Skip to main content

InCommon Certificate Service Transition

Texas A&M University is subscribed to the InCommon Certificate Service to provide certificate services to the campus community. InCommon has transitioned from Sectigo to a new certificate authority, CertiNext.

On July 17th, access to the Sectigo service was disabled and the Texas A&M Certificate Service (cert.tamu.edu) was retired.

Campus members are encouraged to utilize ACME (Automated Certificate Management Environment) for automated certificate issuance and renewal.

Other Texas A&M University System member universities and agencies that are not part of Texas A&M University - College Station (system part 02) that have previously used the Texas A&M Certificate Service or Sectigo Certificate Manager were provisioned separate CertiNext accounts under the new agreement.

More information about the transition is available via InCommon.

Frequently Asked Questions

  • When will existing SSL/TLS certificates expire?
    • All certificates issued via Sectigo remain valid during their natural validity period.
  • What actions need to occur if we need to revoke an existing Sectigo certificate after July 17th?
    • If you need to revoke a certificate, reach out to certificates@tamu.edu with details and Identity Security will coordinate with InCommon and Sectigo to revoke the certificate - Replacing/renewing an existing certificate does NOT necessitate revoking the previous certificate.

Migration Options

Let's Encrypt (preferred)

Public-facing services available outside the campus network should use the public Let’s Encrypt service. Let’s Encrypt certificates are free to use and include robust automation via ACME as part of the service offering.

A list of compatible ACME clients for various platforms are available in Let's Encrypt's Documentation.

ACME Proxy (preferred)

Technology Services now offers ACME certificate issuance via our ACME Proxy Service. This offering can issue certificates for services that reside within Texas A&M's campus network for any tamu.edu DNS domains which can respond to an an HTTP-01 ACME challenge (similar to Let's Encrypt), even if the service is not available outside the firewall. This method does not require a credential.

Direct ACME Integration with CertiNext

For systems that require wildcard certificates or manual certificate installation, a set of EAB credentials (KeyID and HMAC Key) will be issued for the requested domain(s). Organization Validated (OV) certificates issued via EAB credentials do not require the system to be publicly accessible nor do they require a public DNS record. If the Proxy service is not suitable for your use case, you can request a set of EAB credentials by reaching out to certificates@tamu.edu.

Console Access to CertiNext

Console access to the platform is provisioned on a case-by-case basis for manual certificate issuance. If you believe your use case requires access to the CertiNext console, please reach out to certificates@tamu.edu.