Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Create a new self-signed signing certificate set to expire on December 18, 2037:
    • https://md.incommon.org/certs/incommon.pem
  2. Make it possible to securely download the new signing certificate via the Federation Manager.
  3. Deploy a new production metadata aggregate that uses the new self-signed certificate and a SHA2-based signing algorithm (specifically, SHA-256):
    • http://md.incommon.org/InCommon/InCommon-metadata.xml
  4. Deploy a new fallback metadata aggregate that uses the new self-signed certificate and the SHA1-based signing algorithm (like we do now):
    • http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml
  5. Deploy a new test preview metadata aggregate that is identical to the production metadata aggregate (initially):
    • http://md.incommon.org/InCommon/InCommon-metadata-testpreview.xml
  6. Advise all deployments to migrate to one of the new metadata aggregates ASAP but no later than March 29, 2014.
  7. Replace the current metadata aggregate with a redirect to the fallback metadata aggregate on March 29, 2014.
  8. Retire the following resources on March 29, 2014:
    • http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml
    • http://wayf.incommonfederation.org/InCommon/InCommon-metadata-test.xml
    • https://wayf.incommonfederation.org/bridge/certs/incommon.pem
    • https://wayf.incommonfederation.org/bridge/certs/ca.pem
    • http://incommoncrl1.incommonfederation.org/crl/eecrls.crl
    • http://incommoncrl2.incommonfederation.org/crl/eecrls.crl
  9. Sync the fallback metadata aggregate with the production metadata aggregate on June 30, 2014.
  10. Wiki Markup
    Remove the redirect to the _fallback metadata aggregate_ on \[*date TBD*\].

...