Metadata-Version: 2.4
Name: hsm-orchestrator
Version: 1.1.0
Summary: Orchestration tool for Mozilla's offline HSM which facilitates conveying a CSR to the air gapped HSM server
Project-URL: Homepage, https://github.com/mozilla/hsm-orchestrator
Project-URL: Bug Reports, https://github.com/mozilla/hsm-orchestrator/issues
Project-URL: Funding, https://donate.mozilla.org
Project-URL: Say Thanks!, https://saythanks.io/to/gene1wood
Project-URL: Source, https://github.com/mozilla/hsm-orchestrator
Author-email: Gene Wood <gene@mozilla.com>
Maintainer-email: Mozilla Infrastructure Security <security@mozilla.com>
License: Mozilla Public License Version 2.0
        ==================================
        
        1. Definitions
        --------------
        
        1.1. "Contributor"
            means each individual or legal entity that creates, contributes to
            the creation of, or owns Covered Software.
        
        1.2. "Contributor Version"
            means the combination of the Contributions of others (if any) used
            by a Contributor and that particular Contributor's Contribution.
        
        1.3. "Contribution"
            means Covered Software of a particular Contributor.
        
        1.4. "Covered Software"
            means Source Code Form to which the initial Contributor has attached
            the notice in Exhibit A, the Executable Form of such Source Code
            Form, and Modifications of such Source Code Form, in each case
            including portions thereof.
        
        1.5. "Incompatible With Secondary Licenses"
            means
        
            (a) that the initial Contributor has attached the notice described
                in Exhibit B to the Covered Software; or
        
            (b) that the Covered Software was made available under the terms of
                version 1.1 or earlier of the License, but not also under the
                terms of a Secondary License.
        
        1.6. "Executable Form"
            means any form of the work other than Source Code Form.
        
        1.7. "Larger Work"
            means a work that combines Covered Software with other material, in
            a separate file or files, that is not Covered Software.
        
        1.8. "License"
            means this document.
        
        1.9. "Licensable"
            means having the right to grant, to the maximum extent possible,
            whether at the time of the initial grant or subsequently, any and
            all of the rights conveyed by this License.
        
        1.10. "Modifications"
            means any of the following:
        
            (a) any file in Source Code Form that results from an addition to,
                deletion from, or modification of the contents of Covered
                Software; or
        
            (b) any new file in Source Code Form that contains any Covered
                Software.
        
        1.11. "Patent Claims" of a Contributor
            means any patent claim(s), including without limitation, method,
            process, and apparatus claims, in any patent Licensable by such
            Contributor that would be infringed, but for the grant of the
            License, by the making, using, selling, offering for sale, having
            made, import, or transfer of either its Contributions or its
            Contributor Version.
        
        1.12. "Secondary License"
            means either the GNU General Public License, Version 2.0, the GNU
            Lesser General Public License, Version 2.1, the GNU Affero General
            Public License, Version 3.0, or any later versions of those
            licenses.
        
        1.13. "Source Code Form"
            means the form of the work preferred for making modifications.
        
        1.14. "You" (or "Your")
            means an individual or a legal entity exercising rights under this
            License. For legal entities, "You" includes any entity that
            controls, is controlled by, or is under common control with You. For
            purposes of this definition, "control" means (a) the power, direct
            or indirect, to cause the direction or management of such entity,
            whether by contract or otherwise, or (b) ownership of more than
            fifty percent (50%) of the outstanding shares or beneficial
            ownership of such entity.
        
        2. License Grants and Conditions
        --------------------------------
        
        2.1. Grants
        
        Each Contributor hereby grants You a world-wide, royalty-free,
        non-exclusive license:
        
        (a) under intellectual property rights (other than patent or trademark)
            Licensable by such Contributor to use, reproduce, make available,
            modify, display, perform, distribute, and otherwise exploit its
            Contributions, either on an unmodified basis, with Modifications, or
            as part of a Larger Work; and
        
        (b) under Patent Claims of such Contributor to make, use, sell, offer
            for sale, have made, import, and otherwise transfer either its
            Contributions or its Contributor Version.
        
        2.2. Effective Date
        
        The licenses granted in Section 2.1 with respect to any Contribution
        become effective for each Contribution on the date the Contributor first
        distributes such Contribution.
        
        2.3. Limitations on Grant Scope
        
        The licenses granted in this Section 2 are the only rights granted under
        this License. No additional rights or licenses will be implied from the
        distribution or licensing of Covered Software under this License.
        Notwithstanding Section 2.1(b) above, no patent license is granted by a
        Contributor:
        
        (a) for any code that a Contributor has removed from Covered Software;
            or
        
        (b) for infringements caused by: (i) Your and any other third party's
            modifications of Covered Software, or (ii) the combination of its
            Contributions with other software (except as part of its Contributor
            Version); or
        
        (c) under Patent Claims infringed by Covered Software in the absence of
            its Contributions.
        
        This License does not grant any rights in the trademarks, service marks,
        or logos of any Contributor (except as may be necessary to comply with
        the notice requirements in Section 3.4).
        
        2.4. Subsequent Licenses
        
        No Contributor makes additional grants as a result of Your choice to
        distribute the Covered Software under a subsequent version of this
        License (see Section 10.2) or under the terms of a Secondary License (if
        permitted under the terms of Section 3.3).
        
        2.5. Representation
        
        Each Contributor represents that the Contributor believes its
        Contributions are its original creation(s) or it has sufficient rights
        to grant the rights to its Contributions conveyed by this License.
        
        2.6. Fair Use
        
        This License is not intended to limit any rights You have under
        applicable copyright doctrines of fair use, fair dealing, or other
        equivalents.
        
        2.7. Conditions
        
        Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
        in Section 2.1.
        
        3. Responsibilities
        -------------------
        
        3.1. Distribution of Source Form
        
        All distribution of Covered Software in Source Code Form, including any
        Modifications that You create or to which You contribute, must be under
        the terms of this License. You must inform recipients that the Source
        Code Form of the Covered Software is governed by the terms of this
        License, and how they can obtain a copy of this License. You may not
        attempt to alter or restrict the recipients' rights in the Source Code
        Form.
        
        3.2. Distribution of Executable Form
        
        If You distribute Covered Software in Executable Form then:
        
        (a) such Covered Software must also be made available in Source Code
            Form, as described in Section 3.1, and You must inform recipients of
            the Executable Form how they can obtain a copy of such Source Code
            Form by reasonable means in a timely manner, at a charge no more
            than the cost of distribution to the recipient; and
        
        (b) You may distribute such Executable Form under the terms of this
            License, or sublicense it under different terms, provided that the
            license for the Executable Form does not attempt to limit or alter
            the recipients' rights in the Source Code Form under this License.
        
        3.3. Distribution of a Larger Work
        
        You may create and distribute a Larger Work under terms of Your choice,
        provided that You also comply with the requirements of this License for
        the Covered Software. If the Larger Work is a combination of Covered
        Software with a work governed by one or more Secondary Licenses, and the
        Covered Software is not Incompatible With Secondary Licenses, this
        License permits You to additionally distribute such Covered Software
        under the terms of such Secondary License(s), so that the recipient of
        the Larger Work may, at their option, further distribute the Covered
        Software under the terms of either this License or such Secondary
        License(s).
        
        3.4. Notices
        
        You may not remove or alter the substance of any license notices
        (including copyright notices, patent notices, disclaimers of warranty,
        or limitations of liability) contained within the Source Code Form of
        the Covered Software, except that You may alter any license notices to
        the extent required to remedy known factual inaccuracies.
        
        3.5. Application of Additional Terms
        
        You may choose to offer, and to charge a fee for, warranty, support,
        indemnity or liability obligations to one or more recipients of Covered
        Software. However, You may do so only on Your own behalf, and not on
        behalf of any Contributor. You must make it absolutely clear that any
        such warranty, support, indemnity, or liability obligation is offered by
        You alone, and You hereby agree to indemnify every Contributor for any
        liability incurred by such Contributor as a result of warranty, support,
        indemnity or liability terms You offer. You may include additional
        disclaimers of warranty and limitations of liability specific to any
        jurisdiction.
        
        4. Inability to Comply Due to Statute or Regulation
        ---------------------------------------------------
        
        If it is impossible for You to comply with any of the terms of this
        License with respect to some or all of the Covered Software due to
        statute, judicial order, or regulation then You must: (a) comply with
        the terms of this License to the maximum extent possible; and (b)
        describe the limitations and the code they affect. Such description must
        be placed in a text file included with all distributions of the Covered
        Software under this License. Except to the extent prohibited by statute
        or regulation, such description must be sufficiently detailed for a
        recipient of ordinary skill to be able to understand it.
        
        5. Termination
        --------------
        
        5.1. The rights granted under this License will terminate automatically
        if You fail to comply with any of its terms. However, if You become
        compliant, then the rights granted under this License from a particular
        Contributor are reinstated (a) provisionally, unless and until such
        Contributor explicitly and finally terminates Your grants, and (b) on an
        ongoing basis, if such Contributor fails to notify You of the
        non-compliance by some reasonable means prior to 60 days after You have
        come back into compliance. Moreover, Your grants from a particular
        Contributor are reinstated on an ongoing basis if such Contributor
        notifies You of the non-compliance by some reasonable means, this is the
        first time You have received notice of non-compliance with this License
        from such Contributor, and You become compliant prior to 30 days after
        Your receipt of the notice.
        
        5.2. If You initiate litigation against any entity by asserting a patent
        infringement claim (excluding declaratory judgment actions,
        counter-claims, and cross-claims) alleging that a Contributor Version
        directly or indirectly infringes any patent, then the rights granted to
        You by any and all Contributors for the Covered Software under Section
        2.1 of this License shall terminate.
        
        5.3. In the event of termination under Sections 5.1 or 5.2 above, all
        end user license agreements (excluding distributors and resellers) which
        have been validly granted by You or Your distributors under this License
        prior to termination shall survive termination.
        
        ************************************************************************
        *                                                                      *
        *  6. Disclaimer of Warranty                                           *
        *  -------------------------                                           *
        *                                                                      *
        *  Covered Software is provided under this License on an "as is"       *
        *  basis, without warranty of any kind, either expressed, implied, or  *
        *  statutory, including, without limitation, warranties that the       *
        *  Covered Software is free of defects, merchantable, fit for a        *
        *  particular purpose or non-infringing. The entire risk as to the     *
        *  quality and performance of the Covered Software is with You.        *
        *  Should any Covered Software prove defective in any respect, You     *
        *  (not any Contributor) assume the cost of any necessary servicing,   *
        *  repair, or correction. This disclaimer of warranty constitutes an   *
        *  essential part of this License. No use of any Covered Software is   *
        *  authorized under this License except under this disclaimer.         *
        *                                                                      *
        ************************************************************************
        
        ************************************************************************
        *                                                                      *
        *  7. Limitation of Liability                                          *
        *  --------------------------                                          *
        *                                                                      *
        *  Under no circumstances and under no legal theory, whether tort      *
        *  (including negligence), contract, or otherwise, shall any           *
        *  Contributor, or anyone who distributes Covered Software as          *
        *  permitted above, be liable to You for any direct, indirect,         *
        *  special, incidental, or consequential damages of any character      *
        *  including, without limitation, damages for lost profits, loss of    *
        *  goodwill, work stoppage, computer failure or malfunction, or any    *
        *  and all other commercial damages or losses, even if such party      *
        *  shall have been informed of the possibility of such damages. This   *
        *  limitation of liability shall not apply to liability for death or   *
        *  personal injury resulting from such party's negligence to the       *
        *  extent applicable law prohibits such limitation. Some               *
        *  jurisdictions do not allow the exclusion or limitation of           *
        *  incidental or consequential damages, so this exclusion and          *
        *  limitation may not apply to You.                                    *
        *                                                                      *
        ************************************************************************
        
        8. Litigation
        -------------
        
        Any litigation relating to this License may be brought only in the
        courts of a jurisdiction where the defendant maintains its principal
        place of business and such litigation shall be governed by laws of that
        jurisdiction, without reference to its conflict-of-law provisions.
        Nothing in this Section shall prevent a party's ability to bring
        cross-claims or counter-claims.
        
