RA-Portal

Urgent revocation of Harica SSL certificates

Outage
Fri 07/17/2026 12:00 PM - Tue 07/21/2026 05:45 PM

Harica is obligated to revoke a substantial number of SSL certificates.
All SSL certificates issued between 15th June and 15th July of 2026 are affected. They will be revoked automatically by Harica starting from 20th July 2026 12:00 CET.
To ensure the availability of your services via SSL (HTTPS, IPSEC), the affected certificates must either be renewed or newly requested and installed on your servers.

Client certificates are unaffected, as well as SSL certificates issued up until 14th June 2026 and starting from 16th July 2026 and onwards.

Background: The SSL certificates were issued with Extended Key Usage "clientAuth", which was against Harica's Certificate Policy Statement from 15th June to 15th July 2026. To preserve the integrity and trustworthiness of the global certificate ecosystem, these non-conforming certificates must be revoked by Harica within a short period of time.

All affected network contact persons will be notified via e-mail by the RA-Portal.

17.07.2026 12:22
Updates

The new SSL certificates still contain EKU clientAuth. It is the combination of clientAuth and issue date 15.06.2026-15.07.2026 that is not CPS compliant.

17.07.2026 14:40

Harica has renewed all affected certificates between 2026-07-17 22:00 CET and 2026-07-18 11:00 CET. These certificates are available for download in RA-Portal, marked as "Automatisch importiert (CA-Portal) " if you search on your CN and set the filter to "Alle". Please make sure to implement the new certificates in your servers.

20.07.2026 11:29

All affected SSL-certificates have been revoked.

21.07.2026 17:47