To Systems Overview - To Systems IP List - To System Administrators Team
System Administration
The System Administration team is responsible for operation and maintenance of the servers and services provided by CAcert.
Talking to us
Contact your local sysadmin directly using the FULL LISTING or the system-admin@cacert.org aliases.
For more general things, join the Sysadm Maillist and ask there.
For more formal things (bug reports) mail to support@cacert.org.
People
See also: SystemAdministration/Team
Infrastructure team
- Philipp Gühring - hashserver (??)
Ted - CATS
Mario Lipinski - wiki, issue, infrastructure t/l
Markus Warg - translingo
Stefan Freudenberg - blog
Jan Dittberner - infrastructure general, svn, cod and eventually development support tools
Lance Davis - system logging / IDS (??)
Christopher Hoth - email, lists, forum
DominikGeorge - email, community
Jochim Selzer - email, community
Evaldo - irc
Nick Bebout - irc
vicarious - irc
MichaelTänzer - issue
Maurice - blog
UlrichSchroeter - lists
MartinGummi - wiki
Brian Henson - Puppetmaster, ldap
Future(?)
- Kees van Eeten, Ben Pollinger - Forum
- Philippe Teuwen - OpenID
We are always looking for new System Administrators! To see what's going on, join the Sysadm Maillist. If you have specific questions or want to know how to help, post there.
mario@cacert.org currently leads the team on a temporary basis (which means he interfaces with the board and fixes passwords and stuff).
Critical Servers team
- Mendel Mobach (BIT)
Wytze van der Raay (BIT)
Above, people marked (BIT) above are listed on the Firewall/OS Access list in Appendix B, MoU with Oophaga. These people are able to get direct physical (console) access to the machines with Oophaga assistance under SecurityManual.
Access Engineers Team
- Bas van den Dikkenberg
- Hans Verbeek
- Rudi van Drunen
- Rudi Engelbertink
- Stefan Kooman
Access Engineers provide physical gate-keeping to the BIT facility. They have to be present for all direct access by Critical admins. They are listed on the Firewall/Site Access list in Appendix B, MoU with Oophaga.
Documents
The System Administrator's "bible" is the SecurityManual.
which is ruled by the (DRAFT) Security Policy. As the SP is now in DRAFT, it is binding on the system administrators (more precisely the critical sysadm team and the access engineers team).
All are under CCA as Members of CAcert. All are also Assurers, so are fully known to us. All are encouraged to be members of the Association so as to have a say in big community decisions.
See also the (DRAFT) CPS which describes what it is the application delivers.
Principles of CAcert and some common good practices regarding privacy and professionalism from SAGE's Code of Ethics.
List of Guides:
List of Procedures:
- Brain/PoliciesAndSignificantTechnicalStandards/PoliciesDRAFT
- CategoryProcedures
- Roots/CreationCeremony
- SecurityManual
- SystemAdministration
- SystemAdministration/Procedures/CertificateIssuing
- SystemAdministration/Procedures/DNSChanges
- SystemAdministration/Procedures/DiskEncryption
- SystemAdministration/Procedures/DiskMirroring
- SystemAdministration/Procedures/DriveRetirement
- SystemAdministration/Procedures/FirewallChanges
- SystemAdministration/Procedures/FullBackupRestore
- SystemAdministration/Procedures/KeyPeopleContacts
- SystemAdministration/Procedures/OcspResponder
- SystemAdministration/Procedures/OperatingSystemPatches
- SystemAdministration/Procedures/PasswordManagement
Projects:
Systems
List of Systems:
- CategorySystems
- DebianVulnerabilityHandling
- InfrastructureReDesign
- OcspResponder
- Software/Assessment/testserver
- Software/DevelopmentWorkflow
- Software/Webdb
- Software/Webdb/Maintenance/AddNewRoots
- Software/Webdb/Maintenance/DatabaseUpgrades
- SuggestKeySizes
- SystemAdministration
- SystemAdministration/CableIndex
- SystemAdministration/CertificateList
- SystemAdministration/EquipmentList
- SystemAdministration/IPList
- SystemAdministration/InfrastructureHost
- SystemAdministration/InfrastructureHost/MinimalistHostingAgreement
- SystemAdministration/Procedures/DNSChanges
- SystemAdministration/Systems
- SystemAdministration/Systems/Archive
- SystemAdministration/Systems/Blog
- SystemAdministration/Systems/Bugs
- SystemAdministration/Systems/CATS
- SystemAdministration/Systems/Community
- SystemAdministration/Systems/Development
- SystemAdministration/Systems/Email
- SystemAdministration/Systems/Hopper
- SystemAdministration/Systems/Infra01
- SystemAdministration/Systems/Issue
- SystemAdministration/Systems/Lists
- SystemAdministration/Systems/Logger
- SystemAdministration/Systems/Monitor
- SystemAdministration/Systems/Ns
- SystemAdministration/Systems/Ocsp
- SystemAdministration/Systems/SLS
- SystemAdministration/Systems/Signer
- SystemAdministration/Systems/Sun1
- SystemAdministration/Systems/Sun2
- SystemAdministration/Systems/Sun3
- SystemAdministration/Systems/Sun4
- SystemAdministration/Systems/Svn
- SystemAdministration/Systems/Test
- SystemAdministration/Systems/Translations
- SystemAdministration/Systems/Translingo
- SystemAdministration/Systems/Webdb
- SystemAdministration/Systems/Wiki
- SystemAdministration/Systems/Wiki/update201009
- SystemAdministration/Systems/ca-mgr1-test
- SystemAdministration/Systems/cacert1-test
- SystemAdministration/Systems/cacert2-test
- SystemAdministration/Systems/fiddle
- SystemAdministration/Systems/git
- SystemAdministration/Systems/ldap
- SystemAdministration/Systems/template
- SystemAdministration/Team
- Technology/Laboratory/Hardware/InfrastructureHost/Infra-redevelopment-plan
- Technology/Laboratory/Hardware/InfrastructureHost/Vienna1
- Technology/TechnicalSupport/EndUserSupport/IRC
- WeakKeys
- WeakKeys/SmallExponent
- WeakKeys/SmallKey
- comma/Arsenal/IRC
- comma/Arsenal/IRC/improvement
Roles
- Public Services
- Revocation Services
- Support for CATS, audit
- test services
How to become team member
Critical Roles
SP says that board has to approve ABC'd roles:
- crit sysadms
- access engineers
- support engineers
- software analysts
Board or t/l has to start the process with filing a dispute for ABC over new candidate.
Non-critical roles
Please contact Non-Critical-Infrastructure t/l
eg for becoming
- Wiki admin
- Blog admin
- Email admin
- Lists admin
- svn admin
- irc admin
- and others
Non-critical t/l will check the candidates and provide the access.