        9. Miscellaneous
        ----------------
        
        This License represents the complete agreement concerning the subject
        matter hereof. If any provision of this License is held to be
        unenforceable, such provision shall be reformed only to the extent
        necessary to make it enforceable. Any law or regulation which provides
        that the language of a contract shall be construed against the drafter
        shall not be used to construe this License against a Contributor.
        
        10. Versions of the License
        ---------------------------
        
        10.1. New Versions
        
        Mozilla Foundation is the license steward. Except as provided in Section
        10.3, no one other than the license steward has the right to modify or
        publish new versions of this License. Each version will be given a
        distinguishing version number.
        
        10.2. Effect of New Versions
        
        You may distribute the Covered Software under the terms of the version
        of the License under which You originally received the Covered Software,
        or under the terms of any subsequent version published by the license
        steward.
        
        10.3. Modified Versions
        
        If you create software not governed by this License, and you want to
        create a new license for such software, you may create and use a
        modified version of this License if you rename the license and remove
        any references to the name of the license steward (except to note that
        such modified license differs from this License).
        
        10.4. Distributing Source Code Form that is Incompatible With Secondary
        Licenses
        
        If You choose to distribute Source Code Form that is Incompatible With
        Secondary Licenses under the terms of this version of the License, the
        notice described in Exhibit B of this License must be attached.
        
        Exhibit A - Source Code Form License Notice
        -------------------------------------------
        
          This Source Code Form is subject to the terms of the Mozilla Public
          License, v. 2.0. If a copy of the MPL was not distributed with this
          file, You can obtain one at https://mozilla.org/MPL/2.0/.
        
        If it is not possible or desirable to put the notice in a particular
        file, then You may include the notice in a location (such as a LICENSE
        file in a relevant directory) where a recipient would be likely to look
        for such a notice.
        
        You may add additional accurate notices of copyright ownership.
        
        Exhibit B - "Incompatible With Secondary Licenses" Notice
        ---------------------------------------------------------
        
          This Source Code Form is "Incompatible With Secondary Licenses", as
          defined by the Mozilla Public License, v. 2.0.
License-File: LICENSE.txt
Keywords: hsm
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Information Technology
Classifier: Intended Audience :: System Administrators
Classifier: License :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0)
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.9
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security
Classifier: Topic :: Security :: Cryptography
Requires-Python: >=3.9
Requires-Dist: click
Requires-Dist: configobj
Requires-Dist: gitpython
Requires-Dist: platformdirs
Requires-Dist: psutil
Requires-Dist: rich
Provides-Extra: test
Requires-Dist: click; extra == 'test'
Requires-Dist: coverage; extra == 'test'
Requires-Dist: pytest; extra == 'test'
Requires-Dist: pytest-datafiles; extra == 'test'
Description-Content-Type: text/markdown

# HSM Orchestrator

The **HSM Orchestrator** is a command-line tool for interacting with the offline Hardware Security Module (HSM).

It provides commands to:

* Check **CSR `.csr`** and **OpenSSL configuration `.cnf`** files for validity.
* Push the necessary files to a USB stick for transfer to an offline HSM.
* Pull back the signed certificate and updated Certificate Authority (CA) files from a USB stick.

[![PyPI - Version](https://img.shields.io/pypi/v/hsm-orchestrator)](https://pypi.org/project/hsm-orchestrator/) [![Tests](https://github.com/mozilla/hsm-orchestrator/actions/workflows/tests.yml/badge.svg)](https://github.com/mozilla/hsm-orchestrator/actions/workflows/tests.yml)

---

## Installation

As hsm-orchestrator is a command line tool, the easiest way to install it is using [pipx](https://pipx.pypa.io/stable/).
pipx is a tool to help you install and run end-user applications written in Python. It's roughly similar to macOS's
brew and Linux's apt.

