I'm going to keep an eye on the upstream PR to see if someone comes up with a better solution, but in the meantime, deploys (at least on new environments) are broken without this fix.
The upstream PR was replaced with https://github.com/edx/configuration/pull/5203 which just deletes the whole InCommon cert. I'm going to pull that one in instead (more red lines == better).
Pulling a fix down from upstream to deal with a sudden change that InCommon made to their certificate hosting.
See: https://github.com/edx/configuration/pull/5200
I'm going to keep an eye on the upstream PR to see if someone comes up with a better solution, but in the meantime, deploys (at least on new environments) are broken without this fix.