Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. On December 18, 2013, InCommon Operations will deploy two three new metadata aggregates at the following permanent HTTP locations:
    • http://md.incommon.org/InCommon/InCommon-metadata.xml (production metadata)
    • http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml (fallback metadata)
    • http://md.incommon.org/InCommon/InCommon-metadata-preview.xml (preview metadata)
  2. All new Both metadata aggregates will be signed using a new self-signed signing certificate set to expire on December 18, 2037.
    • Although the signing certificate is new, the signing key is not.
  3. Both All new metadata aggregates will be signed with the same key but the fallback metadata aggregate will use a different digest algorithm.
    • The production metadata aggregate will be signed using a SHA-2 digest algorithm (specifically, SHA-256).
    • Initially, the fallback metadata aggregate will be signed using the SHA-1 digest algorithm (which is what we use now).
    • Initially, the preview metadata aggregate will be aliased to the production metadata aggregate. At some point, the preview metadata aggregate will be used to safely introduce breaking changes into InCommon metadata.
  4. All deployments shall migrate to one of the new metadata aggregates ASAP but no later than March 29, 2014.
    • The current metadata aggregate will be replaced with a redirect to the fallback metadata aggregate on March 29, 2014.
    • If your metadata process can verify an XML signature that uses the SHA-256 digest algorithm, migrate to either the production metadata aggregate or the preview metadata aggregate.
    • If your metadata process can not verify an XML signature that uses the SHA-256 digest algorithm, migrate to the fallback metadata aggregate.
  5. All deployments shall be able to verify an XML signature that uses a SHA-256 digest algorithm by June 30, 2014.
    • On June 30, the fallback metadata aggregate will be synced with the production metadata aggregate (i.e., all aggregates will be signed using the SHA-256 digest algorithm).
    • After June 30, all metadata aggregates published by the InCommon Federation will be signed using the SHA-256 digest algorithm.

...

    • .

Policy

It is strongly recommended that InCommon SPs and IdPs refresh and verify metadata at least daily. The security implications of metadata refresh are discussed on the Metadata Consumption wiki page:

...

  1. Create a new self-signed signing certificate set to expire on December 18, 2037:
    • https://md.incommon.org/certs/incommon.pem
  2. Make it possible to securely download the new signing certificate via the Federation Manager.
  3. On December 18, 2013, deploy a new production metadata aggregate that uses the new self-signed certificate and a SHA2-based signing digest algorithm (specifically, SHA-256):
    • http://md.incommon.org/InCommon/InCommon-metadata.xml
  4. On December 18, 2013, deploy a new fallback metadata aggregate that uses the new self-signed certificate and the SHA1SHA-based signing 1 digest algorithm (like we do now):
    • http://md.incommon.org/InCommon/InCommon-metadata-fallback.xml
  5. Deploy On December 18, 2013, deploy a new preview metadata aggregate when it that is most convenient to do soaliased to the production metadata aggregate:
    • http://md.incommon.org/InCommon/InCommon-metadata-preview.xml
  6. Advise all deployments to migrate to one of the new metadata aggregates ASAP but no later than March 29, 2014.
  7. Replace the current metadata aggregate with a redirect to the fallback metadata aggregate on March 29, 2014.
  8. Retire the following resources on March 29, 2014:
    • http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml
    • http://wayf.incommonfederation.org/InCommon/InCommon-metadata-test.xml
    • https://wayf.incommonfederation.org/bridge/certs/incommon.pem
    • https://wayf.incommonfederation.org/bridge/certs/ca.pem
    • http://incommoncrl1.incommonfederation.org/crl/eecrls.crl
    • http://incommoncrl2.incommonfederation.org/crl/eecrls.crl
  9. Sync the fallback metadata aggregate with the production metadata aggregate on June 30, 2014.
  10. Wiki Markup
    Remove the redirect to the _fallback metadata aggregate_ on \[*date TBD*\].

...