Simple instructions for installing pipx on macOS, various distributions of Linux and Windows can be found here :
https://pipx.pypa.io/stable/#install-pipx

Once pipx is installed, you can install hsm-orchestrator by running

`pipx install hsm-orchestrator`

Note : You don't need to install this as the root user (on macOS or Linux)

You can also install the tool using `pip` into a `virtualenv` or using `pip install --user` into the Python user
install directory.

---

## Configuration

### `config.ini` File Location

By default, the hsm-orchestrator stores configuration at:

* **Linux**: `~/.config/hsm-orchestrator/config.ini`
* **macOS**: `~/Library/Application Support/hsm-orchestrator/config.ini`
* **Windows**: `%LOCALAPPDATA%\Mozilla\hsm-orchestrator\config.ini`

You may need to create the `hsm-orchestrator` directory in order to create the `config.ini` within it.

### `config.ini` Contents

Within that `config.ini` file, you can indicate the location of your local [
`mozilla-services/hsm`](https://github.com/mozilla-services/hsm) git repo
and the `csrs` directory within it.

For example if the path to your local `mozilla-services/hsm` repo on your macOS workstation was `~/Documents/hsm`,
then you could create a `~/Library/Application Support/hsm-orchestrator/config.ini` file with the contents of

```ini
repo_dir = /Users/username/Documents/hsm
csr_dir = /Users/username/Documents/hsm/csrs
```

Adding these values to the config means you don't have to pass them on the command line every time you run
hsm-orchestrator.

---

## Usage

If you've used pipx to install hsm-orchestrator, then the `hsm-orchestrator` tool will be in your PATH and can be
run from anywhere.

If you've configured the tool by creating a `config.ini` file, you don't need to pass the `--repo-dir /path/to/hsm/repo`
and `--csr-dir /path/to/csrs` arguments.

### `check`

`hsm-orchestrator check`

This will perform checks of the environment and your `.csr` and `.cnf` files to make sure that everything is setup
correctly.

### `push-to-stick`

`hsm-orchestrator push-to-stick`

This will first check the environment and files, then copy the `.csr`, `.cnf` and the certificate authority files to a
USB stick along with an instructions text file on what to do on the offline HSM.

### On the Offline HSM

Once you've plugged the USB stick into the offline HSM, you can display the instructions file with a command like

`cat *.instructions.txt`

These instructions will explain what commands to run to operate the offline HSM.

### `pull-from-stick`

`hsm-orchestrator pull-from-stick`

After operating the offline HSM and plugging the USB stick back into your workstation, the pull-from-stick command will
move the files off of the USB stick and into the correct directories in the hsm git repo.

## Requirements

* **Python** ≥ 3.9
* Dependencies (installed automatically):

    * [click](https://click.palletsprojects.com/) for CLI arguments
    * [rich](https://rich.readthedocs.io/) for CLI interaction
    * [configobj](https://configobj.readthedocs.io/) for parsing the orchestrator config file and OpenSSl `.cnf` files
    * [gitpython](https://gitpython.readthedocs.io/) for interacting with the hsm git repo
    * [psutil](https://psutil.readthedocs.io/) for interacting with the removable USB stick
    * [platformdirs](https://platformdirs.readthedocs.io/) for platform agnostic config file locations

