...
InCommon Operations will take the following actions:
- Replace the current signing certificate with a long-lived, Create a new self-signed signing certificate based on the current key pair. Set the new certificate to expire on December 18, 2037set to expire on December 18, 2037:
- https://md.incommon.org/certs/incommon.pem
- Make it possible to securely download the new signing certificate via the Federation Manager.
- Deploy a new production metadata aggregate that uses the new self-signed certificate and a SHA2-based signing algorithm (specifically, SHA-256):
- http://md.incommon.org/InCommon/InCommon-metadata.xml
- Deploy a new fallback metadata aggregate that uses the new self-signed certificate and a SHA1-based signing algorithm (like we do now):
- http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml
- Advise all deployments to migrate to one of the new metadata aggregates ASAP but no later than March 29, 2014.
- Replace the current metadata aggregate with a redirect to the fallback metadata aggregate on March 29, 2014.
- Retire the following resources on March 29, 2014:
- http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml
- https://wayf.incommonfederation.org/bridge/certs/incommon.pem
- https://wayf.incommonfederation.org/bridge/certs/ca.pem
- http://incommoncrl1.incommonfederation.org/crl/eecrls.crl
- http://incommoncrl2.incommonfederation.org/crl/eecrls.crl
- Sync the fallback metadata aggregate with the production metadata aggregate on June 30, 2014.
Wiki Markup Remove the redirect to the _fallback metadata aggregate_ on \[*date TBD*\].
...