Experiencing disruptions
·
 Back

Revocation of certificates by HARICA

Disrupted   – Ongoing

Update 23.07 - 10:00:

HM has, at short notice, converted its own PKI portal into an ACME proxy for Let’s Encrypt. Renewal should now be possible again with minor limitations.

Original notice:

HARICA unfortunately has to revoke various certificates.

Affected: All SSL server certificates that were issued between March 27, 2026 and July 20, 2026 (inclusive) and do not contain the certificate extension AIA OCSP URI access method.

This unfortunately also includes the SSL server certificates that were already replaced as part of HARICA’s revocation announcements last week.

The affected SSL server certificates will be revoked on July 25, 2026.

Not affected: User certificates, as well as server certificates that were issued up to March 26, 2026 and from July 21, 2026 (today), inclusive.

The background to this new round of revocations is that at the end of March 2026 HARICA removed the certificate extension AIA OCSP URI access method, as announced at the beginning of the year, from the issued SSL server certificates, but unfortunately failed to update the CP/CPS document accordingly. Thus, in the period from March 27, 2026 to July 20, 2026, SSL server certificates were issued without the certificate extension AIA OCSP URI access method, although according to the CP/CPS documents valid at the time, this extension should have been included in these certificates. Therefore, revocation of the affected SSL server certificates is unfortunately unavoidable.

Please check the systems you manage to see when the certificates were issued and replace them if necessary.

The API and portal are currently slow—we unfortunately have no influence over this, as there are currently long response times on HARICA’s side.

Updated: