Index of /distribution/egi-1.54-1/current-old
------------------------------------------------------------------------------
Subject: VOMS servers need old build of EGI-trustanchors
Dear all
This broadcast concerns sites that manage a VOMS server with VOMS-ADMIN
administrative interface.
A problem has been found where sites upgraded their VOMS server to the
latest version of the trust anchors (CA 1.38+) and subsequently the VOMS
Administrative Interface (VOMS-ADMIN) fails to start. We are presently
working to understand the issue.
This does not affect the VOMS server itself, but solely the admin interface.
The quick fix is for the VOMS server admins to replace the default
EGI trust anchor repository by the following temporary repository
http://egi-igtf.ndpf.info/distribution/egi/current-old/
which can be configured using the following Yum repo file. Please keep the
following in mind:
- only the VOMS ADMIN server is affected. This change DOES NOT apply to other
services at this point, and unless you are affected by this issue you
should NOT change the trust anchor repository
- Only ONE repository can be configured at any one time. Before
configuring the legacy repository, you MUST DISABLE the default repo
(by setting "enabled=0" in the repo.d file)
- You CANNOT upgrade from the default repo to the legacy repo or vice-versa.
Before changing, you must de-install the previous "ca_*" packages and all of
the meta-packages "lcg-CA", "ca-policy-egi-core" and/or "ca-policy-lcg"
The legacy repo.d file should read:
[EGI-trustanchors-historic]
name=EGI-trustanchors-historic
baseurl=http://egi-igtf.ndpf.info/distribution/egi/current-old/
gpgkey=http://repository.egi.eu/sw/production/cas/1/GPG-KEY-EUGridPMA-RPM-3
gpgcheck=1
enabled=1
This repository is made available on a temporary basis and should not be
configured as a permanent site setting. It should not be applied to non VOMS
services.
European Grid Infrastructure EGI Trust Anchor release 1.54 2013.06.24
------------------------------------------------------------------------------
For release DOCUMENTATION available on this EGI Trust Anchor release see
https://wiki.egi.eu/wiki/EGI_IGTF_Release
------------------------------------------------------------------------------
Modifications compared to the previous release:
* updated to IGTF Accredited CA distribution version 1.54-1 Classic, SLCS and
MICS profiles, encoded in meta-package "ca-policy-egi-core-1.54-1" (for new
installs) and "lcg-CA-1.54-1" (for sites upgrading from EGEE/LCG releases).
* Location of the repository changed to repository.egi.eu. See documentation
for details and the updated repo files.
* Your may install BOTH the "egi-core" AND "lcg" meta-packages, according to
your policies. Note that your organisation or NGI may have a specific
policy and may have added or removed CAs compared to the EGI core policy.
The following notices are republished from the IGTF and EUGridPMA, inasfar
as pertinent to this release. More information can be found in the
EUGridPMA newsletter (see https://www.eugridpma.org/):
Changes from 1.53 to 1.54
-------------------------
(24 June 2013)
* Extended life time of Grid-KA CA (dd4b34ea) (DE)
* Added new CERN hierarchy for CERN IT/IS CA (SHA2 migration) (CH)
* Updated metadata for GridGermany DFN-CERT CAs (DE)
* Updated contact metadata for KEK (JP)
* Updated contact metadata for HKU (HK)
* Updated contact metadata for AIST (JP)
The CA modifications, encoded in both "requires" and "obsoletes" clauses, have
been incorporated in the above-mentioned meta-package RPMs. This trust anchor
release is best enjoyed with fetch-crl v3 or better, available from popular
GNU/Linux OS (add-on) repositories Fedora, EPEL, Debian, and from the IGTF.
Version information: ca-policy-egi-core = 1.54-1