Metadata keys roll over

Tom Scavo trscavo at gmail.com
Thu Jun 14 08:52:36 EDT 2018


[For some reason, the original message has not appeared in my inbox. I
see the original message in the archives, however. Weird.]

> * Aaron Howell <aaron.howell at deakin.edu.au> [2018-06-14 07:16]:
>> We are looking to upgrade our keys after many years - we have
>> started to get “don’t support SHA1” conversations. So if we are gong
>> to have to put in new keys, would prefer to make them the default
>> moving forward.

Here's a blog article I wrote a long time ago about the various uses
of the SHA digest algorithm in federation operations:
https://spaces.internet2.edu/x/AYbYAg

This excerpt from the article may be relevant to your discussions:
There are absolutely no security considerations concerning the
signature on certificates in metadata. Refer to the article for
additional context.

Hope this helps,

Tom


More information about the users mailing list