# AIM Sensitive Data and Security Notes ## Sensitive files AIM deliberately keeps secrets outside Git. Important locations include: ``` text /etc/ansible/inventories//group_vars/all/vault.yml /etc/ansible/inventories//group_vars/linux/.ssh/ ``` Vault files may contain Windows and Linux authentication material. `.ssh` directories may contain private keys that cannot be regenerated without coordinating key rotation on managed systems. ## Backup requirement Git is not a backup for ignored secrets. System backup procedures must include customer Vaults and SSH key material. Recovery should preserve existing current files and restore only missing data unless an operator explicitly chooses otherwise. ## Vault handling AIM encrypts newly created Vaults with `ansible-vault`. Plaintext populated Vault data should not remain on disk after a failed encryption attempt. Semantic Vault comparison must not print secret values. It should compare key existence/state rather than exposing plaintext. ## SSH key handling Private-key passphrases and remote SSH passwords are separate concepts. The Linux private key location is: ``` text group_vars/linux/.ssh/svc_bf-ansible ``` Private keys should have restrictive filesystem permissions. ## Authorization AIM authorization is based on membership in a configured group resolved through NSS/SSSD/winbind/local group services. The configured group name is authoritative; numeric GIDs may differ across hosts. Operators should verify effective membership with: ``` bash getent group '' id ```