Summary
Updated, 19 November 2024.
We are changing our SSL certificate supplier to better align processes and maximise efficiency when 90-day security certificate renewal is implemented. Acquia Edge powered by Akamai will be used in front of Mosaic (and later Oxford Fresco) to provide both firewall and security certificate management for platform websites.
Why are we doing this?
- To improve security and to prepare the Mosaic platform for implementation of best-practice 90-day security certificate validation
- To prepare for the transition to Oxford Fresco
What's changing?
- In order to validate the University’s ownership of the domains that need to be handled by the SSL certificates, Akamai validation tokens have been added in bulk by the Central Networks team as CNAME records in the DNS for each sub-domain. This will allow Akamai to automatically validate custom domains every 90 days
- Old and unsupported custom domains will be removed from the certificate
- To enable us to provide the latest custom domain information to our supplier at the point of switchover, we will operate a change freeze period. No custom domains will be added or removed from the SSL certificate during this period.
- Following the end of the change freeze, when we have successfully changed supplier, IT Managers will have to add an Akamai validation token to the appropriate DNS record for any new SSL certificate request as part of the custom domains process
- The Domains documentation will be updated
Key dates
Change freeze period: 27 November 2024 to 6 January 2025 inclusive. Please inform us of any domain needing to be added before this period by Friday, 22 November.
Switch to Acquia Edge powered by Akamai: before 10 December 2024, full details TBA soon