---

## Example Workflow

1. Create a new `.csr` + `.cnf` file in the [`csrs`](https://github.com/mozilla-services/hsm/tree/main/csrs) directory
   of the `hsm` git repo.
    * In the `.cnf` file, the `certs`, `database`, `new_certs_dir`, `certificate` and `serial` settings in the
      default_ca section (often called `CA_default`) are relative paths pointing to the current working directory. For
      example, `serial` should have a value like `./serial` or `$dir/serial` where `$dir` is set elsewhere to `.`.
    * In the `.cnf` file, the `certificate` setting should have the value of the CA certificate `.crt` filename in the
      `hsm` git repo's
      [`certificate-authorities`](https://github.com/mozilla-services/hsm/tree/main/certificate-authorities)
      tree.
    * In the `.cnf` file, the `private_key` setting should have the value of the offline HSM application key name
      (instead of a filename as is typically the case). The names of the offline HSM application key names can be found
      in the form of the directory names in the
      [`certificate-authorities`](https://github.com/mozilla-services/hsm/tree/main/certificate-authorities) directory
      in the `hsm` git repo.
2. Run `hsm-orchestrator check` to check the settings in the `.cnf` file and the environment.
3. Insert a blank USB stick in your workstation.
4. Run `hsm-orchestartor push-to-stick` to push the files from the `hsm` git repo to the USB stick.
5. Unmount/eject the USB stick from your workstation and plug the stick into the offline HSM.
6. On the offline HSM, show the instructions by running `cat *.instructions.txt` in the USB stick's directory.
7. Run the commands described in the instructions. It's easiest to copy and paste them.
8. Unmount/eject the USB stick from the offline HSM and plug the stick back into your workstation.
9. Run `hsm-orchestrator pull-from-stick` to move the signed certificate and update the CA files in the `hsm` git repo.

---

# Design Goals

The hsm-orchestrator was created to improve on the
[previous tool](https://github.com/mozilla-services/hsm/blob/72bf80c5812c9aa07c2a633872e014de0c86ac20/hsm).

* The process should not involve copying executable scripts onto the offline HSM server
  as this would be a pathway through which malware could cross the air gap
* Anything to be executed on the offline HSM servers should be conveyed as instructions
  that can be clearly read an interpreted by the operator each time to prevent malware
* Protections should be made to prevent the instructions which the operator follows on the
  offline HSM from containing malware via methods like [Trojan Source](https://en.wikipedia.org/wiki/Trojan_Source)
  or whitespace hiding executable text off the side of the screen.
* Everything about the actions taken on the offline HSM should be captured along with the
  `.csr` and certificate to make the process deterministically reproducible. This artifact collection
  which would include the `.csr`, `.cnf` file, the instructions, the output from the openssl run
  and the certificate produced. All of these artifacts should be committed to the `hsm` repo.
* Foreign files (`.csr`, `.cnf`, `ca.crt` etc) should stay on the USB stick. No reason to move files onto
  and off of the offline HSM server
* There should be three functions
    * Validate an `openssl.cnf` file and guide the user through customizing the file.
      This is meant for use by the autograph team
    * Push files and commands across the airgap
    * Pull resulting certificates back across
      the airgap.
* Use `click` for processing arguments and `rich` for console output
* Perform checks to detect any risky situations. Over time as we discover new ways to do things wrong
  we should extend the tool to check for those newly encountered problems.
* Don't have the tool get involved in commiting to the git repo or pushing to the remote. Historically
  we spent much more time dealing with commits and pushes that we didn't want than if we had
  just done the commits and pushes ourselves.
* Look for `.csr` files in a specific location instead of doing a `find` across a large area of the `hsm`
  repo

# Possible Future Features

* Do we want to convey time from the workstation to the air gapped HSM server? Or just get
  a GPS time source : https://mozilla-hub.atlassian.net/browse/INFRASEC-1459
* Check the filesystem on the USB stick to ensure it's one which will work on the offline HSM server.
  Maybe we enforce using the UDF filesystem as that should work on all platforms? Maybe bar usage of FAT32?
* Echo the date/time that the signing took place into the output. As the time on the offline HSM drifts
  the benefit of recording this timestamp may decrease.
* We could create a `configobj.InterpolationEngine` like `TemplateInterpolation` but for OpenSSL syntax
    * https://docs.openssl.org/3.1/man5/config/#settings
    * This would remove $$ = $ and add support for [`dollarid`](https://docs.openssl.org/3.1/man5/config/#directives)
      and [`.include`](https://docs.openssl.org/3.1/man5/config/#directives)
