Network technical assurance monitoring

This topic describes network monitoring and its limitations.

Network monitoring

Network monitoring ensures that no aspects of the network were tampered in an OSO setup, whether an iteration is running or in an idle state. The conductor component has network monitoring capabilities. Network monitoring is triggered during conductor instantiation and continues to monitor the network until the conductor ceases to exist.

Network monitoring detects the following tampering scenario:
  • Toggling hipersockets associated with OSO
  • Addition of new network interfaces

During the non-iteration phase, network monitoring monitors LPAR1 and LPAR2 network devices. The LPAR3 device is not accessible for monitoring due to the absence of network connectivity during the non-iteration phase between LPAR2 and LPAR3.

During an iteration phase, network monitoring monitors LPAR2 and LPAR3 network devices. Once Hipersocket between LPAR2 and LPAR3 is online, LPAR1 cannot be monitored due to the absence of network connectivity between LPAR1 and LPAR2 in the iteration phase.

  • What happens when tampering is detected?

    Irrespective of the iteration or non-iteration phase, monitoring error will be produced by network-monitoring. Whenever a monitoring error is produced, a flush is issued, and the system is restored to an optimal state.

The following table explains the operations of SA and OSO when the management network is attached and removed.

Operation With Management Network on LPAR2 and LPAR3 Without Management Network on LPAR2 and LPAR3
Flush Allowed Allowed
Undeploy Allowed Allowed
Signing Iteration Not Allowed Allowed
Change Request Iteration (Backup, Restore, Dump) Not Allowed Allowed

Monitoring management network

Once OSO is up and running, management networks are detached from LPAR2 and LPAR3. In such a scenario, network monitoring behaves in the following way:
  • Removing the management network will isolate LPAR2 and LPAR3 from the external network. However, OSO operations will continue without interruption.
  • When the management network is reattached, OSO will automatically detect the interface and initiate flush operations. Since this triggers a flush, ensure that no iterations are in progress at that time to avoid transaction expiry or failure.
  • When additional hipersockets and management network are detected, all operations involving signing conductor (signing iteration, change request iteration, flush operations and so on) are blocked. To continue with the operations, the user must remove those additional interfaces. However, the user will still be able to list documents and approve documents, but cannot perform the above-mentioned operations.

Data loss caution: Management network operations

Attaching the management network to LPAR2 or LPAR3 results in immediate and irreversible data loss.

Impact
The following data is deleted:
  • All documents in the pre-confirmation and post-confirmation queues
  • Current signing iteration state and progress
  • Pending signing operations
When data loss occurs
Data loss is triggered when the management network is attached during the following operations:
  • Retrieving responses using oso-cli sa on LPAR2 or LPAR3
  • Renewing expired certificates
  • Upgrading Digital Asset Haven components, Secure Appliance, or plugins
  • Rebooting any LPAR
  • Redeploying the conductor
Required action
Before attaching the management network:
  • Ensure that all signing iterations are complete
  • Back up frontend data, if supported by the plugin