Revocation of certificates by HARICA
Disrupted – Resolved after 4d 7h 59m
Update 26.07 - 16:00:
As announced, yesterday at noon (25.07 - 12:00 CEST) HARICA revoked all affected certificates and added them to the corresponding CRLs.
Depending on the browser, it may still take some time before the certificates are marked as invalid. If any certificate was overlooked, please contact the responsible administrator.
The PKI service will remain a proxy for Let’s Encrypt until the issues at HARICA have been fully resolved.
Update 23.07 - 10:00:
HM has quickly converted its own PKI portal into an ACME proxy for Let’s Encrypt. Renewals should now be possible again with minor limitations.
Original notice:
HARICA unfortunately has to revoke various certificates.
Affected: All SSL server certificates that were issued between 27.03.2026 and 20.07.2026 (inclusive) and do not include the AIA OCSP URI access method certificate extension.
This unfortunately also includes the SSL server certificates that were already replaced as part of HARICA’s revocation announcements last week.
The affected SSL server certificates will be revoked on 25.07.2026.
Not affected: User certificates, as well as server certificates that were issued up to 26.03.2026 and from 21.07.2026 (today), inclusive.
The background to this renewed round of revocations is that at the end of March 2026 HARICA removed the AIA OCSP URI access method certificate extension from the issued SSL server certificates, as announced at the beginning of the year, but unfortunately failed to update the CP/CPS document accordingly. Thus, in the period from 27.03.2026 to 20.07.2026, SSL server certificates were issued without the AIA OCSP URI access method certificate extension, even though according to the CP/CPS documents in force at the time this extension should have been included in these certificates. Therefore, revocation of the affected SSL server certificates is unfortunately unavoidable.
Please check, for the systems you manage, when the certificates were issued and replace them if necessary.
The API and portal are currently slow—we unfortunately have no control over this, as HARICA is currently experiencing long response times.