feat: complete evidence restructuring worktree
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
# TLS per DWH REST
|
||||
# TLS for DWH REST
|
||||
|
||||
La chiave DWH è accettabile solo sopra TLS verificato. Errori di autorizzazione o disponibilità
|
||||
non autorizzano mai a disabilitare la verifica del certificato.
|
||||
The DWH key may be used only over verified TLS. Authorization or availability errors never justify
|
||||
disabling certificate verification.
|
||||
|
||||
## CA privata
|
||||
## Private CA
|
||||
|
||||
Quando il DWH REST usa una CA aziendale, consegnare il certificato separatamente dalla chiave
|
||||
API. La CA non è una credenziale, ma la sua integrità è un confine di sicurezza: deve restare
|
||||
fuori da Git e non essere scrivibile da utenti non autorizzati.
|
||||
When DWH REST uses an enterprise CA, deliver the certificate separately from the API key. The CA
|
||||
is not a credential, but its integrity is part of the security boundary. Keep it out of Git and
|
||||
make it unwritable by unauthorized users.
|
||||
|
||||
Esempio ACME Limited:
|
||||
|
||||
@@ -15,26 +15,24 @@ Esempio ACME Limited:
|
||||
THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem
|
||||
```
|
||||
|
||||
## Fingerprint fuori banda
|
||||
## Out-of-band fingerprint
|
||||
|
||||
Calcolare il fingerprint del file ricevuto e confrontarlo attraverso un canale indipendente:
|
||||
Calculate the fingerprint of the received file and compare it through an independent channel:
|
||||
|
||||
```bash
|
||||
openssl x509 -noout -fingerprint -sha256 \
|
||||
-in /absolute/protected/acme-ebikes-dwh-ca.pem
|
||||
```
|
||||
|
||||
Il SAN del certificato deve includere il nome esatto usato dal binding, per esempio
|
||||
`dwh.acme.example`.
|
||||
The certificate SAN must include the exact name used by the binding, such as `dwh.acme.example`.
|
||||
|
||||
## Rinnovo
|
||||
## Renewal
|
||||
|
||||
1. Preparare certificato e chain nuovi.
|
||||
2. Confermare SAN e fingerprint fuori banda.
|
||||
3. Distribuire la nuova CA ai client mantenendo temporaneamente la precedente.
|
||||
4. Aggiornare il binding e confermare la connettività con TLS normale.
|
||||
5. Installare il certificato server.
|
||||
6. Ritirare il trust precedente dopo la finestra concordata.
|
||||
1. Prepare the new certificate and chain.
|
||||
2. Confirm the SAN and fingerprint out of band.
|
||||
3. Distribute the new CA to clients while temporarily keeping the old one.
|
||||
4. Update the binding and confirm connectivity with normal TLS.
|
||||
5. Install the server certificate.
|
||||
6. Remove the old trust after the agreed window.
|
||||
|
||||
Non usare `curl -k`, non disabilitare TLS e non incorporare certificati o fingerprint completi
|
||||
nei documenti condivisi.
|
||||
Do not use `curl -k`, disable TLS, or embed complete certificates or fingerprints in shared documents.
|
||||
|
||||
Reference in New Issue
Block a user