InCommon Certificate Service Transition
This page will be updated as more details are made available. Check back later for updates.
Texas A&M University is subscribed to the InCommon Certificate Service to provide certificate services to the campus community. InCommon has announced that they will be transitioning from Sectigo to a new certificate authority, CertiNext. July 17th is the final day that Sectigo will be available to the university. Due to significant changes between the platforms, the Texas A&M Certificate Service (cert.tamu.edu) will be deprecated on that date. Campus members are encouraged to utilize ACME (Automated Certificate Management Environment) for automated certificate issuance and renewal where possible. For systems where manual certificate installation is still required, additional guidance will be provided for requesting certificates via ACME for manual installation, or if necessary, access to the CertiNext platform will be provisioned.
Other Texas A&M University System member universities and agencies that are not part of Texas A&M University - College Station (part 02) that have previously used the Texas A&M Certificate Service or Sectigo Certificate Manager will have their own account provisioned into CertiNext under the new contracted agreement that the Texas A&M University System has with InCommon.
More information about the transition is available via InCommon.
Frequently Asked Questions
- When will existing SSL/TLS certificates expire?
- All certificates issued via Sectigo prior to access lapsing on July 17th will remain valid during their natural validity period.
- What actions need to occur if we need to revoke an existing Sectigo certificate after July 17th?
- If you need to revoke a certificate, reach out to certificates@tamu.edu with details and Identity Security will coordinate with InCommon and Sectigo to revoke the certificate - simply replacing/renewing the existing certificate does NOT necessitate revoking the previous certificate.
Migration Options
ACME Proxy
Technology Services is currently exploring the capabilities of ESnet's acme-proxy and we expect to make it available to the campus community over the coming days. This offering will allow for services that reside within Texas A&M's network to request certificates for any tamu.edu DNS names that resolve to it via a traditional HTTP-01 ACME challenge (similar to Let's Encrypt), even if the service is not public facing without the need for External Account Binding (EAB) credentials.
Direct ACME Integration with CertiNext
For systems that require wildcard certificates or manual certificate installation, a set of EAB credentials (KeyID and HMAC Key) will be issued for the requested domain(s) to generate certificates from the CertiNext platform. Organization Validated (OV) certificates issued via EAB credentials do not require the system to be publicly accessible nor do they require a public A/CNAME DNS record.
Console Access to CertiNext
We are currently still assessing the RBAC capabilities of the CertiNext platform, but may provision console access to the platform on a case-by-case basis for manual certificate issuance. If you feel that your use case warrants access to the CertiNext console, please reach out to certificates@tamu.edu.