This is a new access request for David Vargas of Bishop Fox. This is the pentest contractor that we are working with through the Security team.
They require the following access: (mark each box with an x)
- civicrm web access
- standard access
- donor services access (manager)
- engage access (manager)
- fr-tech administrative access
- ssh access - if specific hosts: list here
- mysql - if specific hosts or databases: list here
- superset
- other: This is a special case where there will be multiple accounts so differences in privileges can be tested.
New User Procedure / Checklist
When adding a new user to the fundraising / fr-tech ecosystem, we have a set of places where we need to create accounts and access.
Prerequisites
Before we can take any action to add a user, we need to verify that they are authorized to have such access. This requires confirmation from their manager and approval from the C level that access is approved.
[x] user_verification
Requires: user request [x] access_rights: letter to C level (currently Lisa) verifying grant of access [x] account name/contact info: verify on https://collab.wikimedia.org/wiki/Fundraising#Contact_List
Accounts and Services
[x] client_ssl_cert
Requires: user_verification [x] cert_setup: generate cert on frpm1001 using ssl_user_admin [x] account_setup: sms the user the password for the key [x] follow_on: assist with certificate installation
[x] civicrm
Requires: client_ssl_cert [x] account_setup: Create user account. This will notify the user via email to update their password. [x] follow_on: Verify user can log in to https://civicrm.wikimedia.org