Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Create a new self-signed signing certificate set to expire on December 18, 2037: [DONE]
  2. On December 18, 2013, deploy three new metadata aggregates: [DONE]
    1. A new production metadata aggregate that uses the new self-signed certificate and a SHA-2 digest algorithm (specifically, SHA-256):
    2. A new fallback metadata aggregate that uses the new self-signed certificate and the SHA-1 digest algorithm (like we do now):
    3. A new preview metadata aggregate that is aliased to the production metadata aggregate:
  3. Advise all deployments to migrate to one of the new metadata aggregates ASAP but no later than March 29, 2014. [DONE]
  4. Create discussion list help@incommon.org. [DONE]
  5. Replace the current metadata aggregate with a redirect to the fallback metadata aggregate on March 29, 2014. [DONE]
  6. Retire the following resources on March 29, 2014:
    • http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml [DONE]
    • http://wayf.incommonfederation.org/InCommon/InCommon-metadata-test.xml
    • https://wayf.incommonfederation.org/bridge/certs/inc-md-cert.pem
    • https://wayf.incommonfederation.org/bridge/certs/incommon.pem
    • https://wayf.incommonfederation.org/bridge/certs/ca.pem
    • http://incommoncrl1.incommonfederation.org/crl/eecrls.crl
    • http://incommoncrl2.incommonfederation.org/crl/eecrls.crl
  7. Sync the fallback metadata aggregate with the production metadata aggregate on June 30, 2014. [DONE]
  8. Remove the redirect to the fallback metadata aggregate on [date TBD].

...