HM PKI
Operational
HM PKI is the university’s public key infrastructure. The service provides digital certificates that enable secure authentication, encryption, and digital signatures for staff and systems.
News
Everything’s Fine!
There are currently no issues or notifications. This service is operating normally.
Report an Incident
Have you encountered a problem while using this service? Please notify us via our help desk.
Visit the Help DeskStatistics
Show service?
Do you want to open the detail page for issue ""?Resolved issues
Revocation of certificates by HARICA
Disrupted – Resolved after 4d 7h 59m
Update 26.07 - 16:00:
As announced, yesterday at noon (25.07 - 12:00 CEST) HARICA revoked all affected certificates and added them to the corresponding CRLs.
Depending on the browser, it may still take some time before the certificates are marked as invalid. If any certificate was overlooked, please contact the responsible administrator.
The PKI service will remain a proxy for Let’s Encrypt until the issues at HARICA have been fully resolved.
Update 23.07 - 10:00:
HM has quickly converted its own PKI portal into an ACME proxy for Let’s Encrypt. Renewals should now be possible again with minor limitations.
Original notice:
HARICA unfortunately has to revoke various certificates.
Affected: All SSL server certificates that were issued between 27.03.2026 and 20.07.2026 (inclusive) and do not include the AIA OCSP URI access method certificate extension.
This unfortunately also includes the SSL server certificates that were already replaced as part of HARICA’s revocation announcements last week.
The affected SSL server certificates will be revoked on 25.07.2026.
Not affected: User certificates, as well as server certificates that were issued up to 26.03.2026 and from 21.07.2026 (today), inclusive.
The background to this renewed round of revocations is that at the end of March 2026 HARICA removed the AIA OCSP URI access method certificate extension from the issued SSL server certificates, as announced at the beginning of the year, but unfortunately failed to update the CP/CPS document accordingly. Thus, in the period from 27.03.2026 to 20.07.2026, SSL server certificates were issued without the AIA OCSP URI access method certificate extension, even though according to the CP/CPS documents in force at the time this extension should have been included in these certificates. Therefore, revocation of the affected SSL server certificates is unfortunately unavoidable.
Please check, for the systems you manage, when the certificates were issued and replace them if necessary.
The API and portal are currently slow—we unfortunately have no control over this, as HARICA is currently experiencing long response times.