +6,17 @@ | ||||||
| 
 | 
 | ||||||
| * Both operators should print photographic evidence from digital cameras which is stored in a PGP signed repository. The photographs should be of the top and underside of the vacuum sealed object. | * Both operators should print photographic evidence from digital cameras which is stored in a PGP signed repository. The photographs should be of the top and underside of the vacuum sealed object. | ||||||
| 
 | 
 | ||||||
|     * The operators should verify the commit signatures of the photographs they are printing against a list of permitted PGP keys |     * The operators should verify the commit signatures of the photographs they are printing against a list of permitted PGP keys (found in ceremonies repo) | ||||||
| 
 |  | ||||||
|         - [ ] TODO: where do we refer to permitted PGP keys |  | ||||||
| 
 |  | ||||||
| * Each operator should hash the `keychain` repository |  | ||||||
|     - [ ] TODO define keychain repository setup |  | ||||||
| 
 |  | ||||||
|     * `sha256sum keychain/` |  | ||||||
| 
 |  | ||||||
|     * Write it down on a piece of paper as it will be used during the ceremony |  | ||||||
| 
 | 
 | ||||||
| ## Procedure | ## Procedure | ||||||
| 
 | 
 | ||||||
| 1. Verify all transactions for the ceremony in the `ceremonies` repository, ensuring that all the transactions are properly signed by the proposer and the approver. | 1. Verify all transactions for the ceremony in the `ceremonies` repository, ensuring that all the transactions are properly signed by the proposer and the approver using PGP keys which have been checked into ceremonies repository. | ||||||
| 
 |  | ||||||
|     - [ ] TODO guide on how to do this |  | ||||||
| 
 | 
 | ||||||
| 1. Enter the designated location with the 2 operators and all required equipment | 1. Enter the designated location with the 2 operators and all required equipment | ||||||
| 
 | 
 | ||||||
| 1. Lock access to the location - there should be no inflow or outflow of people during the ceremony | 1. Lock access to the location - there should be no inflow or outflow of people during the ceremony | ||||||
| 
 | 
 | ||||||
| 1. Retrieve sealed laptop and polaroid from locked storage | 1. Retrieve sealed Air-Gapped bundle and polaroid from locked storage | ||||||
| 
 | 
 | ||||||
| ### Unsealing Tamper Proofing | ### Unsealing Tamper Proofing | ||||||
| {{ #include ../../../../../../component-documents/tamper-evidence-methods.md:vsbwf-procedure-unsealing}} | {{ #include ../../../../../../component-documents/tamper-evidence-methods.md:vsbwf-procedure-unsealing}} | ||||||
|  |  | ||||||
|  | @ -8,16 +8,7 @@ This is a ceremony for generating root entropy. | ||||||
| 
 | 
 | ||||||
| * Both operators should print photographic evidence from digital cameras which is stored in a PGP signed repository. The photographs should be of the top and underside of the vacuum sealed object. | * Both operators should print photographic evidence from digital cameras which is stored in a PGP signed repository. The photographs should be of the top and underside of the vacuum sealed object. | ||||||
| 
 | 
 | ||||||
|     * The operators should verify the commit signatures of the photographs they are printing against a list of permitted PGP keys |     * The operators should verify the commit signatures of the photographs they are printing against a list of permitted PGP keys found in "ceremonies" repo | ||||||
| 
 |  | ||||||
|         - [ ] TODO: where do we refer to permitted PGP keys |  | ||||||
| 
 |  | ||||||
| * Each operator should hash the `keychain` repository |  | ||||||
|     - [ ] TODO define keychain repository setup |  | ||||||
| 
 |  | ||||||
|     * `sha256sum keychain/` |  | ||||||
| 
 |  | ||||||
|     * Write it down on a piece of paper as it will be used during the ceremony |  | ||||||
| 
 | 
 | ||||||
| * Each member needs to bring their: | * Each member needs to bring their: | ||||||
| 
 | 
 | ||||||
|  |  | ||||||
|  | @ -56,7 +56,7 @@ The proposer must combine these values into a single message, which can be a sim | ||||||
| 
 | 
 | ||||||
|     * `gpg --clearsign <file>` |     * `gpg --clearsign <file>` | ||||||
| 
 | 
 | ||||||
| 1. Notify relevant individuals that there are new transactions queued up, and that a ceremony should be scheduled. This can be automated in the future so that when a commit is made or PR opened, others are notified, for example using a incident management tool(TODO). | 1. Notify relevant individuals that there are new transactions queued up, and that a ceremony should be scheduled. This can be automated in the future so that when a commit is made or PR opened, others are notified, for example using a incident management tool. | ||||||
| 
 | 
 | ||||||
| ## Appendix | ## Appendix | ||||||
| 
 | 
 | ||||||
|  |  | ||||||
		Loading…
	
		Reference in New Issue