# Signing key for CLARIN SPF metadata feeds changed

**URL:** <https://forum.clarin.eu/t/signing-key-for-clarin-spf-metadata-feeds-changed/1225>\
**Category:** AAI Infrastructure\
**Tags:** federated-login, service-provider-fed\
**Created:** [5 February 2026 15:26 UTC](https://forum.clarin.eu/t/signing-key-for-clarin-spf-metadata-feeds-changed/1225 "2026-02-05T15:26:36Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![andmor](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.clarin.eu/andmor/32/24_2.png) [@andmor](https://forum.clarin.eu/u/andmor)\
**Post date:** [5 February 2026 15:26 UTC](https://forum.clarin.eu/t/signing-key-for-clarin-spf-metadata-feeds-changed/1225/1 "2026-02-05T15:26:36Z")

</div>

Dear members of the CLARIN Service Provider Federation,

Due to a technical error [1], we have replaced the signing certificate used for the metadata feeds we distribute.

This affects all metadata feeds available at:

> **[Index of /aai/](https://infra.clarin.eu/aai/)**

If your SP or IdP relies on any of these feeds **and** signature verification is performed using a manually configured certificate, please update your configuration to use the new certificate.

You can download the new X.509 certificate for signature verification here:  
[SPF\_signing\_pub-2026-2031.crt](https://www.clarin.eu/media/9330)

Our FAQ entry [How is the SAML metadata about SPs distributed to the identity federations?](https://forum.clarin.eu/t/how-is-the-saml-metadata-about-sps-distributed-to-the-identity-federations/406) has been updated accordingly

[1] - The previous key was missing the CA extension, which is required by some components of our infrastructure.
