Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-5688

FIWARE.Request.Lab.Gent.Adding Region Support Keys

    Details

    • Type: extRequest
    • Status: Closed
    • Priority: Major
    • Resolution: Done
    • Fix Version/s: 2021
    • Component/s: FIWARE-LAB-HELP
    • Labels:
      None
    • HD-Node:
      Gent

      Description

      The region staff team are responsible of the virtual machines instantiated on their servers. Therefore each region staff should have the control of who access the virtual machines for support purposes and set and enforce the corresponding policy. It is not possible if the public keys are shared among all the regions. Additionally, it is also extremely insecure and a problem when a region leaves the federation.

      A new service, called aiakos and deployed aiakos.lab.fiware.org, has been deployed in FIWARE Lab to manage support region ssh and gpg keys.

      As region administrator, you should create your ssh, and gpg keys and upload it into the aikos service (you can obtain information about how create your keys in https://github.com/telefonicaid/fiware-aiakos/blob/develop/doc/README.rst#generating-a-ssh-key).

      To upload your keys into the aiakos service, you should use just a POST operation
      POST: https://jsapi.apiary.io/apis/fiwareaiakos/reference/aiakos-v1/add-key/post-key.html

      You can find information about why ssh and gpg keys are needed in https://github.com/telefonicaid/fiware-aiakos/blob/develop/doc/README.rst#why-a-ssh-key-and-a-gpg-key-are-needed

        Activity

        Hide
        IMINDS Gent Node Helpdesk added a comment -

        Is the service aiakos running? I'm not able to connect.

        Show
        IMINDS Gent Node Helpdesk added a comment - Is the service aiakos running? I'm not able to connect.
        Hide
        IMINDS Gent Node Helpdesk added a comment -

        I can connect on port 3000. But method is authorized:

        HTTP/1.1 401 Unauthorized

        How is the best way to upload the key? I'm using curl.

        Show
        IMINDS Gent Node Helpdesk added a comment - I can connect on port 3000. But method is authorized: HTTP/1.1 401 Unauthorized How is the best way to upload the key? I'm using curl.
        Hide
        henar Henar Muñoz added a comment -

        Hi
        As written in the documentation, you should include the X-Token-Auth header. Anyway, could you send me the curl request you do to my mail (henar@tid.es).
        Regards,
        Henar

        Show
        henar Henar Muñoz added a comment - Hi As written in the documentation, you should include the X-Token-Auth header. Anyway, could you send me the curl request you do to my mail (henar@tid.es). Regards, Henar
        Hide
        IMINDS Gent Node Helpdesk added a comment -

        Problem is solved, Keys are already uploaded and able to download.

        Thank you.

        Show
        IMINDS Gent Node Helpdesk added a comment - Problem is solved, Keys are already uploaded and able to download. Thank you.

          People

          • Assignee:
            IMINDS Gent Node Helpdesk
            Reporter:
            henar Henar Muñoz
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: