{
  "is": "issue",
  "title": "Revocation of certificates by HARICA",
  "body": "\u003cp\u003eUpdate 26.07 - 16:00:\u003c/p\u003e\n\u003cp\u003eAs announced, yesterday at noon (25.07 - 12:00 CEST) HARICA revoked all affected certificates and added them to the corresponding CRLs.\u003c/p\u003e\n\u003cp\u003eDepending on the browser, it may still take some time before the certificates are marked as invalid. If any certificate was overlooked, please contact the responsible administrator.\u003c/p\u003e\n\u003cp\u003eThe PKI service will remain a proxy for Let’s Encrypt until the issues at HARICA have been fully resolved.\u003c/p\u003e\n\u003cp\u003eUpdate 23.07 - 10:00:\u003c/p\u003e\n\u003cp\u003eHM has quickly converted its own PKI portal into an ACME proxy for Let’s Encrypt. Renewals should now be possible again with minor limitations.\u003c/p\u003e\n\u003cp\u003eOriginal notice:\u003c/p\u003e\n\u003cp\u003eHARICA unfortunately has to revoke various certificates.\u003c/p\u003e\n\u003cp\u003eAffected: All SSL server certificates that were issued between 27.03.2026 and 20.07.2026 (inclusive) and do not include the AIA OCSP URI access method certificate extension.\u003c/p\u003e\n\u003cp\u003eThis unfortunately also includes the SSL server certificates that were already replaced as part of HARICA’s revocation announcements last week.\u003c/p\u003e\n\u003cp\u003eThe affected SSL server certificates will be revoked on 25.07.2026.\u003c/p\u003e\n\u003cp\u003eNot affected: User certificates, as well as server certificates that were issued up to 26.03.2026 and from 21.07.2026 (today), inclusive.\u003c/p\u003e\n\u003cp\u003eThe background to this renewed round of revocations is that at the end of March 2026 HARICA removed the AIA OCSP URI access method certificate extension from the issued SSL server certificates, as announced at the beginning of the year, but unfortunately failed to update the CP/CPS document accordingly. Thus, in the period from 27.03.2026 to 20.07.2026, SSL server certificates were issued without the AIA OCSP URI access method certificate extension, even though according to the CP/CPS documents in force at the time this extension should have been included in these certificates. Therefore, revocation of the affected SSL server certificates is unfortunately unavoidable.\u003c/p\u003e\n\u003cp\u003ePlease check, for the systems you manage, when the certificates were issued and replace them if necessary.\u003c/p\u003e\n\u003cp\u003eThe API and portal are currently slow—we unfortunately have no control over this, as HARICA is currently experiencing long response times.\u003c/p\u003e\n",
  "createdAt": "2026-07-22 08:06:00 +0200 +0200",
  "lastMod": "2026-07-22 08:06:00 +0200 +0200",
  "permalink": "https://status.hm.edu/en/issues/2026-07-22-r%C3%BCckruf-von-zertifikaten-durch-harica/",
  "severity": "disrupted",
  "resolved": true,
  "informational": false,
  "resolvedAt": "2026-07-26 16:05:00+02:00",
  "affected": ["HM PKI"],
  "filename": "2026-07-22-rückruf-von-zertifikaten-durch-harica.md"
}