59 lines
1.6 KiB
Markdown
59 lines
1.6 KiB
Markdown
# AIM Sensitive Data and Security Notes
|
|
|
|
## Sensitive files
|
|
|
|
AIM deliberately keeps secrets outside Git.
|
|
|
|
Important locations include:
|
|
|
|
``` text
|
|
/etc/ansible/inventories/<customer>/group_vars/all/vault.yml
|
|
/etc/ansible/inventories/<customer>/group_vars/linux/.ssh/
|
|
```
|
|
|
|
Vault files may contain Windows and Linux authentication material.
|
|
`.ssh` directories may contain private keys that cannot be regenerated
|
|
without coordinating key rotation on managed systems.
|
|
|
|
## Backup requirement
|
|
|
|
Git is not a backup for ignored secrets.
|
|
|
|
System backup procedures must include customer Vaults and SSH key
|
|
material. Recovery should preserve existing current files and restore
|
|
only missing data unless an operator explicitly chooses otherwise.
|
|
|
|
## Vault handling
|
|
|
|
AIM encrypts newly created Vaults with `ansible-vault`. Plaintext
|
|
populated Vault data should not remain on disk after a failed encryption
|
|
attempt.
|
|
|
|
Semantic Vault comparison must not print secret values. It should
|
|
compare key existence/state rather than exposing plaintext.
|
|
|
|
## SSH key handling
|
|
|
|
Private-key passphrases and remote SSH passwords are separate concepts.
|
|
|
|
The Linux private key location is:
|
|
|
|
``` text
|
|
group_vars/linux/.ssh/svc_bf-ansible
|
|
```
|
|
|
|
Private keys should have restrictive filesystem permissions.
|
|
|
|
## Authorization
|
|
|
|
AIM authorization is based on membership in a configured group resolved
|
|
through NSS/SSSD/winbind/local group services. The configured group name
|
|
is authoritative; numeric GIDs may differ across hosts.
|
|
|
|
Operators should verify effective membership with:
|
|
|
|
``` bash
|
|
getent group '<required-group>'
|
|
id
|
|
```
|