Monthly Archives: October 2008

CAcert Association board election

The CAcert Inc. association baord election will take place at the upcoming CAcert Association Annual General Meeting (AGM 2008) of the 7th of November 2008. If you are a CAcert Association Member and will become nominated for this election please get in touch with the CAcert board and have you nominated by at least two association members.

More details on the CAcert Inc. assocation can be found at the association wiki page
The upcoming AGM2008 agenda and references to reports can be found here

Servers Moved (comments from audit)

The CAcert critical services are now running on machines in the Netherlands.  This involved shutting down the machines in Vienna, transporting the data to Netherlands, handing over to a new team, and bringing the data up in the new location.

Names and places of the running systems will be mentioned elsewhere no doubt, but our thanks go to two groups in Vienna:  Funkfeuer and Sonance.  These two community groups provided the help when it was needed, and now they stand down from operational support to CAcert, retaining only a mention in the history (and, of course, many future Assurances).

BIT colo cam 4 ... not sure this is the right oneTo look at the audit context:  Although I was there, this move was not an audited, officially monitored operation;  this is because (a) the audit was frozen back in December of 2006, partly because of the difficult systems issues, (b) we still lack the full documentation set against which to audit, (c) the new team are focussed on getting basic control, and are not ready for dual control.  Also, always remember to view the auditor presence under the Heisenbergian lens of skepticism! It is your job to check the move and make it safe.  The auditor makes sure you are doing the job, so that we can all rely on the job being done each and every time.

Once we get a declaration that things are under control, the team expands its vision from the brutal short-term needs, and starts on its impressive task list, we will look at getting the audit formally restarted.

Still, that all said, the big job has been done, and done well.  The systems are now in place in the BIT high security ISP, and the new team is doing the work-through.  That will take place over the next few weeks.  At some stage, the new team will then be looking to carve up the work and bring in new people.  This latter expansion will be handled carefully, but it is necessary.  Think about that…

You can help in two ways.  One, take load of the systems people by helping in support, software and a myriad of other tasks.  Two, getting the CPS into DRAFT by answering the two blocking challenges.  Over to you!

CAcert 2008 Annual General Meeting

To all Association Members and interested Community Members.

The CAcert Annual General Meeting will be held on the 7th of November 2008 at 23:00 UTC via IRC CAcert channel.

Any persons believing that they are an Association Member but have not paid membership fees please contact the CAcert Treasurer. Any persons wishing to become an Association Member please get your applications in now. Voting rights will only be given to fully paid up Association Members.

Any Association Members that have not paid their membership fees for three years will automatically be removed from the Association Membership Register.
Draft Agenda:

  • Opening
  • Minutes from 2007 AGM
  • Minutes from SGM in spring
  • New Association Member nominations
  • Financial report
  • Report on re-hosting CAcert services in Nld
  • Report on the Audit Project
  • Election of new board for next year.
  • Public Officer appointment
  • Close of meeting.

day 3

* rehosting day 3 CRday banner

Systems team visited the Ede BIT center to create backups and install a new drive. Systems are now passed over from old team of Philipp to the new team of Mendel and Wytze. The new team has a full book of work ahead of it and will be looking favourably on any locals who could help.

Root team has created trial keys but did not attempt a real root due to concerns over entropy and precise sub-root configuration. Current plan is to sort out these issues and re-convene end of November. This is not a blocking task.

At seven, the completion event took place at 'Planken Wambuis'. During a delicious dinner, the things happened in the last few days were spoken through and the things still to be done were mildly discussed. Around 22.30 the party broke up and went home.

day 2

* rehosting day 2 CRday banner

The second day was mainly testing and making preparations for the rootkey ceremony.
A bug has been found in openSSL which blocks the rootkey creation on friday.

day 1

* rehosting day 1 CRday banner

On 9:06h CET on wednesday, the team arrived at BIT, the Dutch ISP. They started with Opening the sealed disks under the watchful eye of the auditor and one person from the Dutch ISP. Around 12:00h The servers were booted and the data integrety was checked. At 13:32h The servers were running.
The Team is now smoothing out the last glitches, doing extensive tests and are monitoring the servers closely. It's still possible to have some outages in the coming days.

We got some questions by mail regarding the SSL keys and the (possible) debian vulnerability.
There are blacklists of sites who may have this issue. Unfortunately, the off-line page was also on this list.
After investigation, it turned out the off-line page was running on a computer which was booted with an older live-cd containing the bug.
Since it was a single static page, no harm is done. Our on-line site has different keys and it's verified that these ssl keys are ok.
CAcert apologises for this inconvenience.

Rehosting: Travel day

* Travel day CRday banner

The servers were shut down around 8:00h CET on tuesday and a temporary page is set up for the off-line period.
After the disks were removed and sealed under the watchful eye of the auditor and one person from the Austrian ISP, The Vienna team started on their about 1100km trip to the Netherlands and arrived late in the evening.