Sunet TCS-medlemmar,
server-certikat utfärdade mellan 2026-03-27 och 2026-07-20 har haft en
teknisk felaktighet (se detaljer nedan) som gör att HARICA måste
revokera dem 2026-07-25 och nya certifikat utfärdas. Detta är samma
slags fel som förra veckan, men för en annan detalj.
Detta problem upptäcktes när alla började lusläsa CPSer och jämföra
med certfikat efter problemet hos HARICA förra veckan. Då upptäcktes
detta nya problem hos HARICA, och det är inte helt osannolikt att det
blir liknande incidenter hos andra CAs också (men det lär inte påverka
oss/er).
Pinsamt nog påverkar detta allså också certifikat som ni har förnyat
innan idag för den förra vågen av revokeringar
(2026-06-15..2026-07-15) som vi mejlat om.
HARICA har börjat skicka ut epost till era admin-adresser med
information om vilka certifikat som är drabbade och vad ni behöver göra.
Det är samma som sist: ACME med ARI går automatiskt, ACME utan ARI
kräver att man provocerar fram uppdatering, för manuella certifikat
väntar man på att nytt cert utfärdas och laddar hem och installerar det,
eller om man inte vill vänta så begära man nytt cert "som vanligt".
Vi beklagar innerligt det här och hoppas att detta är sista strulet av
detta slag.
--- klipp ---
Dear TCS Members,
We are writing to notify you of an additional technical issue, identified
following feedback received during the review of the public incident related
to the id-kp-clientAuth Extended Key Usage (EKU), affecting HARICA's
certificate profiles used for TLS Server Certificates issued between
2026-03-27 and 2026-07-20.
What happened?
The review identified that affected certificate profiles did not include the
Authority Information Access (AIA) OCSP URI access method, while HARICA's
current CP/CPS requires this method to be present in TLS Server Certificates.
It is worth noting that HARICA’s decision to remove the AIA OCSP URI was
consistent with industry’s best practice. Unfortunately, revocation of
incompatible certificates with the at-the-time CP/CPS is also expected in the
industry.
As of today, HARICA has restored the AIA OCSP URI in all affected TLS Server
certificate profiles to ensure compliance with the current CP/CPS.
HARICA is also in the process of updating its CP/CPS to reflect the planned
sunsetting of the AIA OCSP URI. Once the updated CP/CPS becomes effective, the
AIA OCSP URI will again be removed from the corresponding certificate profiles
in accordance with the revised policy. Certificates with AIA OCSP URI will
remain valid.
Action Required
TLS Server Certificates issued between 2026-03-27 and 2026-07-20 that do not
include the AIA OCSP URI access method are affected and must be replaced.
HARICA is taking immediate steps to facilitate replacement of all affected
certificates. Over the course of today, all affected subscribers will be
notified and provided with specific actions required to replace their
certificates in time, depending on their issuance method:
- Single requests submitted through HARICA's portal and API-based issuance
- HARICA's Legacy ACME
- HARICA's Flexible ACME
For Flexible and Legacy ACME, HARICA has enabled ARI (Automated Renewal
Information) support to allow affected subscribers to complete replacement
automatically. This has already been tested successfully in the course of the
previous mass-replacement event. We urge all server TLS certificate
subscribers to switch to ACME if they have not done so already.
A thorough root cause analysis had already started during the clientAuth issue
which will be extended to identify systemic issues that lead to these CP/CPS
inconsistencies and take measures to minimize the risk of reoccurrence.
We sincerely apologize for the inconvenience this causes and appreciate your
prompt cooperation in ensuring timely certificate replacement.
We remain at your disposal for any further information.
Best regards,
support-tcs(a)harica.gr
Hellenic Academic and Research Institutions Certification Authority (HARICA)
Email Disclaimer
The information in this email is confidential and is intended solely for the
addressee(s). If you have received this transmission in error, and you are not
an intended recipient, be aware that any disclosure, copying, distribution or
use of this transmission or its contents is prohibited. Furthermore, you are
kindly requested to send us back the original message to the sender’s address
and delete the message from your system immediately.
Internet communications are not secure and therefore HARICA does not accept
legal responsibility for the contents of this message and for any damage
whatsoever that is caused by viruses being passed.
[[End of S/MIME Signed Part]]
--
Kent Engström, Sunet TCS
kent.engstrom(a)liu.se, +46 13 28 4444
Sunet TCS-medlemmar,
server-certikat utfärdade 2026-06-15 och fram till nyss har haft en
teknisk felaktighet (se detaljer nedan) som gör att HARICA måste
revokera dem 2026-07-20 och nya certifikat utfärdas.
Som det står nedan kommer HARICA skicka epost om certifikaten men ni
kan vilja kolla själva om ni har några certifikat utfärdade senste
månaden som behöver utfärdas om.
--- klipp ---
Dear TCS Members,
We are writing to notify you of a technical issue, identified following a
Certificate Problem Report, affecting HARICA's certificate profiles used for
TLS Server Certificates issued on or after June 15th 2026.
What happened?
The affected certificate profiles incorrectly included the clientAuth Extended
Key Usage (EKU), which was not permitted under HARICA's CP/CPS. This issue has
since been corrected in our CP/CPS. However, in accordance with industry
requirements and our CP/CPS, all affected certificates must be revoked within
5 days of the issue's discovery — by 2026-07-20.
This revocation timeline is a standard industry requirement applicable to all
publicly trusted CAs, intended to preserve the integrity and trustworthiness
of the global certificate ecosystem.
Action Required
HARICA is taking immediate steps to facilitate replacement of all affected
certificates. Over the course of today, all affected subscribers will be
notified of the upcoming revocation and provided with specific actions
required to replace their certificates in time, depending on their issuance
method:
- Single requests submitted through HARICA's portal and API-based issuance
- HARICA's Legacy ACME
- HARICA's Flexible ACME
For Flexible and Legacy ACME, HARICA will enable ARI (Automated Renewal
Information) support to allow affected subscribers to complete replacement
automatically.
We plan to submit a public bug later today following industry practice and
share more details.
We sincerely apologize for the inconvenience this causes and appreciate your
prompt cooperation in ensuring timely certificate replacement.
We remain at your disposal for any further information.
Best regards,
support-tcs(a)harica.gr
Hellenic Academic and Research Institutions Certification Authority (HARICA)
--
Kent Engström, Sunet TCS
kent.engstrom(a)liu.se, +46 13 28 4444