Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make configuration rerolls less burdensome for users/admins #1196

Open
1 of 4 tasks
zenmonkeykstop opened this issue Oct 30, 2024 · 0 comments
Open
1 of 4 tasks

Make configuration rerolls less burdensome for users/admins #1196

zenmonkeykstop opened this issue Oct 30, 2024 · 0 comments

Comments

@zenmonkeykstop
Copy link
Contributor

zenmonkeykstop commented Oct 30, 2024

  • I have searched for duplicates or related issues

Description

If a Tails-based Journalist workstation is lost or stolen, the current recommendation is to regenerate the Journalist Interface address and auth details, and to either delete the journalist's account or update its credentials. If the SVS USB is lost or stolen, the Submission Key would almost certainly need to be regenerated.

Since SecureDrop Workstation has both JI creds and the Submission Key, if an SDW is lost or stolen both types of creds would need to be updated, including for all users on other SDWs.

This process should be streamlined as much as possible to reduce admin overhead and support burden.

Potential tasks:

  • Document process for re-rolling the Journalist Interface and Submission Key and securely distributing new details to workstations
  • Support multiple Submission Keys #1197
  • Support per-workstation Journalist Interface client auth keys.
@deeplow deeplow mentioned this issue Nov 12, 2024
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant