Attesting that I was watching and listening to the live stream of the ceremony on Youtube for the entire duration of the broadcast without interruption. Notes were taken as I went with a stopwatch keeping track of relative timestamps from the start of the ceremony.
All times are of my viewing of the ceremony, not necessarily as the ceremony actually occurred due to delay between real events and the stream.
This message will be signed with my Keybase GPG key 51B0 6736 1740 F5FC
date: 2020-10-30 broadcast start time: 10:15 AM broadcast stop time: 12:21 PM ceremony start: 10:26 AM
- ernest w durbin
- william woodruff
00:00:00 airplane mode on all devices
00:01:41 booting raspberry pi
00:02:49 usb inserted
00:03:10 usb mounted
00:06:05 pictures of HSM completed
00:06:30 bag opened hsm removed
00:08:37 hsm inserted into rpi
00:09:34 hsm provisioned
00:12:31 all pins entered
00:12:50 success prompt
00:14:19 converted to .pem
00:14:44 confirmed pems created
00:15:03 hsm removed
00:16:55 hsm sealed in bag (note bag labeled before sealing, out of order per runbook)
00:18:41 bag opened hsm removed
00:19:43 hsm inserted into rpi
00:20:08 hsm provisioned
00:22:20 auth key confirmed
00:22:36 confirmed again
00:23:51 converted to .pem
00:23:16 hsm removed from rpi
00:26:13 hsm sealed in bag
00:27:24 bag opened hsm removed
00:28:31 hsm inserted into rpi
00:28:55 hsm provisioned
00:30:45 pins inputted and confirmed
00:31:55 converted to .pem
00:32:34 removed hsm from rpi
00:34:05 hsm sealed in bag
<ceremony took a break here>
<note: me and William both took down serial number as 'DENK0130189' which isn't correct>
<unsure if this was our fault or if the serial number was not pronounced right initially>
00:38:43 break over
00:40:13 removed hsm from bag
00:40:45 hsm inserted into rpi
00:42:03 hsm provisioned
00:43:45 pin entered didn't match
00:45:13 cancelled provisioning
<at this point one character of SO pin leaked to screen>
<rolled w/ dice a new first character of the SO pin>
00:47:11 new first character secretly selected
00:48:16 start new provisioning
00:49:16 new SO pin and user pin confirmed
<whole SO pin leaked to screen, regenerated a brand new SO pin with dice>
00:54:17 started generating new SO pin w/ dice
01:00:36 generation of new SO pin complete
01:02:28 reprovisioned hsm
01:03:36 SO and user pin entered
01:05:12 generated nitrohsm keys
01:05:40 completed key generation
01:06:19 hsm removed from rpi
01:08:07 hsm sealed in bag
01:09:38 removed hsm from bag
01:10:22 inserted into rpi
01:11:33 factory reset hsm
01:12:40 SO and user pin typed and confirmed
01:13:48 generated hsm keys
01:14:24 generation complete
01:14:56 removed hsm from rpi
01:16:23 sealed hsm in bag
01:17:35 removed hsm from bag
01:17:52 inserted into rpi
01:18:34 provision run
01:19:30 SO and user pin typed and confirmed
01:20:49 nitro key generated
01:21:19 generation complete
01:22:14 removed hsm from rpi
01:23:46 sealed hsm in bag
01:25:08 ceremony products copied to flash storage
01:26:43 sync
01:26:52 unmounted
01:26:59 remove flash drive (not in runbook)
<not in runbook, making an additional copy of ceremony products>
01:26:44 backup flash drive removed from bag
01:27:33 mounted
01:28:00 copy, sync and unmounted
<back to runbook>
01:28:50 rpi shutdown
01:36:40 commit created and signed
<ceremony products committed under ceremony/2020-10-30 directory>
<commit SHA: e77db08e2ef806e3670c2ee6599a1e7bf11401cf>
<branch: 'ceremony-2020-10-30'>
<url: https://github.com/psf/psf-tuf-runbook/commit/e77db08e2ef806e3670c2ee6599a1e7bf11401cf>
01:38:55 ceremony complete
Thank you! Very helpful. Also add a link to this to the video metadata.
Some sort of addendum or revision might include: